aldebaran-access
Who may come in: nobody Cloudflare Access has not signed in. Access puts a
signed token in Cf-Access-Jwt-Assertion on every request it lets through; the
Worker checks it itself, so the site is not open to anything that reaches it
by another road.
| Item | What it is |
|---|---|
admitted(token, keys, team, audience, now_s) | The email (or service token's name) of whoever Access signed in, or a Refused. |
Refused | Closed: not configured, not a token, wrong algorithm, unknown key, bad key, bad signature, other application, other team, expired. |
certs(team), kid(token), Keys, Key | Where the team's keys are read from, which key a token names, and their shape. Fetching is the adapter's. |
HEADER | The header name. |
RS256 only, pure Rust, builds for wasm.