Skip to main content

Module auth

Module auth 

Source
Expand description

OAuth browser-based sign-in (auth-code + PKCE), token refresh, and credential storage.

Re-exports§

pub use browser_flow::AuthSuccess;

Modules§

browser_flow
OAuth 2.0 authorization code + PKCE flow with a one-shot local HTTP server.
config
Compile-time constants and runtime overrides for the pidge OAuth app.
device_code
RFC 8628 OAuth 2.0 device authorization grant flow.
refresh
OAuth refresh-token grant.

Structs§

AuthClient
High-level auth client. Holds a shared reqwest::Client and the resolved client_id; provides device-code sign-in and access-token retrieval (with transparent refresh).
FileStore
IdTokenClaims
The immutable identity of a Microsoft account, from its ID token: the tenant (tid) and the account’s object id within it (oid). Unlike the profile’s mail or userPrincipalName, these can’t be edited to look like another account.
KeychainStore
LocalBackend
The CLI’s backend: consults config.yaml for the account’s TokenStorage and dispatches to the keychain or file store.
TokenSet
A user’s OAuth tokens for one account.
TokenStore

Traits§

TokenBackend
Where an account’s TokenSet is loaded from and saved to.

Functions§

extract_id_claims
Extract tid and oid from an ID token. None if the JWT is malformed or either claim is missing or empty. The signature is not verified (see the module docs): only use this on a token just received from Microsoft’s token endpoint over TLS.
extract_tenant_id
Extract the tid claim from a JWT. Returns None if the JWT is malformed or if tid is missing.