Skip to main content

FakePasServer

Struct FakePasServer 

Source
pub struct FakePasServer { /* private fields */ }
Expand description

Wiremock-wrapped fake PAS Authorization Server.

Self::start constructs the server, generates an ed25519 keypair, and mounts the discovery + JWKS routes. The returned Self::issuer_url is the value to pass into oidc::Config::new’s issuer parameter so that crate::oidc::RelyingParty::new’s discovery + JWKS fetches resolve here.

Token-endpoint expectations are configured per-test via Self::expect_token_exchange and Self::reject_next_token_exchange.

Implementations§

Source§

impl FakePasServer

Source

pub async fn start() -> Self

Start a fresh fake PAS server. Mounts the discovery + JWKS routes immediately; the token endpoint stays unmounted until a test calls Self::expect_token_exchange or Self::reject_next_token_exchange.

Source

pub async fn start_without_end_session() -> Self

Start a fake PAS whose discovery document omits end_session_endpoint — models an OP that does not support OIDC RP-Initiated Logout, so crate::oidc::RelyingParty::end_session_url returns crate::oidc::EndSessionError::NotSupported.

Source

pub fn issuer_url(&self) -> Url

Issuer URL — pass to oidc::Config::new(client_id, redirect_uri, issuer).

Source

pub fn token_url(&self) -> Url

Token endpoint URL (<issuer>/oauth/token).

Source

pub fn jwks_url(&self) -> Url

JWKS URL (<issuer>/.well-known/jwks.json).

Source

pub fn sign_id_token<S: ScopeSet>( &self, request: &IssueRequest<S>, config: &IssueConfig, ) -> Result<String, IssueError>

Sign an id_token with the fake server’s signing key.

The resulting JWT is verifiable by any crate::oidc::RelyingParty::new-bootstrapped RP that fetched JWKS from this server.

Source

pub fn sign_access_token( &self, issuer: &str, audience: &str, request: &IssueRequest, ) -> Result<String, IssueError>

Sign an RFC 9068 access token with the fake server’s signing key, pinning kid from the key — mirror of PAS’s encode_access_token. The result verifies against any crate::oidc::RelyingParty::access_token_verifier-built verifier that fetched JWKS from this server, as long as issuer + audience match its expectations.

issuer is used verbatim — the caller chooses the form: pass the bare issuer (issuer_url().as_str().trim_end_matches('/')) for a token the perimeter accepts, or the trailing-slash form to exercise the engine’s exact-iss reject (M23). This is what lets a boundary test prove the access_token_verifier trailing-slash trim end-to-end.

Source

pub async fn expect_token_exchange(&self, body: TokenExchangeBody)

Mount a one-shot mock for POST /oauth/token returning body as 200 JSON. Multiple calls stack; each is consumed once in the order they were configured.

Source

pub async fn reject_next_token_exchange( &self, status: u16, body: impl Into<String>, )

Mount a one-shot mock for POST /oauth/token returning the given HTTP status + plaintext body (typical for testing 4xx rejection or 5xx server-error paths).

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more