IdentityImpl
Defined in: src/token-identity.ts:607
Applies this module’s guards, then delegates to worker-supplied hooks.
The framework owns the guards and owns none of the policy. It decides who may ask and what shape of credential is refused outright; the worker decides what a credential resolves to and whether a grant is minted. That split is deliberate – the guards are the part that is identical in every deployment and catastrophic to get wrong, and the policy is the part that is different in every deployment and cannot be guessed.
A method whose hook is absent is not registered at all, so the protocol a
server hosts describes what it actually does. A worker that resolves
credentials but does not mint grants hosts introspect_token and not
issue_grant, and a client discovers that through ordinary reflection rather
than by calling and reading an error. Absent beats routed-and-refusing: it is
what keeps a dependency upgrade from growing a credential-to-identity oracle
on every existing worker.
Constructors
Section titled “Constructors”Constructor
Section titled “Constructor”new IdentityImpl(options?): IdentityImpl;Defined in: src/token-identity.ts:614
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
options |
IdentityOptions |
Returns
Section titled “Returns”IdentityImpl
Accessors
Section titled “Accessors”grantKeys
Section titled “grantKeys”Get Signature
Section titled “Get Signature”get grantKeys(): GrantKeys | undefined;Defined in: src/token-identity.ts:626
The sealed-grant configuration, when this deployment has one.
Returns
Section titled “Returns”GrantKeys | undefined
resolveToken
Section titled “resolveToken”Get Signature
Section titled “Get Signature”get resolveToken(): | TokenResolver | undefined;Defined in: src/token-identity.ts:632
The worker’s resolveToken, which an HTTP handler also consults for
bearer credentials (WIRE_PROTOCOL.md §16).
Returns
Section titled “Returns”| TokenResolver
| undefined
Methods
Section titled “Methods”introspectToken()
Section titled “introspectToken()”introspectToken(token, auth): Promise<TokenIdentity>;Defined in: src/token-identity.ts:658
Resolve token, after checking the caller may ask.
The guard order is load-bearing and must not be tidied: authorization comes before anything looks at the subject credential – including its length and its shape – so an unauthorized caller learns nothing about it, not even how long looking at it took.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
token |
string |
auth |
AuthContext |
Returns
Section titled “Returns”Promise<TokenIdentity>
issueGrant()
Section titled “issueGrant()”issueGrant( purpose, scopes, ttlSeconds, auth): Promise<IssuedGrant>;Defined in: src/token-identity.ts:686
Mint a grant for the caller, after checking they authenticated recently.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
purpose |
string |
scopes |
readonly string[] |
ttlSeconds |
number |
auth |
AuthContext |
Returns
Section titled “Returns”Promise<IssuedGrant>
offeredMethods()
Section titled “offeredMethods()”offeredMethods(): ReadonlySet<string>;Defined in: src/token-identity.ts:643
Return the methods this deployment can actually answer.
A method whose hook is absent is not registered, so the protocol a server hosts describes what it does – and a client learns that from reflection rather than by calling and reading an error.
Returns
Section titled “Returns”ReadonlySet<string>
