Skip to main content

AuthError

Enum AuthError 

Source
#[non_exhaustive]
pub enum AuthError {
Show 13 variants Expired, Denied, Network(Error), Transport(String), Protocol(String), MigrationRequired, NotAccountOwner { allowed_roles: String, }, CapiDisabled, UnknownAccount { requested: u64, available: String, }, AccountRequired(String), MfaRequired { factors: Vec<String>, }, MfaInvalidCode, MfaQuotaExceeded,
}
Expand description

Errors from the OIDC token-acquisition flows.

Exit-code mapping is applied at the CLI layer in the error-contract work unit; here we only classify the failure.

#[non_exhaustive]: classifying a failure more precisely means a new variant — Transport below is one, and it is not the last — and this enum is part of the supported redisctl-core library surface, where an exhaustive downstream match would make each of those a major release. Match a wildcard arm and treat it as an unclassified failure.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

Expired

The device/authorization code expired before the user approved (expired_token).

§

Denied

The user denied the authorization request (access_denied).

§

Network(Error)

Network/transport failure talking to the SM API.

§

Transport(String)

The same failure from an oauth2 flow, which runs on that crate’s own HTTP stack and so produces an error type AuthError::Network cannot hold. Carried separately rather than folded into AuthError::Protocol: a request that never arrived says nothing about the credentials, and is worth retrying.

§

Protocol(String)

The identity provider returned something unexpected or unparseable.

§

MigrationRequired

The Redis Cloud account still authenticates with a password and has not been linked to a social/SSO identity, so the token exchange cannot complete. Linking is a one-time step the user performs in the Redis Cloud console.

§

NotAccountOwner

The signed-in user’s role on the account does not permit programmatic (CAPI) access, so the login cannot mint a key. A one-time step for someone who does hold the role, not a retryable failure. allowed_roles is what SM reported as sufficient, already formatted.

Fields

§allowed_roles: String
§

CapiDisabled

The account itself has API access switched off, so no role can mint a key. Only Redis can turn it back on — it is not exposed to account owners.

§

UnknownAccount

--account named an account the signed-in user does not belong to. Carries what they do have, so the caller can list the options instead of just refusing.

Fields

§requested: u64
§available: String
§

AccountRequired(String)

No usable account choice: none was given where one is required, or the caller gave up. A precondition for the caller to fix, not a backend failure.

§

MfaRequired

SM challenged the login for multi-factor authentication (user-mfa-required). Carries the factor types SM offered, when it reports them.

Fields

§factors: Vec<String>
§

MfaInvalidCode

The submitted MFA code was rejected (mfa-invalid-code).

§

MfaQuotaExceeded

Too many MFA attempts (mfa-quota-exceeded); retrying now will not help.

Trait Implementations§

Source§

impl Debug for AuthError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for AuthError

Source§

fn fmt(&self, __formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Error for AuthError

Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl From<Error> for AuthError

Source§

fn from(source: Error) -> Self

Converts to this type from the input type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T> ToStringFallible for T
where T: Display,

Source§

fn try_to_string(&self) -> Result<String, TryReserveError>

ToString::to_string, but without panic on OOM.

Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more