Skip to main content

OauthClientCache

Struct OauthClientCache 

Source
pub struct OauthClientCache { /* private fields */ }

Implementations§

Source§

impl OauthClientCache

Source

pub fn new(managers: Arc<DashMap<String, UpstreamOauthManager>>) -> Self

Create a new cache backed by the gateway’s OAuth manager map.

Source

pub async fn get_or_build( &self, config: &UpstreamConfig, subject: &str, ) -> Result<Arc<AuthClient<Client>>, OauthError>

Return a cached AuthClient<reqwest::Client> for (upstream, subject), building one on first use.

Kept for callers that need a shared Arc<AuthClient<reqwest::Client>> (e.g. status-check endpoints). The MCP connection path uses get_or_build_capped instead so the BodyCappedHttpClient cap applies.

If a cached entry exists but was built from a different OAuth registration than the current config, the entry is evicted and rebuilt so stale client_ids never sign requests.

For Dynamic upstreams the fingerprint includes the stored client_id (fetched from SQLite via the upstream manager) so a re-registration cycle evicts the cached AuthClient.

Concurrent first-request callers for the same key are serialised by a per-key mutex so only one token exchange runs.

Source

pub async fn get_or_build_capped<C>( &self, config: &UpstreamConfig, subject: &str, http_client: C, ) -> Result<AuthClient<C>, OauthError>
where C: StreamableHttpClient + Clone,

Build an AuthClient<C> wrapping the supplied HTTP client and return it WITHOUT caching it.

Entry point for callers that manage their own per-connection cache and need to pass a pre-built HTTP client (e.g. one with a response-size cap) so the OAuth path gets identical transport behavior to the non-OAuth path. The caller is responsible for caching the resulting AuthClient at whatever level it owns, so there is no double-caching here.

Source

pub fn evict_subject(&self, upstream: &str, subject: &str)

Evict the entry for a single (upstream, subject) pair.

Used by API handlers when credentials are cleared or when a refresh fails terminally and the next request must reauthenticate.

Source

pub fn evict_upstream(&self, upstream: &str)

Evict every entry for upstream.

Used at config reload when an upstream is removed or its OAuth registration changes, and when the whole server shuts down the upstream’s sessions.

Source

pub fn evict_upstreams_not_in(&self, known: &HashSet<&str>)

Evict every entry whose upstream is not in known.

Used at config reload to drop cached clients for upstreams that no longer exist in config.

Source

pub fn len(&self) -> usize

Number of cached clients. Intended for tests and observability.

Source

pub fn is_empty(&self) -> bool

True when the cache holds no clients.

Source

pub fn insert_for_tests( &self, upstream: &str, subject: &str, fingerprint: &str, client: Arc<AuthClient<Client>>, )

Insert a pre-built AuthClient directly into the cache.

Test-only seam: available in labby-auth’s own tests and downstream debug test builds. It is intentionally not gated by a Cargo feature so --all-features --release cannot expose it in production artifacts.

Trait Implementations§

Source§

impl Clone for OauthClientCache

Source§

fn clone(&self) -> OauthClientCache

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> FromRef<T> for T
where T: Clone,

§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,