pub struct RefreshError { /* private fields */ }Expand description
A failed key refresh: discovery, fetch, or a key set with nothing usable in it. The keys held before the attempt are kept.
Display is the whole cause chain, outermost first, joined with ": " (e.g.
fetching the JWKS from https://…: request failed: …), so a log line needs no
special formatting to show the root cause. RefreshError::kind is the
coarse, matchable stage that failed.
§Security
A configured issuer or jwks_uri may carry a credential: userinfo
(https://user:pass@…, which the fetch sends as HTTP Basic auth) or a
query string (…/jwks?key=…). Every URL in the message is therefore
redacted — userinfo becomes ***@, a query ?*** and a fragment #***,
while scheme, host, port and path stay, so the endpoint is still
identifiable — and upstream errors are included without the URL they
would otherwise repeat verbatim. The fetch itself uses the URL unchanged.
The message still names the endpoints and repeats upstream error text,
so it is for logs and operators: a public, unauthenticated endpoint (a
health check reachable from outside, say) should report
RefreshError::kind instead.
Implementations§
Source§impl RefreshError
impl RefreshError
Sourcepub fn kind(&self) -> RefreshErrorKind
pub fn kind(&self) -> RefreshErrorKind
Which stage of the refresh failed.
Trait Implementations§
Source§impl Clone for RefreshError
impl Clone for RefreshError
Source§impl Debug for RefreshError
impl Debug for RefreshError
Source§impl Display for RefreshError
impl Display for RefreshError
impl Eq for RefreshError
Source§impl Error for RefreshError
impl Error for RefreshError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()