Skip to main content

Signer

Trait Signer 

Source
pub trait Signer:
    Send
    + Sync
    + Debug {
    // Required methods
    fn key_id(&self) -> KeyId;
    fn sign(&self, hash: &Digest) -> Vec<u8> ⓘ;

    // Provided method
    fn signature_over(&self, hash: &Digest) -> KeySignature { ... }
}
Expand description

Signs a record’s chain hash.

Implementations must be cheap enough to run on every append — this is on the write path of every journaled effect — and must not perform I/O in sign. A signer that calls out to a KMS per record turns the journal’s write path into a network dependency, which is the same mistake as a policy engine that can fail open. Fetch and cache the credential elsewhere; sign locally.

Required Methods§

Source

fn key_id(&self) -> KeyId

The identity this signer writes as.

Source

fn sign(&self, hash: &Digest) -> Vec<u8> ⓘ

Sign a record’s chain hash.

Provided Methods§

Source

fn signature_over(&self, hash: &Digest) -> KeySignature

Attach a signature to a hash.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§