#[non_exhaustive]pub struct KeySetStatus {
pub keys: usize,
pub jwks_uri: Option<String>,
pub last_attempt: Option<SystemTime>,
pub last_success: Option<SystemTime>,
pub last_error: Option<RefreshError>,
}Expand description
A point-in-time view of the signing keys an crate::OAuthValidator holds,
from crate::OAuthValidator::key_set_status.
Reading it does no I/O and never waits on a refresh in flight, so a
readiness probe, a status page or a metrics scrape can call it as often as
it likes. #[non_exhaustive]: read its fields, never build one; a field
may be added in a minor release.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.keys: usizeHow many usable verification keys are held.
jwks_uri: Option<String>The JWKS URL in use: the configured jwks_uri, or the one discovered
from the issuer’s metadata — None while it is still undiscovered.
Redacted as RefreshError’s # Security note describes: any
userinfo shows as ***@ and any query as ?***.
last_attempt: Option<SystemTime>When the most recent refresh started, whether or not it has finished
and however it ended; None before the first one.
last_success: Option<SystemTime>When a refresh last succeeded (loaded a key set with at least one
usable key); None if none ever has. A failed refresh leaves it — and
the keys — as they were.
last_error: Option<RefreshError>Why the most recent finished refresh failed; None if it succeeded
or none has finished yet. Read RefreshError’s # Security note
before exposing its Display publicly.
Implementations§
Source§impl KeySetStatus
impl KeySetStatus
Sourcepub fn is_ready(&self) -> bool
pub fn is_ready(&self) -> bool
At least one usable key is held — see
crate::OAuthValidator::is_ready.