Struct KeycloakClaims
pub struct KeycloakClaims { /* private fields */ }Expand description
Keycloak-specific JWT claims implementing Claims and Ephemeral.
Standard JWT fields are accessible via the Claims trait methods
(sub, iat, iss, preferred_username) and the Ephemeral trait
(exp_unix, is_expired). Keycloak-specific role checks are available
directly on this struct.
use rust_auth_lib::{KeyValidator, KeyValidatorConfig, TokenValidator, keycloak::KeycloakClaims};
let validator = KeyValidator::new(KeyValidatorConfig::from_env()?)?;
let claims = validator.validate::<KeycloakClaims>(token)?;
println!("subject: {}", claims.sub());
println!("expires at unix: {}", claims.exp_unix());
if claims.has_role("operator") { /* authorized */ }Implementations§
§impl KeycloakClaims
impl KeycloakClaims
pub fn has_role(&self, role: &str) -> bool
pub fn has_role(&self, role: &str) -> bool
Returns true if the token carries the given realm-level role.
Realm-level roles apply across all clients in the Keycloak realm and are
stored in the realm_access.roles claim. For roles scoped to a specific
OAuth2 client, use has_client_role instead.
pub fn has_client_role(&self, client_id: &str, role: &str) -> bool
pub fn has_client_role(&self, client_id: &str, role: &str) -> bool
Returns true if the token carries the given role scoped to a specific OAuth2 client.
pub fn roles(&self) -> &[String]
pub fn roles(&self) -> &[String]
Returns all realm-level roles carried by this token, or an empty slice if none.
For a single-role membership check, prefer has_role.
Use this method when you need to enumerate, log, or forward the full role list.
pub fn client_roles(&self, client_id: &str) -> &[String]
pub fn client_roles(&self, client_id: &str) -> &[String]
Returns all roles scoped to a specific OAuth2 client, or an empty slice if none.
For a single-role membership check, prefer has_client_role.
Use this method when you need to enumerate, log, or forward the full role list for
a given client.
Trait Implementations§
§impl Claims for KeycloakClaims
impl Claims for KeycloakClaims
§fn sub(&self) -> &str
fn sub(&self) -> &str
sub claim) — identifies who the token
represents, typically a user ID or service account identifier.§fn iss(&self) -> Option<&str>
fn iss(&self) -> Option<&str>
iss claim), or None if the claim is
absent. Used to verify the token came from the expected identity
provider.§fn preferred_username(&self) -> Option<&str>
fn preferred_username(&self) -> Option<&str>
preferred_username OIDC claim,
or None if the claim is absent. Not present in all token types —
machine-to-machine tokens typically omit it.§impl Clone for KeycloakClaims
impl Clone for KeycloakClaims
§fn clone(&self) -> KeycloakClaims
fn clone(&self) -> KeycloakClaims
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more§impl Debug for KeycloakClaims
impl Debug for KeycloakClaims
§impl<'de> Deserialize<'de> for KeycloakClaims
impl<'de> Deserialize<'de> for KeycloakClaims
§fn deserialize<__D>(
__deserializer: __D,
) -> Result<KeycloakClaims, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(
__deserializer: __D,
) -> Result<KeycloakClaims, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for KeycloakClaims
impl RefUnwindSafe for KeycloakClaims
impl Send for KeycloakClaims
impl Sync for KeycloakClaims
impl Unpin for KeycloakClaims
impl UnsafeUnpin for KeycloakClaims
impl UnwindSafe for KeycloakClaims
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request§impl<L> LayerExt<L> for L
impl<L> LayerExt<L> for L
§fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
fn named_layer<S>(&self, service: S) -> Layered<<L as Layer<S>>::Service, S>where
L: Layer<S>,
Layered].