Skip to main content

InvalidTokenKind

Enum InvalidTokenKind 

Source
#[non_exhaustive]
pub enum InvalidTokenKind {
Show 25 variants TooLarge, NotJwt, MalformedHeader, CriticalHeader, AlgorithmNotAllowed, TypeNotAllowed, KeyNotFound, KeySetUnavailable, MalformedToken, BadSignature, Expired, NotYetValid, WrongIssuer, WrongAudience, MissingClaim, MalformedClaim, SenderConstrained, ClientNotAllowed, TokenTooOld, ClaimMismatch, StaticTokenMismatch, NoMechanism, OAuthTokenRequired, StaticTokenRequired, Other,
}
Expand description

Which check refused a token — see InvalidToken::kind.

Each kind names one family of checks, and as_str gives it a stable, low-cardinality snake_case label for metrics and alerting (for example, KeySetUnavailable is an authorization-server outage, not junk traffic). Every kind is a 401 invalid_token; the kind changes nothing about the response.

#[non_exhaustive]: a kind may be added in a minor release, so match with a wildcard arm. Which kind an existing refusal carries, and each kind’s label, are stable; the InvalidToken::detail text is not.

§Examples

use oauth_resource_server::{InvalidToken, InvalidTokenKind};

/// Whether a refusal points at the authorization server rather than at the
/// caller — worth an alert of its own.
fn is_idp_trouble(invalid: &InvalidToken) -> bool {
    match invalid.kind() {
        InvalidTokenKind::KeySetUnavailable => true,
        InvalidTokenKind::Expired | InvalidTokenKind::BadSignature => false,
        _ => false,
    }
}

let outage = InvalidToken::new(InvalidTokenKind::KeySetUnavailable, "JWKS refresh failed");
assert!(is_idp_trouble(&outage));
assert_eq!(outage.kind().as_str(), "key_set_unavailable");

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

TooLarge

The credential is over the 16 KiB cap; refused before it is decoded.

§

NotJwt

The credential is not three dot-separated segments: a mistyped static token, or an opaque (non-JWT) access token.

§

MalformedHeader

The JWS protected header is not a base64url JSON object this crate can read (including an alg it does not know at all, such as none).

§

CriticalHeader

The header lists critical extensions (crit, RFC 7515 §4.1.11), none of which this crate supports.

§

AlgorithmNotAllowed

The header’s alg is not in the configured allowlist.

§

TypeNotAllowed

The header’s typ is not an access-token type (or is absent or JWT while require_at_jwt is on).

§

KeyNotFound

No held key matches the token’s kid and alg while the key set is healthy: not in it even after a refetch, or unknown while the unknown-kid refetch cooldown runs and the last refresh succeeded.

§

KeySetUnavailable

The key set could not be loaded: discovery or the JWKS fetch failed, including during the refetch cooldown when the last refresh failed or no key is held at all. An authorization-server (or network) outage, not the caller’s fault.

§

MalformedToken

The header checks passed but the rest does not decode: the payload is not base64url JSON (an object), or the signature is not base64url.

§

BadSignature

The signature does not verify with the selected key (or the key could not be used to verify it).

§

Expired

exp is in the past (beyond the configured leeway).

§

NotYetValid

nbf is in the future (beyond the configured leeway), or, with max_token_age_secs set, iat is.

§

WrongIssuer

iss is not exactly the configured issuer (including an iss array).

§

WrongAudience

No aud entry is an accepted audience.

§

MissingClaim

A claim the checks need is absent: exp, iss or aud; iat with max_token_age_secs set; a required_claims entry.

§

MalformedClaim

A claim the checks need is present but unreadable: an exp, iss or aud of the wrong type, an nbf (or, with max_token_age_secs set, an iat) that is not a NumericDate.

§

SenderConstrained

The token carries cnf (a DPoP or mTLS sender constraint), which this crate cannot verify and so refuses as a bearer token.

§

ClientNotAllowed

allowed_client_ids is set and the token’s client (client_id, else azp) is absent or not listed.

§

TokenTooOld

max_token_age_secs is set and the token was issued (iat) longer ago than that, plus the leeway.

§

ClaimMismatch

A required_claims entry is present in the token with another value (and, for an array claim, not among its elements).

§

StaticTokenMismatch

Only static tokens are configured (no OAuth validator) and no credential is one of them.

§

NoMechanism

Neither a static token nor an OAuth validator is configured.

§

OAuthTokenRequired

A credential was accepted, but the handler needs an OAuth access token (the axum AuthorizedToken extractor) and got a static token.

§

StaticTokenRequired

A credential was accepted, but the handler needs a static token (the axum StaticTokenMatch extractor) and got an OAuth access token.

§

Other

Anything else: every InvalidToken built from a String or &str, and a decoder failure this crate cannot classify more precisely.

Implementations§

Source§

impl InvalidTokenKind

Source

pub fn as_str(self) -> &'static str

A stable, lowercase snake_case label ("expired", "bad_signature", "key_set_unavailable", …), for a metrics label or a log field. It does not change between releases for an existing kind.

Trait Implementations§

Source§

impl Clone for InvalidTokenKind

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for InvalidTokenKind

Source§

impl Debug for InvalidTokenKind

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for InvalidTokenKind

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for InvalidTokenKind

Source§

impl Hash for InvalidTokenKind

Source§

fn hash<__H: Hasher>(&self, state: &mut __H)

Feeds this value into the given Hasher. Read more
1.3.0 · Source§

fn hash_slice<H>(data: &[Self], state: &mut H)
where H: Hasher, Self: Sized,

Feeds a slice of this type into the given Hasher. Read more
Source§

impl PartialEq for InvalidTokenKind

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for InvalidTokenKind

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more