-
-
Notifications
You must be signed in to change notification settings - Fork 6.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Rust-Axum][Breaking Changes] Extracting Claims in Cookie/Header #20097
Conversation
&self, | ||
headers: &axum::http::header::HeaderMap, | ||
key: &str, | ||
) -> Option<String>; | ||
) -> Option<Self::Claims>; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
User Impl this trait to extract Claims (e.g: JWT) from Header/Cookie.
@@ -68,7 +70,7 @@ pub trait Payments { | |||
method: Method, | |||
host: Host, | |||
cookies: CookieJar, | |||
token_in_cookie: Option<String>, | |||
claims: Self::Claims, |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Extracted Claims (in previous step) is injected into Operation. User then can do whatever he/she wants with the Claims (e.g: get AccountID from the Claims)
Kindly ping @wing328 to review |
op.vendorExtensions.put("x-has-header-auth-methods", "true"); | ||
op.vendorExtensions.put("x-api-key-header-name", toModelName(s.keyParamName)); | ||
op.vendorExtensions.put("x-has-header-auth-methods", true); | ||
op.vendorExtensions.put("x-api-key-header-name", s.keyParamName); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bug fix here. We must use keyParamName
instead of transforming
thanks for the PR. let's give it a try if users need the old behavior with a valid use case, we will come up with a way for that. |
Thank you for reviewing @wing328 |
This PR helps handling Authentication via API key (in Header and in Cookie). Extracted Claims are now sent to all Operations
Integration tests passed:
PR checklist
Commit all changed files.
This is important, as CI jobs will verify all generator outputs of your HEAD commit as it would merge with master.
These must match the expectations made by your contribution.
You may regenerate an individual generator by passing the relevant config(s) as an argument to the script, for example
./bin/generate-samples.sh bin/configs/java*
.IMPORTANT: Do NOT purge/delete any folders/files (e.g. tests) when regenerating the samples as manually written tests may be removed.
master
(upcoming7.x.0
minor release - breaking changes with fallbacks),8.0.x
(breaking changes without fallbacks)