MCPcopy Create free account
hub / github.com/hashintel/hash / extract_token_from_headers

Function extract_token_from_headers

libs/@local/graph/api/src/rest/jwt.rs:290–318  ·  view source on GitHub ↗

Extracts a JWT token from request headers. Checks headers in order: 1. `Cf-Access-Jwt-Assertion` (Cloudflare Access) 2. `Authorization: Bearer `

(headers: &HeaderMap)

Source from the content-addressed store, hash-verified

288/// 1. `Cf-Access-Jwt-Assertion` (Cloudflare Access)
289/// 2. `Authorization: Bearer <token>`
290fn extract_token_from_headers(headers: &HeaderMap) -> Result<Cow<'_, str>, Report<JwtError>> {
291 // Cloudflare Access header
292 if let Some(value) = headers.get("Cf-Access-Jwt-Assertion") {
293 return value
294 .to_str()
295 .map(Cow::Borrowed)
296 .change_context(JwtError::InvalidTokenEncoding);
297 }
298
299 // Standard Authorization: Bearer header
300 if let Some(value) = headers.get(header::AUTHORIZATION) {
301 let value = value
302 .to_str()
303 .change_context(JwtError::InvalidTokenEncoding)?;
304
305 // RFC 7235: authentication schemes are case-insensitive
306 return value
307 .get(..7)
308 .filter(|prefix| prefix.eq_ignore_ascii_case("bearer "))
309 .and_then(|_| value.get(7..))
310 .map(Cow::Borrowed)
311 .ok_or_else(|| {
312 Report::new(JwtError::MissingToken)
313 .attach("Authorization header present but scheme is not Bearer")
314 });
315 }
316
317 Err(Report::new(JwtError::MissingToken))
318}
319
320/// Axum extractor that validates a JWT and provides the decoded claims.
321///

Callers 1

from_request_partsMethod · 0.85

Calls 7

ErrInterface · 0.85
to_strMethod · 0.80
getMethod · 0.65
change_contextMethod · 0.45
mapMethod · 0.45
filterMethod · 0.45
attachMethod · 0.45

Tested by

no test coverage detected