//! Pure OAuth entities — no HTTP or persistence logic. use serde::{Deserialize, Serialize}; /// An OAuth 2.0 access token with optional refresh token and absolute /// expiry time (epoch seconds). #[derive(Debug, Clone, Serialize, Deserialize)] pub struct OAuthToken { pub access_token: String, pub refresh_token: Option, pub expires_at: u64, pub token_type: String, } /// Static configuration for an OAuth provider. #[derive(Debug, Clone, Serialize, Deserialize)] pub struct OAuthConfig { pub auth_url: String, pub token_url: String, pub client_id: String, pub client_secret: Option, pub scopes: Vec, } impl Default for OAuthConfig { fn default() -> Self { OAuthConfig { auth_url: String::new(), token_url: String::new(), client_id: String::new(), client_secret: None, scopes: vec![ "openid".to_string(), "profile".to_string(), "email".to_string(), ], } } }