#[non_exhaustive]pub enum AuthError {
Show 13 variants
Expired,
Denied,
Network(Error),
Transport(String),
Protocol(String),
MigrationRequired,
NotAccountOwner {
allowed_roles: String,
},
CapiDisabled,
UnknownAccount {
requested: u64,
available: String,
},
AccountRequired(String),
MfaRequired {
factors: Vec<String>,
},
MfaInvalidCode,
MfaQuotaExceeded,
}Expand description
Errors from the OIDC token-acquisition flows.
Exit-code mapping is applied at the CLI layer in the error-contract work unit; here we only classify the failure.
#[non_exhaustive]: classifying a failure more precisely means a new variant — Transport
below is one, and it is not the last — and this enum is part of the supported redisctl-core
library surface, where an exhaustive downstream match would make each of those a major
release. Match a wildcard arm and treat it as an unclassified failure.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Expired
The device/authorization code expired before the user approved (expired_token).
Denied
The user denied the authorization request (access_denied).
Network(Error)
Network/transport failure talking to the SM API.
Transport(String)
The same failure from an oauth2 flow, which runs on that crate’s own HTTP stack and so
produces an error type AuthError::Network cannot hold. Carried separately rather than
folded into AuthError::Protocol: a request that never arrived says nothing about the
credentials, and is worth retrying.
Protocol(String)
The identity provider returned something unexpected or unparseable.
MigrationRequired
The Redis Cloud account still authenticates with a password and has not been linked to a social/SSO identity, so the token exchange cannot complete. Linking is a one-time step the user performs in the Redis Cloud console.
NotAccountOwner
The signed-in user’s role on the account does not permit programmatic (CAPI) access, so
the login cannot mint a key. A one-time step for someone who does hold the role, not a
retryable failure. allowed_roles is what SM reported as sufficient, already formatted.
CapiDisabled
The account itself has API access switched off, so no role can mint a key. Only Redis can turn it back on — it is not exposed to account owners.
UnknownAccount
--account named an account the signed-in user does not belong to. Carries what they do
have, so the caller can list the options instead of just refusing.
AccountRequired(String)
No usable account choice: none was given where one is required, or the caller gave up. A precondition for the caller to fix, not a backend failure.
MfaRequired
SM challenged the login for multi-factor authentication (user-mfa-required). Carries the
factor types SM offered, when it reports them.
MfaInvalidCode
The submitted MFA code was rejected (mfa-invalid-code).
MfaQuotaExceeded
Too many MFA attempts (mfa-quota-exceeded); retrying now will not help.
Trait Implementations§
Source§impl Error for AuthError
impl Error for AuthError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Auto Trait Implementations§
impl !RefUnwindSafe for AuthError
impl !UnwindSafe for AuthError
impl Freeze for AuthError
impl Send for AuthError
impl Sync for AuthError
impl Unpin for AuthError
impl UnsafeUnpin for AuthError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> ToStringFallible for Twhere
T: Display,
impl<T> ToStringFallible for Twhere
T: Display,
Source§fn try_to_string(&self) -> Result<String, TryReserveError>
fn try_to_string(&self) -> Result<String, TryReserveError>
ToString::to_string, but without panic on OOM.