pub struct UpstreamOauthManager { /* private fields */ }Expand description
Upstream OAuth manager for a single upstream MCP server.
Cheap to clone — all mutable state is behind Arc.
Implementations§
Source§impl UpstreamOauthManager
impl UpstreamOauthManager
Sourcepub async fn build_auth_client(
&self,
subject: &str,
) -> Result<AuthClient<Client>, OauthError>
pub async fn build_auth_client( &self, subject: &str, ) -> Result<AuthClient<Client>, OauthError>
Return an AuthClient ready for use, proactively refreshing if near expiry.
Creates a fresh AuthorizationManager backed by stored credentials. Uses
cached AS metadata to avoid an extra HTTP round-trip.
Returns OauthError::NeedsReauth when no credentials are stored or the
refresh token has been revoked.
Sourcepub async fn build_auth_client_with<C>(
&self,
subject: &str,
http_client: C,
) -> Result<AuthClient<C>, OauthError>where
C: StreamableHttpClient,
pub async fn build_auth_client_with<C>(
&self,
subject: &str,
http_client: C,
) -> Result<AuthClient<C>, OauthError>where
C: StreamableHttpClient,
Build an AuthClient<C> wrapping the supplied HTTP client.
Identical to build_auth_client except the caller provides the HTTP
transport, enabling BodyCappedHttpClient or any other
StreamableHttpClient to be used on the OAuth path. The resulting
client is NOT cached — callers that need caching must do so themselves.
Sourcepub async fn refresh_auth_client(&self, subject: &str) -> Result<(), OauthError>
pub async fn refresh_auth_client(&self, subject: &str) -> Result<(), OauthError>
Force a refresh for stored credentials.
AuthorizationManager::get_access_token() only refreshes inside rmcp’s
short refresh buffer. Status checks need an explicit refresh so UI state
cannot report a stale credential row as connected.
Source§impl UpstreamOauthManager
impl UpstreamOauthManager
Sourcepub fn new(
sqlite: SqliteStore,
key: EncryptionKey,
upstream: UpstreamConfig,
redirect_uri: String,
) -> Self
pub fn new( sqlite: SqliteStore, key: EncryptionKey, upstream: UpstreamConfig, redirect_uri: String, ) -> Self
Create a new manager for upstream.
redirect_uri is the absolute URL of the OAuth callback endpoint that will
receive the authorization code (e.g.
https://soma.example/v1/upstream-oauth/{name}/callback).
Sourcepub fn upstream_config(&self) -> &UpstreamConfig
pub fn upstream_config(&self) -> &UpstreamConfig
Return the UpstreamConfig this manager was constructed with.
Used to persist transient (probe-created) managers back into the consumer’s config when authorization completes for the first time.
Sourcepub async fn has_credentials(&self, subject: &str) -> Result<bool, OauthError>
pub async fn has_credentials(&self, subject: &str) -> Result<bool, OauthError>
Return true if persisted credentials exist for subject.
Does not check whether the credentials are still valid.
Begin the authorization flow.
Discovers (or uses cached) AS metadata, registers or configures the OAuth client, generates a PKCE challenge, saves the pending state to SQLite, and returns the authorization URL to redirect the operator’s browser to.
Enforces S256 PKCE — returns OauthError::UnsupportedMethod if the AS does
not advertise S256 in code_challenge_methods_supported.
Complete the authorization callback.
Exchanges the authorization code for tokens and persists the encrypted credentials. Completion is reconstructed from persisted PKCE state rather than an in-memory pending map, so callbacks remain valid across restarts.
Sourcepub async fn clear_credentials(&self, subject: &str) -> Result<(), OauthError>
pub async fn clear_credentials(&self, subject: &str) -> Result<(), OauthError>
Delete all stored credentials for subject and evict any cached state.
pub async fn credential_row( &self, subject: &str, ) -> Result<Option<UpstreamOauthCredentialRow>, OauthError>
pub async fn subject_for_state( &self, csrf_token: &str, ) -> Result<Option<String>, OauthError>
Sourcepub async fn stored_dynamic_client_id(
&self,
subject: &str,
) -> Result<Option<String>, OauthError>
pub async fn stored_dynamic_client_id( &self, subject: &str, ) -> Result<Option<String>, OauthError>
Look up the stored dynamic client_id for subject, if any.
Returns None when the upstream is not Dynamic or when no registration
has been persisted yet. Used by OauthClientCache to include the
per-subject client_id in the fingerprint so a re-registration is
detected and the stale AuthClient is evicted.
Trait Implementations§
Source§impl Clone for UpstreamOauthManager
impl Clone for UpstreamOauthManager
Source§fn clone(&self) -> UpstreamOauthManager
fn clone(&self) -> UpstreamOauthManager
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more