Skip to main content

exchange_code

Function exchange_code 

Source
pub fn exchange_code(
    ctx: &Ctx,
    provider: &'static Provider,
    redirect_uri: &str,
    code: &str,
    verifier: &str,
) -> impl Future<Output = Result<String>> + Send + use<>
Expand description

Trades the authorization code from the callback for an access token (one subrequest).

Sends the client id and secret from the provider’s Worker secrets (Provider::client_id_secret, Provider::client_secret_secret), the same redirect_uri as the authorization URL, and the PKCE verifier kept in the session.

§Errors

  • Error::Unauthorized when the provider refuses the code (expired, used twice, wrong verifier); the reason is logged.
  • Error::Internal when a secret is missing (the message names it) or the provider cannot be reached.

§Examples

use ocre::{Ctx, Result, oauth::{GITHUB, exchange_code, profile}};

async fn callback(ctx: &Ctx, code: &str, verifier: &str) -> Result<String> {
    let token = exchange_code(ctx, &GITHUB, "https://app.example.com/auth/github/callback", code, verifier).await?;
    Ok(profile(&GITHUB, &token).await?.uid)
}