#[non_exhaustive]pub enum CredentialSource {
Bearer(HeaderName),
Raw(HeaderName),
}tower only.Expand description
Where a request may carry a credential. Each configured source contributes
at most one candidate — the header’s FIRST value; a request that repeats the
header has the later values ignored, not refused — and every candidate is
checked independently (see crate::authenticate()): a bad credential in
one source never masks a good one in another.
A header value that is not visible ASCII contributes no candidate. Every
configured source header is marked sensitive
(http::HeaderValue::set_sensitive) on the request, before the callback and
the inner service see it, so Debug output and tracing layers print it as
Sensitive.
Used by both layers: HttpAuthLayerBuilder::sources here, and the axum
layer’s AuthLayerBuilder::sources (also reachable as
oauth_resource_server::axum::CredentialSource).
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Bearer(HeaderName)
<header>: Bearer <token> (RFC 6750 §2.1). The scheme is matched
case-insensitively (RFC 9110 §11.1): bearer x is the same credential as
Bearer x. The token is the rest of the value after the first space,
trimmed. Any other scheme contributes no candidate.
Raw(HeaderName)
<header>: <token>: the whole value, verbatim — for an API-key header
such as X-Api-Key.
Implementations§
Source§impl CredentialSource
impl CredentialSource
Authorization: Bearer <token>, the default and only source unless the
layer’s builder is given sources.