#[non_exhaustive]pub struct ResolvedOAuthConfig {Show 20 fields
pub issuer: String,
pub jwks_uri: Option<String>,
pub audience: String,
pub audiences: Vec<String>,
pub resource: String,
pub required_scopes: Vec<String>,
pub scopes_supported: Vec<String>,
pub scope_claims: Vec<String>,
pub principal_claims: Vec<String>,
pub algorithms: Vec<Algorithm>,
pub leeway_secs: u64,
pub require_at_jwt: bool,
pub allow_unscoped_tokens: bool,
pub allow_insecure_http: bool,
pub accept_static_bearer: bool,
pub allowed_client_ids: Vec<String>,
pub max_token_age_secs: Option<u64>,
pub required_claims: BTreeMap<String, Value>,
pub resource_name: Option<String>,
pub key_naming: KeyNamingBuf,
}Expand description
The validated config an crate::OAuthValidator is built from.
Only OAuthConfig::resolve produces one with every invariant checked, so
holding a ResolvedOAuthConfig (rather than an Option of one) IS the answer
to “is OAuth on and usable” — nothing downstream re-checks a boolean. Fields
are public so tests and applications can adjust a resolved value (the
validator re-checks the invariants whose violation it could not survive: a
non-empty audience set, a non-empty algorithm list, and leeway_secs within
MAX_LEEWAY_SECS).
#[non_exhaustive]: outside this crate one comes from
OAuthConfig::resolve (or, in tests, testing::resolved_config) and is
then adjusted field by field, never built with a struct literal — which is
what lets a new resolved setting be added without a breaking change.
Debug is hand-written and masks a credential in issuer, jwks_uri and
resource the way OAuthConfig’s does.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.issuer: StringSee OAuthConfig::issuer; byte-exact.
jwks_uri: Option<String>None means “discover from the issuer’s metadata”. Never blank.
audience: StringThe single audience; may be empty when audiences is not. Use
ResolvedOAuthConfig::accepted_audiences for the effective set.
audiences: Vec<String>§resource: String§required_scopes: Vec<String>required_scope ∪ required_scopes: trimmed, deduplicated, in config
order (required_scope first). A token must carry every one; empty means
no scope check at all.
scopes_supported: Vec<String>See OAuthConfig::scopes_supported; None there resolves to
required_scopes. Advertised in the metadata document (omitted from it
when empty) and in the 401 challenge.
scope_claims: Vec<String>§principal_claims: Vec<String>§algorithms: Vec<Algorithm>Parsed and deduplicated. Algorithm has no HMAC or none variant,
so this can never hold one.
leeway_secs: u64§require_at_jwt: bool§allow_unscoped_tokens: boolSee OAuthConfig::allow_unscoped_tokens. Informational once
resolved: resolve has already applied it.
allow_insecure_http: boolSee OAuthConfig::allow_insecure_http. resolve has already applied
it to the configured URLs; the validator still reads it, for a
discovered jwks_uri and for redirects followed while fetching keys.
accept_static_bearer: bool§allowed_client_ids: Vec<String>See OAuthConfig::allowed_client_ids; empty means no client check.
max_token_age_secs: Option<u64>See OAuthConfig::max_token_age_secs; None means no age check.
required_claims: BTreeMap<String, Value>See OAuthConfig::required_claims; empty means no claim check.
resource_name: Option<String>Human-readable name published as resource_name in the RFC 9728
metadata document; omitted from it when None. Not a config key:
OAuthConfig::resolve leaves it None, and an application that wants
one sets it on the resolved value (it names the application, which the
operator has no reason to change).
key_naming: KeyNamingBufHow the validator’s log lines and errors name settings; what resolve
was given.
Implementations§
Source§impl ResolvedOAuthConfig
impl ResolvedOAuthConfig
Sourcepub fn accepted_audiences(&self) -> Vec<String>
pub fn accepted_audiences(&self) -> Vec<String>
audience ∪ audiences, blanks dropped, in config order.
Trait Implementations§
Source§impl Clone for ResolvedOAuthConfig
impl Clone for ResolvedOAuthConfig
Source§impl Debug for ResolvedOAuthConfig
Hand-written so a credential in a URL setting never reaches a log line
through {:?}.
impl Debug for ResolvedOAuthConfig
Hand-written so a credential in a URL setting never reaches a log line
through {:?}.