pub struct SigningKeys {
pub key_id: String,
/* private fields */
}Expand description
Local access-token signing keys.
Signs with a single active Ed25519 key (key_id / encoding_key) but
verifies against every key in verifiers — the active key plus, after a
Self::rotate, the immediately previous key. Publishing both in the
JWKS and accepting tokens signed by either gives an overlap window so a
key rotation does not instantly invalidate outstanding access tokens;
the previous key ages out on the next rotation (its still-valid tokens
bounded by the access-token TTL).
Fields§
§key_id: StringImplementations§
Source§impl SigningKeys
impl SigningKeys
Sourcepub fn load_or_create(path: &Path) -> Result<Self, AuthError>
pub fn load_or_create(path: &Path) -> Result<Self, AuthError>
Load the active signing key from path (generating one on first
run), plus the previous key from the sibling <path>.prev slot if a
prior Self::rotate left one there.
Any key material that does not parse as an Ed25519 PKCS#8 DER key —
notably a pre-migration RSA PEM key written by an older release — is
quarantined to <path>.retired-<unix-ts> rather than reused, and a
fresh Ed25519 key is generated in its place. The retired key is never
promoted to a verifier: it is being retired precisely because its
signing path is not the one we trust.
Sourcepub fn rotate(path: &Path) -> Result<Self, AuthError>
pub fn rotate(path: &Path) -> Result<Self, AuthError>
Rotate the signing key while keeping the outgoing key valid for one overlap window.
Moves the current active key into the <path>.prev slot (replacing
any older previous key) and generates a fresh active key at path.
Access tokens signed by the now-previous key keep validating until
their TTL expires, because the returned SigningKeys still carries
the previous key as a verifier and advertises it in the JWKS. The
caller is responsible for swapping the new value in (e.g. replacing
the Arc<SigningKeys> in AuthState).
pub fn issue_access_token( &self, claims: &AccessClaims, ) -> Result<String, AuthError>
Sourcepub fn validate_access_token(
&self,
token: &str,
expected_audience: &str,
) -> Result<AccessClaims, AuthError>
👎Deprecated: Use validate_access_token_with_issuer for RFC 7519 §4.1.1 compliance
pub fn validate_access_token( &self, token: &str, expected_audience: &str, ) -> Result<AccessClaims, AuthError>
Use validate_access_token_with_issuer for RFC 7519 §4.1.1 compliance
Validate access token signature, algorithm, and audience.
NOTE: this method does NOT enforce the iss claim. Callers that
need RFC 7519 issuer validation MUST use
Self::validate_access_token_with_issuer instead. This entry
point is preserved for the lab consumer, which performs its own
post-decode iss check. New consumers should always use the
issuer-enforcing variant.
Sourcepub fn validate_access_token_with_issuer(
&self,
token: &str,
expected_audience: &str,
expected_issuer: &str,
) -> Result<AccessClaims, AuthError>
pub fn validate_access_token_with_issuer( &self, token: &str, expected_audience: &str, expected_issuer: &str, ) -> Result<AccessClaims, AuthError>
Validate signature, algorithm, audience, AND issuer in a single
pass — the issuer is enforced via Validation::set_issuer BEFORE
decode (RFC 7519 §4.1.1 compliant) rather than via a manual
claims.iss != expected check after decode.
The verification key is selected by the token’s kid header, so a
token signed by the previous key during a rotation overlap still
validates.
pub const fn jwks(&self) -> &JwksDocument
Trait Implementations§
Source§impl Clone for SigningKeys
impl Clone for SigningKeys
Source§fn clone(&self) -> SigningKeys
fn clone(&self) -> SigningKeys
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more