Skip to main content

AuthClient

Struct AuthClient 

Source
pub struct AuthClient { /* private fields */ }
Expand description

High-level auth client. Holds a shared reqwest::Client and the resolved client_id; provides device-code sign-in and access-token retrieval (with transparent refresh).

Implementations§

Source§

impl AuthClient

Source

pub fn from_env() -> Result<Self, ClientError>

Construct an AuthClient from compile-time/env configuration.

Errors with ClientError::NotProvisioned if no client_id is available.

Source

pub fn from_env_with_backend( backend: Arc<dyn TokenBackend>, ) -> Result<Self, ClientError>

Like Self::from_env, but tokens are loaded from and saved to backend instead of the CLI’s config-resolved keychain/file store. This is the constructor for hosted consumers such as the MCP server.

Source

pub fn with_backend(self, backend: Arc<dyn TokenBackend>) -> Self

Replace the token backend (builder style). Handy for tests that pair Self::for_test with an in-memory store.

Source

pub fn scope(&self) -> &str

The space-separated Microsoft Graph scope string this client requests.

Source

pub fn client_id(&self) -> &str

The Entra client_id this client authenticates as.

Source

pub async fn store_tokens( &self, email: &str, tokens: &TokenSet, ) -> Result<(), ClientError>

Persist a freshly obtained TokenSet for email through the configured backend. Hosted sign-in flows call this after Self::exchange_code.

Source

pub fn authorize_url( &self, redirect_uri: &str, code_challenge: &str, state: &str, ) -> String

Build the Microsoft /authorize URL for an auth-code + PKCE sign-in whose callback lands on redirect_uri (which must be registered on the Entra app). The caller owns state and the PKCE verifier behind code_challenge; pair with Self::exchange_code.

Source

pub fn authorize_url_with_hint( &self, redirect_uri: &str, code_challenge: &str, state: &str, login_hint: Option<&str>, ) -> String

Self::authorize_url with a login_hint: the address Microsoft preselects in its account picker. The picker is still shown (prompt=select_account), so the user can pick another account; the hint only makes the expected one the obvious choice.

Source

pub async fn exchange_code( &self, code: &str, code_verifier: &str, redirect_uri: &str, ) -> Result<AuthSuccess, ClientError>

Redeem an authorization code delivered to redirect_uri for tokens. Nothing is stored; call Self::store_tokens once the caller has decided which account the tokens belong to.

Source

pub fn for_test( client_id: impl Into<String>, authority_base: impl Into<String>, ) -> Self

Construct an AuthClient against a specific authority, for tests with wiremock.

Source

pub async fn run_browser_flow<F>( &self, on_authorize_url_ready: F, ) -> Result<AuthSuccess, ClientError>
where F: FnOnce(&str),

Run the OAuth 2.0 authorization-code + PKCE sign-in flow with a one-shot localhost HTTP server for the redirect callback.

on_authorize_url_ready receives the constructed /authorize URL once the local listener is bound and the URL is built. The caller is responsible for printing it to the user and (best-effort) opening the browser.

Works for both work/school (M365) and personal (live.com / outlook.com / hotmail.com) Microsoft accounts. Device-code is kept in tree for potential future headless use but no longer the default sign-in path.

Source

pub async fn get_valid_token(&self, email: &str) -> Result<String, ClientError>

Get a valid (un-expired) access token for an email, refreshing if necessary. Returns ClientError::SessionExpired if the refresh fails; the caller should prompt the user to pidge auth login again for that account.

Tokens come from the configured TokenBackend. The default, LocalBackend, resolves the storage backend from the account’s config entry and falls back to the OS keychain if the email has no entry in config.yaml yet (e.g. mid-login).

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more