pub fn verify<T>(
token: &SecretString,
key_b64: &SecretString,
) -> Result<T, AuthenticationError>where
T: DeserializeOwned,Expand description
ยงErrors
Returns AuthenticationError for invalid token format, base64 encoding,
JSON, algorithm or signature. AuthenticationError::MissingExpiry rejects
absent exp, AuthenticationError::TokenExpired rejects elapsed expiry
and the nbf and optional iat guards retain their time errors.
This verifier decodes JWT header, payload, and signature segments with the JOSE base64url alphabet without padding, as required by RFC 7515 / RFC 7519.