Skip to main content

release_code

Function release_code 

Source
async fn release_code(
    services: &Services,
    auth_req: &AuthRequest,
    params: &CompleteParams,
) -> Result<Response>
Expand description

Retire the pending authorization request, mint the code, and hand it to the client’s redirect target.

The request is retired before the code exists, so a resubmitted form finds nothing to mint against. The login token is spent on the same pass, which makes this the one-shot tail of both entry points; a request that vanished or changed since it was read keeps the token, as a refused peek does.