pub struct UpstreamOrder {Show 13 fields
pub order_id: String,
pub upstream_order_url: String,
pub upstream_finalize_url: Option<String>,
pub upstream_certificate_url: Option<String>,
pub csr_der: Vec<u8>,
pub status: String,
pub error: Option<String>,
pub created_at: i64,
pub updated_at: i64,
pub client_ip: Option<String>,
pub client_ptr: Option<String>,
pub user_agent: Option<String>,
pub request_id: Option<String>,
}Fields§
§order_id: String§upstream_order_url: String§upstream_finalize_url: Option<String>§upstream_certificate_url: Option<String>§csr_der: Vec<u8>The client’s CSR, kept so a relay interrupted by a restart can still finalize upstream. See the migration for why it cannot be recovered any other way.
status: String§error: Option<String>§created_at: i64§updated_at: i64§client_ip: Option<String>The finalize request’s context, stored by UpstreamOrder::set_client
so UpstreamOrder::client can hand it back to the audit row written
when the relay settles — long after that request returned. See the
migration for why it cannot come from anywhere else.
client_ptr: Option<String>§user_agent: Option<String>§request_id: Option<String>Implementations§
Source§impl UpstreamOrder
impl UpstreamOrder
Sourcepub fn client(&self) -> ClientContext
pub fn client(&self) -> ClientContext
The stored finalize context, in the shape an audit row takes.
Sourcepub async fn set_client(
order_id: &str,
client: &ClientContext,
database: &Database,
) -> Result<(), Error>
pub async fn set_client( order_id: &str, client: &ClientContext, database: &Database, ) -> Result<(), Error>
Records the finalize request’s context on an already-created mapping row.
A separate UPDATE rather than a parameter of UpstreamOrder::create
because that runs inside SignerBackend::issue, which is handed a CSR
and an order id and deliberately knows nothing about HTTP. post_finalize
calls this the moment the backend answers Processing.
That leaves a window — between the backend’s own create and this
UPDATE — in which a relay could theoretically settle and find no
context. It cannot happen in practice: settling takes at least one
round trip to the upstream CA, and this statement is a few microseconds
of local work on the same task. If it ever did, the audit row would
simply carry no address, which is the same degradation as a resumed
order and not a wrong answer.
Sourcepub async fn create(
order_id: &str,
upstream_order_url: &str,
upstream_finalize_url: Option<&str>,
csr_der: &[u8],
database: &Database,
) -> Result<Option<UpstreamOrder>, Error>
pub async fn create( order_id: &str, upstream_order_url: &str, upstream_finalize_url: Option<&str>, csr_der: &[u8], database: &Database, ) -> Result<Option<UpstreamOrder>, Error>
Records a newly opened upstream order as processing.
Returns Ok(None) when a row for order_id already exists — the
primary key rejecting a duplicate is how two concurrent finalize
requests are stopped from opening two upstream orders for one local
order. The caller treats that as “a relay is already running”.
pub async fn find_by_order_id( order_id: &str, database: &Database, ) -> Result<Option<UpstreamOrder>, Error>
Sourcepub async fn mark_valid(
order_id: &str,
certificate_url: Option<&str>,
database: &Database,
) -> Result<(), Error>
pub async fn mark_valid( order_id: &str, certificate_url: Option<&str>, database: &Database, ) -> Result<(), Error>
Marks the relay finished, recording where the certificate came from.
Sourcepub async fn mark_invalid(
order_id: &str,
error: &str,
database: &Database,
) -> Result<(), Error>
pub async fn mark_invalid( order_id: &str, error: &str, database: &Database, ) -> Result<(), Error>
Marks the relay failed, recording why for an operator to read later — the client only ever sees the problem document on the order itself.
Sourcepub async fn list_processing(
profiles: &[String],
database: &Database,
) -> Result<Vec<UpstreamOrder>, Error>
pub async fn list_processing( profiles: &[String], database: &Database, ) -> Result<Vec<UpstreamOrder>, Error>
Rows still processing, oldest first — relays whose in-memory task
died with the process and need one respawned at startup.
Restricted to the profiles the calling backend actually serves, via
the owning order’s own profile: several endpoints may relay to
several different upstreams, and resuming another one’s order would
drive it against the wrong CA. An empty profiles therefore matches
nothing, which is the safe reading of “this backend serves nothing”.
Trait Implementations§
Source§impl Clone for UpstreamOrder
impl Clone for UpstreamOrder
Source§fn clone(&self) -> UpstreamOrder
fn clone(&self) -> UpstreamOrder
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl Freeze for UpstreamOrder
impl RefUnwindSafe for UpstreamOrder
impl Send for UpstreamOrder
impl Sync for UpstreamOrder
impl Unpin for UpstreamOrder
impl UnsafeUnpin for UpstreamOrder
impl UnwindSafe for UpstreamOrder
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more