pub fn decode_with(key: &Key, token: &str, now: i64) -> Result<Claims>Expand description
Verifies token with key at Unix time now (seconds) and returns its claims.
Checks, in order: the shape, the header’s alg (ALGORITHM only), the
signature (constant-time comparison), then the expiry (exp > now).
Handlers use decode, which takes the key from SECRET_KEY_BASE and
the current time.
§Errors
Error::Unauthorized (401) for any failure: malformed token, other
algorithm, bad signature, expired. The error does not say which check
failed.
§Examples
use ocre::jwt::{Claims, Key, decode_with, encode_with};
let key = Key::from_secret_key_base(&"x".repeat(64));
let token = encode_with(&key, &Claims { sub: "42".to_owned(), iat: 0, exp: 60 });
assert_eq!(decode_with(&key, &token, 59)?.sub, "42");
assert!(matches!(decode_with(&key, &token, 60), Err(ocre::Error::Unauthorized))); // expired
assert!(decode_with(&key, "not.a.token", 0).is_err());