pub struct DeviceFlowClient { /* private fields */ }Expand description
Device-authorization-grant client bound to one Okta issuer + public client id.
Cheap to construct and holds no network state, so status --wait can rebuild it from the
persisted issuer + client id to resume a login started by an earlier login --device.
Implementations§
Source§impl DeviceFlowClient
impl DeviceFlowClient
Sourcepub fn new(issuer: Url, client_id: impl Into<String>) -> Self
pub fn new(issuer: Url, client_id: impl Into<String>) -> Self
Build a client for the given issuer (e.g.
https://<your-okta-issuer>/oauth2/default) and public client id.
Sourcepub async fn start(
&self,
scopes: &[&str],
) -> Result<DeviceAuthorization, AuthError>
pub async fn start( &self, scopes: &[&str], ) -> Result<DeviceAuthorization, AuthError>
Start device authorization: POST /v1/device/authorize.
Returns the codes to display and the device code needed to resume polling — persist the
returned DeviceAuthorization and hand it to poll later.
Sourcepub async fn poll(
&self,
authz: &DeviceAuthorization,
timeout: Option<Duration>,
) -> Result<TokenSet, AuthError>
pub async fn poll( &self, authz: &DeviceAuthorization, timeout: Option<Duration>, ) -> Result<TokenSet, AuthError>
Poll the token endpoint until the user approves, the code is denied/expires, or timeout
elapses. The oauth2 crate runs the loop internally (respecting the server’s poll
interval and slow_down), so this is a single blocking call.
timeout bounds the whole wait; None falls back to the device code’s own lifetime. A
timeout surfaces as AuthError::Expired. Callable from a freshly built client after
deserializing authz.