pub struct Authorization {
pub id: String,
pub order_id: String,
pub identifier: Identifier,
pub status: AuthzStatus,
pub expires: i64,
pub created_at: i64,
}Expand description
An ACME authorization (RFC 8555 §7.1.4). One authorization is created per
order identifier when the order is created, starting in the pending state
and carrying the challenges the client can satisfy to prove control of the
identifier.
§Storage Details
identifieris persisted as a JSON{type, value}object.- Timestamps are epoch seconds (matching orders/accounts/nonces) and rendered
as RFC3339 strings in
Authorization::to_json. - The authorization URL is derived from the id + base URL (like the
order’s
finalize/certificateURLs), never stored.
§Wildcards
A wildcard authorization stores its identifier in the wildcard form
(*.example.com), while the ACME object shows the base name plus a separate
"wildcard": true member (RFC 8555 §7.1.4). Storing the base name instead
would collide: the canonical wildcard order ["example.com", "*.example.com"]
creates two authorizations, and UNIQUE(order_id, identifier) compares the
serialized JSON — both rows would be identical and the order would fail to
persist. Deriving with Authorization::base_identifier costs a
strip_prefix and no migration.
Fields§
§id: String§order_id: String§identifier: Identifier§status: AuthzStatus§expires: i64§created_at: i64Implementations§
Source§impl Authorization
impl Authorization
Sourcepub async fn create(
order_id: &str,
identifier: Identifier,
expires: i64,
database: &Database,
) -> Result<Authorization, Error>
pub async fn create( order_id: &str, identifier: Identifier, expires: i64, database: &Database, ) -> Result<Authorization, Error>
Creates a new authorization for identifier in the pending state.
pub async fn find_by_id( id: &str, database: &Database, ) -> Result<Option<Authorization>, Error>
Sourcepub async fn find_by_order(
order_id: &str,
database: &Database,
) -> Result<Vec<Authorization>, Error>
pub async fn find_by_order( order_id: &str, database: &Database, ) -> Result<Vec<Authorization>, Error>
Lists an order’s authorizations, oldest first (creation order), for the
order object’s authorizations array and the all-valid readiness check.
Sourcepub async fn count_by_order(
order_id: &str,
database: &Database,
) -> Result<i64, Error>
pub async fn count_by_order( order_id: &str, database: &Database, ) -> Result<i64, Error>
How many authorizations an order has. crate::sqlite::order::Order::count_by_account’s
counterpart, and for the same reason.
Sourcepub async fn find_ids_by_orders(
order_ids: &[&str],
database: &Database,
) -> Result<HashMap<String, Vec<String>>, Error>
pub async fn find_ids_by_orders( order_ids: &[&str], database: &Database, ) -> Result<HashMap<String, Vec<String>>, Error>
The authorization ids of several orders at once, keyed by order id.
The listing paths need nothing but the ids — Order::to_json builds its
authorizations URLs from them — and were calling
Authorization::find_by_order once per row: 51 queries for a default
page of 50. One IN (…) instead.
An order with no authorizations is simply absent from the map, which is
what a caller wants: map.remove(id).unwrap_or_default().
Sourcepub async fn mark_valid(&mut self, database: &Database) -> Result<(), Error>
pub async fn mark_valid(&mut self, database: &Database) -> Result<(), Error>
Moves the authorization to the valid state and keeps self in sync (the
same persist-and-sync pattern as crate::sqlite::order::Order::finalize).
Sourcepub async fn mark_invalid(&mut self, database: &Database) -> Result<(), Error>
pub async fn mark_invalid(&mut self, database: &Database) -> Result<(), Error>
Moves the authorization to the terminal invalid state, after one of its
challenges failed validation (RFC 8555 §7.1.6).
No error is stored: the RFC puts the problem document on the
challenge, and the authorization object has no error member — a client
reads the reason from the challenge it triggered.
Sourcepub fn is_wildcard(&self) -> bool
pub fn is_wildcard(&self) -> bool
Whether this authorization covers the wildcard of its identifier.
Derived from the stored value rather than stored separately — see the
type’s doc comment for why the row keeps the *. prefix.
Sourcepub fn base_identifier(&self) -> &str
pub fn base_identifier(&self) -> &str
The name to actually prove control of: the identifier with any *.
stripped.
A wildcard is proved by controlling the zone, so the DNS record lives at
_acme-challenge.example.com, not at _acme-challenge.*.example.com.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for Authorization
impl RefUnwindSafe for Authorization
impl Send for Authorization
impl Sync for Authorization
impl Unpin for Authorization
impl UnsafeUnpin for Authorization
impl UnwindSafe for Authorization
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more