flwr_oauth2/www_authenticate_parser

This module parses RFC7235 WWW-Authenticate headers, as produced by authorization servers on 401 responses (e.g. the Bearer challenge defined by RFC6750 §3).

It supports the common challenge formats — schemes with key=value parameters, quoted strings, and multiple comma-separated challenges — but not token68 credentials.

Use parse to turn a header value into a list of Challenge values, or lex to work with the raw token stream.

Types

A parsed challenge from a WWW-Authenticate header: the auth scheme (e.g. Bearer) and its parameters (e.g. [#("realm", "example"), #("error", "invalid_token")]).

pub type Challenge {
  Challenge(scheme: String, parameters: List(#(String, String)))
}

Constructors

  • Challenge(scheme: String, parameters: List(#(String, String)))

Errors returned when a WWW-Authenticate header cannot be parsed.

pub type ParserError {
  UnexpectedToken(token: Token)
}

Constructors

  • UnexpectedToken(token: Token)

A token produced by lex. Text holds raw characters; a backslash-escaped quote inside a quoted-string stays raw in Text and is unescaped during parsing.

pub type Token {
  Text(value: String)
  Comma
  Quote
  Equals
  Whitespace
}

Constructors

  • Text(value: String)
  • Comma
  • Quote
  • Equals
  • Whitespace

Values

pub fn lex(source: String) -> List(Token)

A lexer that can lex RFC7235 WWW-Authenticate Headers If parsing of the WWW-Authenticate Header is required see parse.

pub fn parse(
  www_authenticate source: String,
) -> Result(List(Challenge), ParserError)

Implements a parser to parse RFC7235 WWW-Authenticate Headers The parser can parse the most common WWW-Authenticate formats, but not token68.

✨ Search Document