Skip to main content

ttk_server/attestation/
mock.rs

1//! Mock provider for local development and CI where no TEE hardware exists.
2//!
3//! Produces AWS Nitro-format documents signed through a published mock root CA (see
4//! [`create_mock_attestation_document`]). Clients verify them fully, but only accept them when
5//! mock attestation is explicitly allowed.
6
7use super::nitro_doc::{create_mock_attestation_document, wrap_as_eat};
8use super::{AttestationError, AttestationProvider};
9use crate::{AttestationParams, EatClaimsSet};
10
11/// Always-available provider producing Nitro-format documents signed through the mock root CA.
12pub struct MockSession;
13
14/// Mock implementation of [`AttestationProvider`]; builds a mock-signed Nitro-format document.
15impl AttestationProvider for MockSession {
16    /// Returns `"mock"`.
17    fn name(&self) -> &'static str {
18        "mock"
19    }
20
21    /// The mock provider is always available.
22    fn is_available() -> bool {
23        true
24    }
25
26    /// Builds a mock attestation document for `params` and wraps it as an EAT claims-set.
27    fn generate_document(
28        &self,
29        params: &AttestationParams,
30    ) -> Result<EatClaimsSet, AttestationError> {
31        wrap_as_eat(&create_mock_attestation_document(params)?)
32    }
33}