#[non_exhaustive]pub struct StaticTokenMatch { /* private fields */ }Expand description
Which StaticTokens entry accepted a request: returned by
authenticate_with_static_tokens next to Credential::StaticToken,
and inserted into request extensions by the layers (features axum and
tower) whenever they insert Credential::StaticToken — with the
axum feature it is also an extractor. It carries the entry’s label only;
nothing in it exposes the secret.
A layer configured with a single static_token inserts one too, with no
label.
Implementations§
Source§impl StaticTokenMatch
impl StaticTokenMatch
Sourcepub fn label(&self) -> Option<&str>
pub fn label(&self) -> Option<&str>
The matched entry’s label, as given to StaticTokens::with; None
for an unlabeled entry.
Trait Implementations§
Source§impl Clone for StaticTokenMatch
impl Clone for StaticTokenMatch
Source§impl Debug for StaticTokenMatch
impl Debug for StaticTokenMatch
impl Eq for StaticTokenMatch
Source§impl<S: Send + Sync> FromRequestParts<S> for StaticTokenMatch
Available on crate feature axum only.
impl<S: Send + Sync> FromRequestParts<S> for StaticTokenMatch
axum only.Refuses, fail-closed, exactly as the AuthorizedToken extractor does:
with the layer’s own 401 and WWW-Authenticate challenge when the layer
inserted none (an OAuth token was accepted, or an
optional or
allow_unauthenticated layer passed
the request through), logged at error when the layer has no static token
at all, and with 500 (logged at error) on a route no AuthLayer
covers. The layer inserts one next to every Credential::StaticToken —
unlabeled for a single static_token —
and removes an outer layer’s whenever it accepts an OAuth token, so it
always describes the innermost accepted Credential.
§Examples
use axum::{Router, routing::get};
use oauth_resource_server::StaticTokenMatch;
async fn audit(matched: StaticTokenMatch) -> String {
format!("static key {:?}", matched.label())
}Source§impl<S: Send + Sync> OptionalFromRequestParts<S> for StaticTokenMatch
Available on crate feature axum only.Option<StaticTokenMatch>: None when an AuthLayer ran and accepted
no static token (an OAuth token was accepted, or nothing was presented to
an optional or
allow_unauthenticated layer). On a
route no AuthLayer covers it still refuses with 500, logged at
error, rather than reading as anonymous.
impl<S: Send + Sync> OptionalFromRequestParts<S> for StaticTokenMatch
axum only.Option<StaticTokenMatch>: None when an AuthLayer ran and accepted
no static token (an OAuth token was accepted, or nothing was presented to
an optional or
allow_unauthenticated layer). On a
route no AuthLayer covers it still refuses with 500, logged at
error, rather than reading as anonymous.