Skip to main content

Module auth

Module auth 

Source
Expand description

JWT interceptors, validation layer, and re-exports from rust-auth-lib.

Enabled by the auth feature (on by default). See auth for the full list of re-exported types and the two sub-modules it contains: auth::interceptor and auth::layer. Re-exports from rust-auth-lib plus the two gRPC-specific sub-modules.

Everything a consumer needs for JWT auth lives here; a direct dependency on rust-auth-lib is not required.

§Sub-modules

  • [interceptor] — [ClientJwtInterceptor], the outbound client interceptor that attaches Bearer tokens to every outgoing request.
  • [layer] — [JwtValidationLayer] / [JwtValidationService] and the [validator_into_layer] constructor for server-side JWT validation.

§Re-exported items

Traits: [TokenProvider], [TokenValidator], [Claims], [Ephemeral]

Token sources: [FileTokenProvider], [ForwardedToken]

Validators: [KeyValidator], [KeyValidatorConfig]

Errors: [AuthError], [ConfigError], [TokenError]

Claims: [KeycloakClaims]

Free function: [extract_token] — strips the Bearer prefix from an incoming tonic request’s Authorization header and returns a [ForwardedToken].

§Intentionally omitted

  • KeycloakClientCredentialsProvider — requires a live Keycloak token endpoint; use rust-auth-lib directly if needed.

Re-exports§

pub use interceptor::ClientJwtInterceptor;
pub use layer::JwtValidationLayer;
pub use layer::validator_into_layer;

Modules§

interceptor
ClientJwtInterceptor — outbound tonic interceptor that attaches a JWT Authorization: Bearer header to every request by calling a TokenProvider.
layer
Server-side JWT validation layer for tonic gRPC services.

Structs§

FileTokenProvider
Reads a bearer token from a file, caching the result for a configurable TTL.
ForwardedToken
Wraps a raw bearer token string and implements TokenProvider by returning it directly — no I/O, no network calls.
KeyValidator
KeyValidatorConfig
KeycloakClaims
Keycloak-specific JWT claims implementing Claims and Ephemeral.

Enums§

AuthError
ConfigError
TokenError
Errors that can occur when fetching or forwarding a token.

Traits§

Claims
The contract that all JWT claims types must fulfill.
Ephemeral
A value that expires at a known point in time.
TokenProvider
Any source of a bearer token: fetched from an IdP, forwarded from an upstream request, or static (e.g. for testing).
TokenValidator
Validates a raw JWT string and returns decoded claims.

Functions§

extract_token
Construct from the metadata of an incoming tonic request.