Skip to main content

JwtValidationLayer

Type Alias JwtValidationLayer 

Source
pub type JwtValidationLayer<C, V> = InterceptorLayer<JwtValidationService<C, V>>;
Expand description

An [InterceptorLayer] that installs JWT validation on a tonic server.

Wrap your tonic server with this layer to enforce that every incoming gRPC request carries a valid Authorization: Bearer <token> header. Requests that fail validation are rejected with [tonic::Code::Unauthenticated] before reaching any handler.

JwtValidationLayer is a type alias for tonic::service::InterceptorLayer<JwtValidationService<V>>. Because it is a type alias, use the free function validator_into_layer to construct it.

§Example

ⓘ
use std::sync::Arc;
use rust_grpc_lib::auth::{
    validator_into_layer, KeycloakClaims, KeyValidator, KeyValidatorConfig,
};

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // Reads AUTH_JWKS_FILE or AUTH_PEM_FILE; optionally AUTH_ISSUER
    let validator = Arc::new(KeyValidator::new(KeyValidatorConfig::from_env()?)?);

    tonic::transport::Server::builder()
        .layer(validator_into_layer::<KeycloakClaims, _>(validator))
        .add_service(MyServiceServer::new(MyService))
        .serve("[::1]:50051".parse()?)
        .await?;

    Ok(())
}

Aliased Type§

pub struct JwtValidationLayer<C, V> { /* private fields */ }