Skip to main content

decode

Function decode 

Source
pub fn decode(ctx: &Ctx, token: &str) -> Result<Claims>
Expand description

Verifies a token from a client with the key derived from SECRET_KEY_BASE and returns its claims.

Checks the signature, the algorithm (ALGORITHM only) and the expiry against the current time (crate::now), like decode_with. During a secret rotation, tokens signed with a key listed in SECRET_KEY_BASE_PREVIOUS still verify. No D1 or KV operation.

§Errors

  • Error::Unauthorized (401) for any invalid token: malformed, other algorithm, bad signature, expired.
  • Error::Internal (500) when SECRET_KEY_BASE is not set or is shorter than 64 characters, or a previous secret is shorter than 64 characters (message names the fix).

§Examples

use axum::http::{HeaderMap, Uri};
use axum::extract::State;
use ocre::{Ctx, Error, Result, jwt::{self, Location}};

async fn me(State(ctx): State<Ctx>, headers: HeaderMap, uri: Uri) -> Result<String> {
    let token = jwt::token_from(&headers, &uri, &[Location::Bearer]).ok_or(Error::Unauthorized)?;
    let claims = jwt::decode(&ctx, &token)?;
    Ok(claims.sub)
}