pub fn token_from(
headers: &HeaderMap,
uri: &Uri,
locations: &[Location],
) -> Option<String>Expand description
The token of the first locations entry that has a non-empty one.
Locations are tried in order, so [Location::Bearer, Location::Cookie("token")]
accepts API clients and browsers (Loco’s multiple JWT locations with
fallback). It only finds the token: verify it with decode. Works for
API keys (crate::token) too. No binding call.
§Examples
use axum::http::{HeaderMap, HeaderValue, Uri};
use ocre::jwt::{Location, token_from};
let mut headers = HeaderMap::new();
headers.insert("cookie", HeaderValue::from_static("theme=dark; token=abc"));
let uri: Uri = "/events?token=xyz".parse().unwrap();
assert_eq!(token_from(&headers, &uri, &[Location::Bearer]), None);
assert_eq!(token_from(&headers, &uri, &[Location::Bearer, Location::Cookie("token")]).as_deref(), Some("abc"));
assert_eq!(token_from(&headers, &uri, &[Location::Query("token")]).as_deref(), Some("xyz"));
headers.insert("authorization", HeaderValue::from_static("Bearer 123"));
assert_eq!(token_from(&headers, &uri, &[Location::Bearer, Location::Cookie("token")]).as_deref(), Some("123"));