Expand description
OAuth browser-based sign-in (auth-code + PKCE), token refresh, and credential storage.
Re-exports§
pub use browser_flow::AuthSuccess;
Modules§
- browser_
flow - OAuth 2.0 authorization code + PKCE flow with a one-shot local HTTP server.
- config
- Compile-time constants and runtime overrides for the pidge OAuth app.
- device_
code - RFC 8628 OAuth 2.0 device authorization grant flow.
- refresh
- OAuth refresh-token grant.
Structs§
- Auth
Client - High-level auth client. Holds a shared
reqwest::Clientand the resolvedclient_id; provides device-code sign-in and access-token retrieval (with transparent refresh). - File
Store - IdToken
Claims - The immutable identity of a Microsoft account, from its ID token: the
tenant (
tid) and the account’s object id within it (oid). Unlike the profile’smailoruserPrincipalName, these can’t be edited to look like another account. - Keychain
Store - Local
Backend - The CLI’s backend: consults
config.yamlfor the account’sTokenStorageand dispatches to the keychain or file store. - Token
Set - A user’s OAuth tokens for one account.
- Token
Store
Traits§
- Token
Backend - Where an account’s
TokenSetis loaded from and saved to.
Functions§
- extract_
id_ claims - Extract
tidandoidfrom an ID token.Noneif the JWT is malformed or either claim is missing or empty. The signature is not verified (see the module docs): only use this on a token just received from Microsoft’s token endpoint over TLS. - extract_
tenant_ id - Extract the
tidclaim from a JWT. ReturnsNoneif the JWT is malformed or iftidis missing.