pub struct AuthManager { /* private fields */ }Expand description
Manages OIDC discovery, token exchange, and the DPoP flow.
Implementations§
Source§impl AuthManager
impl AuthManager
Sourcepub async fn discover(
oidc_config: OidcConfig,
resource: String,
vault: Vault,
resource_metadata_url: Option<&str>,
) -> Result<Self>
pub async fn discover( oidc_config: OidcConfig, resource: String, vault: Vault, resource_metadata_url: Option<&str>, ) -> Result<Self>
Resolves the authorization server endpoints for resource.
resource_metadata_url is the (already validated) RFC 9728 metadata URL
taken from a WWW-Authenticate challenge, if any.
Sourcepub async fn set_internal_url_tx(&self, tx: Sender<String>)
pub async fn set_internal_url_tx(&self, tx: Sender<String>)
Delivers the next authorization URL to tx instead of opening a
browser (for automation and tests).
Sourcepub async fn set_internal_callback_tx(&self, tx: Sender<SocketAddr>)
pub async fn set_internal_callback_tx(&self, tx: Sender<SocketAddr>)
Reports the address the next loopback callback server binds to.
Sourcepub async fn reauthenticate(
&self,
user_id: &str,
scopes: Option<Vec<String>>,
url_tx: Option<Sender<String>>,
) -> Result<()>
pub async fn reauthenticate( &self, user_id: &str, scopes: Option<Vec<String>>, url_tx: Option<Sender<String>>, ) -> Result<()>
Full re-authentication flow: PAR -> Loopback Callback -> Token Exchange
Sourcepub async fn refresh(&self, user_id: &str) -> Result<bool>
pub async fn refresh(&self, user_id: &str) -> Result<bool>
Renews the access token with the stored refresh token (RFC 6749 §6), without user interaction.
Returns Ok(false) when there is nothing to refresh with or the
authorization server rejects the refresh token (which is then deleted),
so the caller can fall back to the interactive flow.
Sourcepub fn enforce_issuer_binding(&self, user_id: &str) -> Result<()>
pub fn enforce_issuer_binding(&self, user_id: &str) -> Result<()>
Discards stored credentials issued by a different authorization server than the one discovered now. Credentials are bound to their issuer.
Trait Implementations§
Source§impl Clone for AuthManager
impl Clone for AuthManager
Source§fn clone(&self) -> AuthManager
fn clone(&self) -> AuthManager
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more