feat(bootstrap): create temporary settings and config files to prevent data loss refactor(edit_log): switch from Vec to VecDeque for efficient memory management fix(gateway): ensure store directories are created before starting the API server refactor(bgbash): implement a global singleton for BashControl feat(auth): enhance session authentication middleware to use SessionRepository fix(edit_log_repo): update to use VecDeque for in-memory edit log storage fix(memory_repo): add newline escaping for frontmatter fields fix(session_lock_repo): improve error handling for lock file operations fix(bash_tools): prevent path traversal in job_id argument refactor(delete): enforce empty directory deletion in file system tools fix(edit): optimize string replacement to only replace the first occurrence fix(git_cred): improve credential management with piped input to git commands feat(git_operator): add safety filter to block destructive git operations fix(shell): register background jobs in Bash control feat(spawn): add access tier specification for pipeline stages refactor(hive_mind): run directives concurrently for improved performance fix(auth): update refresh token verification in the refresh handler fix(chat): optimize LLM client usage based on model matching fix(conversations): enhance message deletion to target specific indices feat(api): add JWT authentication middleware for all API routes fix(state): implement refresh token verification in JwtTokenService fix(daemon): improve usage tracking with saturating addition fix(tui): handle compacted messages in the TUI state management
33 lines
1.2 KiB
Rust
33 lines
1.2 KiB
Rust
//! TokenService port — JWT access and refresh token abstraction.
|
|
//!
|
|
//! Defines the trait that JWT adapter implementations provide. Covers
|
|
//! token generation (pair of access + refresh tokens) and access token
|
|
//! verification (returns the subject claim).
|
|
|
|
use anyhow::Result;
|
|
|
|
/// Abstraction for JWT-based token generation and verification.
|
|
///
|
|
/// Implementors handle signing key management, token serialisation,
|
|
/// and expiry validation. The trait is `Send + Sync` for use across
|
|
/// thread boundaries.
|
|
pub trait TokenService: Send + Sync {
|
|
/// Generate an access + refresh token pair for the given subject
|
|
/// identifier.
|
|
///
|
|
/// Returns `(access_token, refresh_token)`.
|
|
fn generate_tokens(&self, sub: &str) -> Result<(String, String)>;
|
|
|
|
/// Verify an access token and return the embedded subject claim.
|
|
///
|
|
/// Returns `Err` if the token is expired, malformed, or has an
|
|
/// invalid signature.
|
|
fn verify_access_token(&self, token: &str) -> Result<String>;
|
|
|
|
/// Verify a refresh token and return the embedded subject claim.
|
|
///
|
|
/// Returns `Err` if the token is expired, malformed, or has an
|
|
/// invalid signature.
|
|
fn verify_refresh_token(&self, token: &str) -> Result<String>;
|
|
}
|