Skip to main content

Module jwt

Module jwt 

Source
Expand description

The HS256 signing key and the claims that are minted below the server crate.

Lives here rather than beside the rest of the claim machinery in headless_lms_server::domain::models_requests because the answer readers that mint download URLs sit in headless-lms-models, under the server crate.

Structs§

DownloadClaim
Authorizes the bearer to read one specific host-stored file for a while.
JwtKey

Constants§

DEVELOPMENT_JWT_PASSWORD
The fixed password development and test builds sign with. Production reads JWT_PASSWORD, so nothing signed with this is accepted there.
DOWNLOAD_CLAIM_PARAM
Query parameter carrying a DownloadClaim; the claimed-file route repeats it in a rename.

Functions§

claimed_file_url
The URL one host-stored file is read through, carrying a claim minted for it here and now.
sign_hs256_claim
validate_hs256_claim
Decodes and verifies an HS256 token into the requested claim type.