Crate tame_oauth

source ยท
Expand description

ยง๐Ÿ” tame-oauth

Embark Embark Crates.io Docs dependency status Build status

tame-oauth is a small oauth crate that follows the sans-io approach.

ยงWhy?

  • You want to control how you actually make oauth HTTP requests

ยงWhy not?

  • The only auth flows that is currently implemented is the service account, user credentials and metadata server flow for GCP. Other flows can be added, but right now GCP is the only provider we need.
  • There are several other oauth crates available that have many more features and are easier to work with, if you donโ€™t care about what HTTP clients they use.
  • This crate requires more boilerplate to use.

ยงFeatures

  • gcp (default) - Support for GCP oauth2
  • wasm-web - Enables wasm features in ring needed for tame-oauth to be used in a wasm browser context. Note this feature should not be used when targeting wasm outside the browser context, in which case you would likely need to target wasm32-wasi.
  • jwt (default) - Support for JSON Web Tokens, required for gcp
  • url (default) - Url parsing, required for gcp

ยงExamples

ยงsvc_account

Usage: cargo run --example svc_account -- <key_path> <scope..>

A small example of using tame-oauth together with reqwest. Given a key file and 1 or more scopes, it will attempt to get a token that could be used to access resources in those scopes.

cargo run --example svc_account -- ~/.secrets/super-sekret.json https://www.googleapis.com/auth/pubsub https://www.googleapis.com/auth/devstorage.read_only

ยงdefault_creds

Usage: cargo run --example default_creds -- <scope..>

Attempts to find and use the default credentials to get a token. Note that scopes are not used in all cases as eg. end user credentials only ever have the cloud platform scope.

cargo run --example default_creds -- https://www.googleapis.com/auth/devstorage.read_only

ยงContributing

Contributor Covenant

We welcome community contributions to this project.

Please read our Contributor Guide for more information on how to get started.

ยงLicense

Licensed under either of

at your option.

ยงContribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

Modulesยง

Structsยง

  • Represents a id token as returned by OAuth2 servers.
  • Represents a access token as returned by OAuth2 servers.

Enumsยง