pub struct Key(/* private fields */);Expand description
An HS256 signing key, derived from SECRET_KEY_BASE.
Handlers do not build one: encode and decode derive it from the
Worker secret. Use it with encode_with and decode_with in tests,
tools and scripts.
§Examples
let key = ocre::jwt::Key::from_secret_key_base(&"x".repeat(64));
let token = ocre::jwt::encode_with(&key, &ocre::jwt::Claims::new("42", 60));
assert_eq!(ocre::jwt::decode_with(&key, &token, ocre::now())?.sub, "42");Implementations§
Source§impl Key
impl Key
Sourcepub fn from_secret_key_base(secret: &str) -> Self
pub fn from_secret_key_base(secret: &str) -> Self
Derives the key from a SECRET_KEY_BASE value: HMAC-SHA256 of a fixed label.
The label makes the JWT key differ from the session cookie key derived
from the same secret. Any length is accepted here; the Worker secret
read by encode and decode must be 64 characters or more.
§Examples
use ocre::jwt::{Claims, Key, decode_with, encode_with};
let key = Key::from_secret_key_base(&"x".repeat(64));
let token = encode_with(&key, &Claims::new("42", 60));
assert_eq!(decode_with(&key, &token, ocre::now())?.sub, "42");
// Another secret, another key: the token no longer verifies.
assert!(decode_with(&Key::from_secret_key_base(&"y".repeat(64)), &token, ocre::now()).is_err());Auto Trait Implementations§
impl Freeze for Key
impl RefUnwindSafe for Key
impl Send for Key
impl Sync for Key
impl Unpin for Key
impl UnsafeUnpin for Key
impl UnwindSafe for Key
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more