Skip to main content

Nonce

Struct Nonce 

Source
pub struct Nonce {
    pub value: String,
    pub created_at: i64,
}
Expand description

A replay nonce used for ACME protocol anti-replay protection.

§ACME Protocol Compliance

According to RFC 8555, nonces are used to prevent replay attacks:

  • Each nonce is a UUID v4 string
  • Nonces are generated for every response
  • Clients must include a valid nonce in their requests
  • Nonces are single-use and expire after a TTL period

§Security Considerations

  • Nonces are stored in the database with timestamps
  • Expired nonces are automatically cleaned up
  • Single-use enforcement prevents replay attacks
  • Time-to-live limits prevent indefinite nonce accumulation

§Database Storage

Nonces are stored in the nonces table with:

  • value: The UUID string of the nonce
  • created_at: Unix timestamp when the nonce was created

§Lifecycle

  1. New nonce created for each response
  2. Nonce saved to database
  3. Client uses nonce in subsequent request
  4. Nonce verified and consumed (single-use)
  5. Expired nonces automatically cleaned up

Fields§

§value: String§created_at: i64

Implementations§

Source§

impl Nonce

Source

pub fn new() -> Self

Source

pub async fn save(&self, database: &Database) -> Result<(), Error>

Source

pub async fn verify( nonce: &str, database: &Database, ttl: Duration, ) -> Result<bool, Error>

Consumes nonce if it is live: a single DELETE whose rows_affected decides, so two concurrent replays cannot both succeed.

Takes &str rather than String — it only ever binds a reference, and this runs on every signed POST, which is the hottest path in the server.

Source

pub async fn count(database: &Database) -> Result<i64, Error>

How many nonce rows exist right now.

The one thing worth showing about this table: individual values are bearer credentials and are never listed (see the note on fingerprint), but the count is a useful health signal — it should hover around the request rate times the TTL, and a number far above that means the reaper is not running.

Source

pub async fn cleanup(database: &Database, ttl: Duration) -> Result<u64, Error>

Trait Implementations§

Source§

impl Debug for Nonce

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Nonce

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

§

impl Freeze for Nonce

§

impl RefUnwindSafe for Nonce

§

impl Send for Nonce

§

impl Sync for Nonce

§

impl Unpin for Nonce

§

impl UnsafeUnpin for Nonce

§

impl UnwindSafe for Nonce

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more