#[non_exhaustive]pub struct RejectContext<'a> {
pub rejection: &'a TokenRejection,
pub status: StatusCode,
pub request: &'a Parts,
}tower only.Expand description
What an on_reject callback (HttpAuthLayerBuilder::on_reject, or the
axum layer’s AuthLayerBuilder::on_reject) is told about a refusal.
#[non_exhaustive]: read its fields; more may be added without a breaking
change.
Its Debug prints the rejection, the status, the method, the URI’s path
(any query as ?***: a client may send an RFC 6750 §2.3 access_token
there) and version, and the request’s header NAMES — never a header value,
so tracing::warn!(?cx, "refused") cannot log the presented credential
(which, for an insufficient-scope refusal, is a validly signed, unexpired
token).
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.rejection: &'a TokenRejectionWhy the request was refused. TokenRejection::Invalid’s reason is for
logs only — never put it in the response.
status: StatusCodeThe status the response will carry (401, or 403 for insufficient scope), whatever the callback sets.
request: &'a PartsThe refused request’s method, URI, version, headers and extensions — for
content negotiation (Accept), or a per-path error shape.