Skip to main content

IdentityError

Enum IdentityError 

Source
#[non_exhaustive]
pub enum IdentityError {
Show 15 variants Malformed(String), MissingKid, UnknownKid(String), AlgorithmRejected { alg: String, kid: String, }, Verification(String), TtlTooLong(u64), BadTimestamps { iat: u64, exp: u64, }, FutureIat { iat: u64, now: u64, }, EmptyField(&'static str), SpoofingCharacter(&'static str), BadIssuer(String), Jwks(String), ScopeEscalation { scope: String, }, ExpEscalation { child: u64, parent: u64, }, ChainTooDeep(usize),
}
Expand description

Identity validation failures.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

Malformed(String)

Token structurally malformed.

§

MissingKid

Header lacks a kid.

§

UnknownKid(String)

No key registered for this kid.

§

AlgorithmRejected

Token alg is not accepted, or does not match the key type for its kid (algorithm-confusion defense).

Fields

§alg: String

Stated algorithm.

§kid: String

Key id.

§

Verification(String)

Signature invalid / expired / nbf future / wrong audience — collapsed by jsonwebtoken; the detail string preserves the cause.

§

TtlTooLong(u64)

exp - iat exceeds the 15-minute NHI cap.

§

BadTimestamps

exp ≤ iat or other timestamp nonsense.

Fields

§iat: u64

Issued-at.

§exp: u64

Expiry.

§

FutureIat

iat is unreasonably far in the future.

Fields

§iat: u64

Issued-at claim.

§now: u64

Validator wall clock.

§

EmptyField(&'static str)

Required identity field empty.

§

SpoofingCharacter(&'static str)

Field carries a bidi override or zero-width character that would spoof how the identity renders in a log or audit view.

§

BadIssuer(String)

Issuer not in the allowlist.

§

Jwks(String)

JWKS document was malformed or contained no supported signing keys.

§

ScopeEscalation

Child scopes exceed parent scopes.

Fields

§scope: String

The offending scope.

§

ExpEscalation

Child outlives parent.

Fields

§child: u64

Child expiry.

§parent: u64

Parent expiry.

§

ChainTooDeep(usize)

Delegation chain deeper than permitted.

Trait Implementations§

Source§

impl Debug for IdentityError

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Display for IdentityError

Source§

fn fmt(&self, __formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Error for IdentityError

1.30.0 · Source§

fn source(&self) -> Option<&(dyn Error + 'static)>

Returns the lower-level source of this error, if any. Read more
1.0.0 · Source§

fn description(&self) -> &str

👎Deprecated since 1.42.0:

use the Display impl or to_string()

1.0.0 · Source§

fn cause(&self) -> Option<&dyn Error>

👎Deprecated since 1.33.0:

replaced by Error::source, which can support downcasting

Source§

fn provide<'a>(&'a self, request: &mut Request<'a>)

🔬This is a nightly-only experimental API. (error_generic_member_access)
Provides type-based access to context intended for error reports. Read more
Source§

impl PartialEq for IdentityError

Source§

fn eq(&self, other: &IdentityError) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Eq for IdentityError

Source§

impl StructuralPartialEq for IdentityError

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,