Public declaration syntax from forge-rs/crates/forge-auth/src/error.rs Original source SHA-256: 8b29405122d0fe1f244f03058f6f25a16ad4af73a9396cf99a3bf36754b758fa Function bodies and constant values are omitted. This is not the complete implementation. Source line 15 pub type ForgeAuthResult = Result; Source line 31 #[derive(Debug, thiserror::Error)] pub enum ForgeAuthError { /// The Arsenal ACT has expired and is no longer valid. /// /// Agents must obtain a fresh token before retrying the operation. /// /// # ANVIL Spec §8.7.1 #[error( "ACT '{token_id}' for agent '{agent_did}' expired at {expired_at} — obtain a fresh token" )] TokenExpired { /// The unique identifier of the expired token. token_id: String, /// The DID of the agent that presented the token. agent_did: String, /// The timestamp at which the token expired (ISO 8601). expired_at: String, }, /// The agent's ACT does not grant the required scope for the operation. /// /// The agent must obtain a token with the missing capability, or the /// operation must be re-scoped to match the agent's granted permissions. /// /// # ANVIL Spec §8.7.2 #[error( "agent '{agent_did}' lacks required scope '{required_scope}' — available scopes: {available_scopes:?}" )] InsufficientScope { /// The DID of the agent whose token was checked. agent_did: String, /// The scope string that was required but not granted. required_scope: String, /// The scopes that the agent's ACT actually grants. available_scopes: Vec, }, /// A sub-agent delegation attempted to grant capabilities exceeding the parent's scope. /// /// Child agent capabilities must be a strict subset of the parent's. This is /// a security invariant that prevents privilege escalation via delegation. /// /// # ANVIL Spec §11.3.1 #[error( "capability escalation denied: child '{child_did}' requested scope '{requested}' but parent '{parent_did}' only grants {available:?}" )] CapabilityEscalation { /// The DID of the parent agent whose ACT was being delegated. parent_did: String, /// The DID of the child agent that would receive the delegation. child_did: String, /// The scope string that was requested but exceeds the parent's grant. requested: String, /// The scopes available in the parent's ACT. available: Vec, }, /// Delegation was denied due to constraint violations in the parent's ACT. /// /// This covers cases where the parent's token does not permit delegation at all, /// or the target agent is not in the allowed delegates list, or the delegation /// depth has been exceeded. /// /// # ANVIL Spec §11.3.2 #[error("delegation from parent '{parent_did}' to child '{child_did}' denied: {reason}")] DelegationDenied { /// The DID of the parent agent attempting to delegate. parent_did: String, /// The DID of the intended child agent. child_did: String, /// Human-readable reason for the denial. reason: String, }, /// The ACT is structurally invalid or malformed. /// /// This indicates the token could not be validated even before checking /// scopes or time validity. The token may be corrupted, incorrectly /// constructed, or tampered with. /// /// # ANVIL Spec §8.7.3 #[error("invalid Arsenal ACT: {reason}")] InvalidToken { /// Human-readable explanation of why the token is invalid. reason: String, }, /// An error propagated from the underlying Arsenal SDK. /// /// This wraps errors from `arsenal-core` operations that do not map /// cleanly to a Forge-specific authorization error. Boxed to keep /// the overall enum size small. #[error("arsenal error: {0}")] Arsenal(Box), /// A proxy request was denied due to insufficient proxy scopes. #[error( "proxy access denied for variable '{variable}' — agent '{agent_did}' lacks proxy scope" )] ProxyDenied { /// The DID of the agent. agent_did: String, /// The variable name that was denied. variable: String, }, /// A proxy request requires consent that has not been granted. #[error("consent required for agent '{agent_did}' to access variable '{variable}'")] ConsentRequired { /// The DID of the agent. agent_did: String, /// The variable name requiring consent. variable: String, }, /// A fingerprint hash chain mismatch was detected. #[error("fingerprint mismatch for agent '{agent_did}' — possible key compromise")] FingerprintMismatch { /// The DID of the agent with the mismatched fingerprint. agent_did: String, }, /// An identity operation failed during an auth workflow. /// /// This wraps errors from `forge-identity` operations (derivation, lineage) /// that occur during identity-aware auth flows like sub-agent creation. /// /// # ANVIL Spec §11.1 #[error("identity error: {reason}")] IdentityError { /// Human-readable description of the identity failure. reason: String, }, } Source line 174 #[must_use] pub fn is_expired(&self) -> bool; Source line 180 #[must_use] pub fn is_insufficient_scope(&self) -> bool; Source line 186 #[must_use] pub fn is_capability_escalation(&self) -> bool; Source line 192 #[must_use] pub fn is_delegation_denied(&self) -> bool; Source line 198 #[must_use] pub fn is_invalid_token(&self) -> bool; Source line 204 #[must_use] pub fn is_proxy_denied(&self) -> bool; Source line 210 #[must_use] pub fn is_consent_required(&self) -> bool; Source line 216 #[must_use] pub fn is_fingerprint_mismatch(&self) -> bool; Source line 222 #[must_use] pub fn is_identity_error(&self) -> bool; Source line 236 #[must_use] pub fn error_code(&self) -> &'static str;