ttk_server/attestation/mock.rs
1//! Mock provider for local development and CI where no TEE hardware exists.
2//!
3//! Produces AWS Nitro-format documents signed through a published mock root CA (see
4//! [`create_mock_attestation_document`]). Clients verify them fully, but only accept them when
5//! mock attestation is explicitly allowed.
6
7use super::nitro_doc::{create_mock_attestation_document, wrap_as_eat};
8use super::{AttestationError, AttestationProvider};
9use crate::{AttestationParams, EatClaimsSet};
10
11/// Always-available provider producing Nitro-format documents signed through the mock root CA.
12pub struct MockSession;
13
14/// Mock implementation of [`AttestationProvider`]; builds a mock-signed Nitro-format document.
15impl AttestationProvider for MockSession {
16 /// Returns `"mock"`.
17 fn name(&self) -> &'static str {
18 "mock"
19 }
20
21 /// The mock provider is always available.
22 fn is_available() -> bool {
23 true
24 }
25
26 /// Builds a mock attestation document for `params` and wraps it as an EAT claims-set.
27 fn generate_document(
28 &self,
29 params: &AttestationParams,
30 ) -> Result<EatClaimsSet, AttestationError> {
31 wrap_as_eat(&create_mock_attestation_document(params)?)
32 }
33}