pub struct AuthClient { /* private fields */ }Expand description
High-level auth client. Holds a shared reqwest::Client and the resolved
client_id; provides device-code sign-in and access-token retrieval (with
transparent refresh).
Implementations§
Source§impl AuthClient
impl AuthClient
Sourcepub fn from_env() -> Result<Self, ClientError>
pub fn from_env() -> Result<Self, ClientError>
Construct an AuthClient from compile-time/env configuration.
Errors with ClientError::NotProvisioned if no client_id is available.
Sourcepub fn for_test(
client_id: impl Into<String>,
authority_base: impl Into<String>,
) -> Self
pub fn for_test( client_id: impl Into<String>, authority_base: impl Into<String>, ) -> Self
Construct an AuthClient against a specific authority — for tests with wiremock.
Sourcepub async fn run_browser_flow<F>(
&self,
on_authorize_url_ready: F,
) -> Result<AuthSuccess, ClientError>
pub async fn run_browser_flow<F>( &self, on_authorize_url_ready: F, ) -> Result<AuthSuccess, ClientError>
Run the OAuth 2.0 authorization-code + PKCE sign-in flow with a one-shot localhost HTTP server for the redirect callback.
on_authorize_url_ready receives the constructed /authorize URL
once the local listener is bound and the URL is built — the caller
is responsible for printing it to the user and (best-effort) opening
the browser.
Works for both work/school (M365) and personal (live.com / outlook.com / hotmail.com) Microsoft accounts. Device-code is kept in tree for potential future headless use but no longer the default sign-in path.
Sourcepub async fn get_valid_token(&self, email: &str) -> Result<String, ClientError>
pub async fn get_valid_token(&self, email: &str) -> Result<String, ClientError>
Get a valid (un-expired) access token for an email, refreshing if necessary.
Returns ClientError::SessionExpired if the refresh fails — caller should
prompt the user to pidge auth login again for that account.
The token storage backend is resolved from the account’s config entry; if
the email has no entry in config.yaml yet (e.g. mid-login) we fall back
to the OS keychain.