org.llm4s.llmconnect.auth
Members list
Type members
Classlikes
A bearer token and when it stops being valid. The value is redacted in toString.
A bearer token and when it stops being valid. The value is redacted in toString.
Attributes
- Supertypes
-
trait Serializabletrait Producttrait Equalsclass Objecttrait Matchableclass AnyShow all
Supplies the bearer token for each request, refreshing it as needed.
Supplies the bearer token for each request, refreshing it as needed.
Attributes
- Supertypes
-
class Objecttrait Matchableclass Any
- Known subtypes
A named provider section's auth block: the workload's identity token, plus the keys the provider declares in ProviderConfigSpec.authExtras (a token URL, a federation rule id, ...), resolved by validation. Values are redacted in toString.
A named provider section's auth block: the workload's identity token, plus the keys the provider declares in ProviderConfigSpec.authExtras (a token URL, a federation rule id, ...), resolved by validation. Values are redacted in toString.
Extras are trimmed and a blank one is dropped, however the config is built - as a section's auth block is read - so a blank clientId is absent rather than posted empty, and a required key left blank is reported as missing.
Attributes
- Companion
- object
- Supertypes
-
trait Serializabletrait Producttrait Equalsclass Objecttrait Matchableclass AnyShow all
Attributes
- Companion
- class
- Supertypes
-
trait Producttrait Mirrorclass Objecttrait Matchableclass Any
- Self type
-
AuthConfig.type
Caches the token fetch returns until refreshMargin before it expires - or half-way through its life, if it lives shorter than twice the margin. Concurrent callers share one in-flight fetch.
Caches the token fetch returns until refreshMargin before it expires - or half-way through its life, if it lives shorter than twice the margin. Concurrent callers share one in-flight fetch.
A failed fetch is shared for a brief window: the callers waiting behind it get the same failure at once instead of each making their own attempt in turn, which during an outage would hold the last of N callers for N times the exchange's timeout. A rejection (an authentication or configuration error, or any other error not marked recoverable) is shared for FailureTtl (5 seconds); a transient failure (a org.llm4s.error.RecoverableError: network, timeout, rate limit, 5xx) for TransientFailureTtl (1 second) - long enough for the callers queued behind the fetch, short enough that a blip does not outlive itself. After the window the next call tries again; a success, or a rejected cached token, ends it sooner.
A cancellation is never shared. A fetch whose thread is interrupted - it returns CancelledError, throws InterruptedException, or fails while the flag is set - returns CancelledError to that caller alone, with its interrupt flag set, and caches nothing: the next caller through the lock makes its own fetch.
Attributes
- Companion
- object
- Supertypes
Attributes
- Companion
- class
- Supertypes
-
class Objecttrait Matchableclass Any
- Self type
Where a workload's identity token comes from - typically a SPIFFE JWT-SVID file that spiffe-helper keeps fresh. The configured form, before it is read.
Where a workload's identity token comes from - typically a SPIFFE JWT-SVID file that spiffe-helper keeps fresh. The configured form, before it is read.
Attributes
- Supertypes
-
trait Enumtrait Serializabletrait Producttrait Equalsclass Objecttrait Matchableclass AnyShow all
Fetches the subject token a token exchange presents.
Fetches the subject token a token exchange presents.
Attributes
- Companion
- object
- Supertypes
-
class Objecttrait Matchableclass Any
Attributes
- Companion
- trait
- Supertypes
-
class Objecttrait Matchableclass Any
- Self type
-
IdentityTokenSource.type
The RFC 8693 token exchange and its caching provider.
The RFC 8693 token exchange and its caching provider.
Attributes
- Supertypes
-
class Objecttrait Matchableclass Any
- Self type
-
TokenExchange.type
An RFC 8693 token exchange: present identityToken at tokenUrl, get back a short-lived bearer token. Databricks workload identity federation is one such endpoint (https://<workspace>/oidc/v1/token, scope = all-apis, clientId = the service principal).
An RFC 8693 token exchange: present identityToken at tokenUrl, get back a short-lived bearer token. Databricks workload identity federation is one such endpoint (https://<workspace>/oidc/v1/token, scope = all-apis, clientId = the service principal).
toString shows tokenUrl without its userinfo or query, which may carry credentials, and redacts clientId.
Attributes
- Companion
- object
- Supertypes
-
trait Serializabletrait Producttrait Equalsclass Objecttrait Matchableclass AnyShow all
Attributes
- Companion
- class
- Supertypes
-
trait Producttrait Mirrorclass Objecttrait Matchableclass Any
- Self type
-
TokenExchangeConfig.type