pub struct AccessTokenSubstrateResourceService<'a> { /* private fields */ }Expand description
Cross-mode resource service for verifying bearer tokens and forwarding propagation requests.
§Capabilities
| Method | Description |
|---|---|
authenticate_authorization_header | Verify a bearer token from an Authorization header |
parse_propagation_directive | Extract and parse the propagation directive from request headers |
propagate_request | End-to-end: extract bearer + directive from request, verify, and forward |
propagate_bearer | Low-level: forward a pre-extracted bearer to a downstream target |
§Service pattern
Constructed from ServerState via resource_service() when both
substrate_runtime and oauth_resource_server_verifier are present,
mirroring BackendOidcModeAuthService.
Implementations§
Source§impl<'a> AccessTokenSubstrateResourceService<'a>
impl<'a> AccessTokenSubstrateResourceService<'a>
pub fn new( runtime: &'a AccessTokenSubstrateRuntime, verifier: &'a OAuthResourceServerVerifier, ) -> Self
Verify a bearer token extracted from an Authorization header.
Returns None when the header is absent or not a bearer token.
Sourcepub fn parse_propagation_directive(
headers: &HeaderMap,
) -> Result<Option<PropagationDirective>, AccessTokenSubstrateResourceServiceError>
pub fn parse_propagation_directive( headers: &HeaderMap, ) -> Result<Option<PropagationDirective>, AccessTokenSubstrateResourceServiceError>
Extract and parse a PropagationDirective from request headers.
Returns Ok(None) when the x-securitydept-propagation header is
absent, Ok(Some(directive)) when present and valid, or
PropagationDirectiveInvalid
when the header value is malformed.
Sourcepub async fn propagate_request<F: PropagationForwarder>(
&self,
forwarder: &F,
request: Request<F::Body>,
) -> Result<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
pub async fn propagate_request<F: PropagationForwarder>( &self, forwarder: &F, request: Request<F::Body>, ) -> Result<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
End-to-end propagation: extract, verify, and forward.
- Extracts the bearer token from the
Authorizationheader and verifies it via the configuredOAuthResourceServerVerifier. - Parses the
PropagationDirectivefrom thex-securitydept-propagationheader. - Delegates to
propagate_bearer.
This is the recommended entry-point for propagation route handlers.
Sourcepub async fn propagate_request_with_diagnosis<F: PropagationForwarder>(
&self,
forwarder: &F,
request: Request<F::Body>,
) -> DiagnosedResult<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
pub async fn propagate_request_with_diagnosis<F: PropagationForwarder>( &self, forwarder: &F, request: Request<F::Body>, ) -> DiagnosedResult<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
End-to-end propagation with a machine-readable diagnosis surface.
Sourcepub async fn propagate_bearer<F: PropagationForwarder>(
&self,
forwarder: &F,
bearer: &PropagatedBearer<'_>,
target: &PropagationRequestTarget,
request: Request<F::Body>,
) -> Result<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
pub async fn propagate_bearer<F: PropagationForwarder>( &self, forwarder: &F, bearer: &PropagatedBearer<'_>, target: &PropagationRequestTarget, request: Request<F::Body>, ) -> Result<Response<F::Body>, AccessTokenSubstrateResourceServiceError>
Validate and forward a bearer token to a downstream propagation target.
This is the low-level building block used by
propagate_request. Use it directly when
the bearer and target have already been extracted and verified by the
caller.
Trait Implementations§
Source§impl<'a> Clone for AccessTokenSubstrateResourceService<'a>
impl<'a> Clone for AccessTokenSubstrateResourceService<'a>
Source§fn clone(&self) -> AccessTokenSubstrateResourceService<'a>
fn clone(&self) -> AccessTokenSubstrateResourceService<'a>
1.0.0 · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl<'a> Copy for AccessTokenSubstrateResourceService<'a>
Auto Trait Implementations§
impl<'a> Freeze for AccessTokenSubstrateResourceService<'a>
impl<'a> !RefUnwindSafe for AccessTokenSubstrateResourceService<'a>
impl<'a> Send for AccessTokenSubstrateResourceService<'a>
impl<'a> Sync for AccessTokenSubstrateResourceService<'a>
impl<'a> Unpin for AccessTokenSubstrateResourceService<'a>
impl<'a> UnsafeUnpin for AccessTokenSubstrateResourceService<'a>
impl<'a> !UnwindSafe for AccessTokenSubstrateResourceService<'a>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more