Expand description
The HS256 signing key and the claims that are minted below the server crate.
Lives here rather than beside the rest of the claim machinery in
headless_lms_server::domain::models_requests because the answer readers that mint download
URLs sit in headless-lms-models, under the server crate.
Structs§
- Download
Claim - Authorizes the bearer to read one specific host-stored file for a while.
- JwtKey
Constants§
- DEVELOPMENT_
JWT_ PASSWORD - The fixed password development and test builds sign with. Production reads
JWT_PASSWORD, so nothing signed with this is accepted there. - DOWNLOAD_
CLAIM_ PARAM - Query parameter carrying a
DownloadClaim; the claimed-file route repeats it in a rename.
Functions§
- claimed_
file_ url - The URL one host-stored file is read through, carrying a claim minted for it here and now.
- sign_
hs256_ claim - validate_
hs256_ claim - Decodes and verifies an HS256 token into the requested claim type.