Expand description
JWT interceptors, validation layer, and re-exports from rust-auth-lib.
Enabled by the auth feature (on by default). See auth for the full
list of re-exported types and the two sub-modules it contains:
auth::interceptor and auth::layer.
Re-exports from rust-auth-lib plus the two gRPC-specific sub-modules.
Everything a consumer needs for JWT auth lives here; a direct dependency on
rust-auth-lib is not required.
§Sub-modules
- [
interceptor] — [ClientJwtInterceptor], the outbound client interceptor that attachesBearertokens to every outgoing request. - [
layer] — [JwtValidationLayer] / [JwtValidationService] and the [validator_into_layer] constructor for server-side JWT validation.
§Re-exported items
Traits: [TokenProvider], [TokenValidator], [Claims], [Ephemeral]
Token sources: [FileTokenProvider], [ForwardedToken]
Validators: [KeyValidator], [KeyValidatorConfig]
Errors: [AuthError], [ConfigError], [TokenError]
Claims: [KeycloakClaims]
Free function: [extract_token] — strips the Bearer prefix from an
incoming tonic request’s Authorization header and returns a
[ForwardedToken].
§Intentionally omitted
KeycloakClientCredentialsProvider— requires a live Keycloak token endpoint; userust-auth-libdirectly if needed.
Re-exports§
pub use interceptor::ClientJwtInterceptor;pub use layer::JwtValidationLayer;pub use layer::validator_into_layer;
Modules§
- interceptor
ClientJwtInterceptor— outbound tonic interceptor that attaches a JWTAuthorization: Bearerheader to every request by calling aTokenProvider.- layer
- Server-side JWT validation layer for tonic gRPC services.
Structs§
- File
Token Provider - Reads a bearer token from a file, caching the result for a configurable TTL.
- Forwarded
Token - Wraps a raw bearer token string and implements
TokenProviderby returning it directly — no I/O, no network calls. - KeyValidator
- KeyValidator
Config - Keycloak
Claims - Keycloak-specific JWT claims implementing
ClaimsandEphemeral.
Enums§
- Auth
Error - Config
Error - Token
Error - Errors that can occur when fetching or forwarding a token.
Traits§
- Claims
- The contract that all JWT claims types must fulfill.
- Ephemeral
- A value that expires at a known point in time.
- Token
Provider - Any source of a bearer token: fetched from an IdP, forwarded from an upstream request, or static (e.g. for testing).
- Token
Validator - Validates a raw JWT string and returns decoded claims.
Functions§
- extract_
token - Construct from the metadata of an incoming tonic request.