pub struct AuthClient { /* private fields */ }Expand description
High-level auth client. Holds a shared reqwest::Client and the resolved
client_id; provides device-code sign-in and access-token retrieval (with
transparent refresh).
Implementations§
Source§impl AuthClient
impl AuthClient
Sourcepub fn from_env() -> Result<Self, ClientError>
pub fn from_env() -> Result<Self, ClientError>
Construct an AuthClient from compile-time/env configuration.
Errors with ClientError::NotProvisioned if no client_id is available.
Sourcepub fn for_test(
client_id: impl Into<String>,
authority_base: impl Into<String>,
) -> Self
pub fn for_test( client_id: impl Into<String>, authority_base: impl Into<String>, ) -> Self
Construct an AuthClient against a specific authority — for tests with wiremock.
Sourcepub async fn start_device_code(&self) -> Result<DeviceCodeResponse, ClientError>
pub async fn start_device_code(&self) -> Result<DeviceCodeResponse, ClientError>
Run the device code flow. Returns the device code response immediately;
caller is expected to display the user code and call poll_for_tokens.
Sourcepub async fn poll_for_tokens(
&self,
device_code_resp: &DeviceCodeResponse,
) -> Result<PollSuccess, ClientError>
pub async fn poll_for_tokens( &self, device_code_resp: &DeviceCodeResponse, ) -> Result<PollSuccess, ClientError>
Poll for tokens after start_device_code. Blocks until success or terminal error.
Sourcepub async fn get_valid_token(&self, email: &str) -> Result<String, ClientError>
pub async fn get_valid_token(&self, email: &str) -> Result<String, ClientError>
Get a valid (un-expired) access token for an email, refreshing if necessary.
Returns ClientError::SessionExpired if the refresh fails — caller should
prompt the user to pidge auth login again for that account.
The token storage backend is resolved from the account’s config entry; if
the email has no entry in config.yaml yet (e.g. mid-login) we fall back
to the OS keychain.