pub fn decode(ctx: &Ctx, token: &str) -> Result<Claims>Expand description
Verifies a token from a client with the key derived from SECRET_KEY_BASE and returns its claims.
Checks the signature, the algorithm (ALGORITHM
only) and the expiry against the current time (crate::now), like
decode_with. During a secret rotation, tokens
signed with a key listed in
SECRET_KEY_BASE_PREVIOUS still
verify. No D1 or KV operation.
§Errors
Error::Unauthorized(401) for any invalid token: malformed, other algorithm, bad signature, expired.Error::Internal(500) whenSECRET_KEY_BASEis not set or is shorter than 64 characters, or a previous secret is shorter than 64 characters (message names the fix).
§Examples
use axum::http::{HeaderMap, Uri};
use axum::extract::State;
use ocre::{Ctx, Error, Result, jwt::{self, Location}};
async fn me(State(ctx): State<Ctx>, headers: HeaderMap, uri: Uri) -> Result<String> {
let token = jwt::token_from(&headers, &uri, &[Location::Bearer]).ok_or(Error::Unauthorized)?;
let claims = jwt::decode(&ctx, &token)?;
Ok(claims.sub)
}