26 releases

0.10.0 Mar 21, 2024
0.9.6 Nov 20, 2023
0.9.5 Oct 25, 2023
0.9.3 Jun 9, 2023
0.2.1 Jul 15, 2019

#58 in Authentication

Download history 4922/week @ 2024-09-28 5505/week @ 2024-10-05 7037/week @ 2024-10-12 7639/week @ 2024-10-19 7928/week @ 2024-10-26 9187/week @ 2024-11-02 8278/week @ 2024-11-09 8084/week @ 2024-11-16 8311/week @ 2024-11-23 10879/week @ 2024-11-30 11065/week @ 2024-12-07 8304/week @ 2024-12-14 1171/week @ 2024-12-21 744/week @ 2024-12-28 4922/week @ 2025-01-04 4881/week @ 2025-01-11

13,050 downloads per month
Used in 11 crates (7 directly)

MIT/Apache

80KB
1.5K SLoC

🔐 tame-oauth

Embark Embark Crates.io Docs dependency status Build status

tame-oauth is a small oauth crate that follows the sans-io approach.

Why?

  • You want to control how you actually make oauth HTTP requests

Why not?

  • The only auth flows that is currently implemented is the service account, user credentials and metadata server flow for GCP. Other flows can be added, but right now GCP is the only provider we need.
  • There are several other oauth crates available that have many more features and are easier to work with, if you don't care about what HTTP clients they use.
  • This crate requires more boilerplate to use.

Features

  • gcp (default) - Support for GCP oauth2
  • wasm-web - Enables wasm features in ring needed for tame-oauth to be used in a wasm browser context. Note this feature should not be used when targeting wasm outside the browser context, in which case you would likely need to target wasm32-wasi.
  • jwt (default) - Support for JSON Web Tokens, required for gcp
  • url (default) - Url parsing, required for gcp

Examples

svc_account

Usage: cargo run --example svc_account -- <key_path> <scope..>

A small example of using tame-oauth together with reqwest. Given a key file and 1 or more scopes, it will attempt to get a token that could be used to access resources in those scopes.

cargo run --example svc_account -- ~/.secrets/super-sekret.json https://www.googleapis.com/auth/pubsub https://www.googleapis.com/auth/devstorage.read_only

default_creds

Usage: cargo run --example default_creds -- <scope..>

Attempts to find and use the default credentials to get a token. Note that scopes are not used in all cases as eg. end user credentials only ever have the cloud platform scope.

cargo run --example default_creds -- https://www.googleapis.com/auth/devstorage.read_only

Contributing

Contributor Covenant

We welcome community contributions to this project.

Please read our Contributor Guide for more information on how to get started.

License

Licensed under either of

at your option.

Contribution

Unless you explicitly state otherwise, any contribution intentionally submitted for inclusion in the work by you, as defined in the Apache-2.0 license, shall be dual licensed as above, without any additional terms or conditions.

Dependencies

~2–11MB
~145K SLoC