pub struct Destination {
pub name: String,
pub url: String,
pub authentication: Option<PushAuthentication>,
pub signing: Option<BodySigning>,
}Expand description
One place the deployment sends its own events.
Fields§
§name: StringWhat the operator calls it. Appears in logs and in the stored id.
url: StringWhere to POST. Not checked against an allowlist, because there is no caller to check — see the module docs.
authentication: Option<PushAuthentication>HTTP authentication for the receiver, if it wants any.
signing: Option<BodySigning>A body signature for the receiver, if it verifies one.
None means deliveries carry no signature at all — not an unsigned
header, no header. See signed_with for what a
signature is and is not evidence of.
Implementations§
Source§impl Destination
impl Destination
pub fn new(name: impl Into<String>, url: impl Into<String>) -> Self
pub fn authenticated( self, scheme: impl Into<String>, credentials: Secret, ) -> Self
Sourcepub fn signed_with(self, secret: &Secret) -> Self
pub fn signed_with(self, secret: &Secret) -> Self
Sign every delivery to this destination under secret.
Standard Webhooks: webhook-signature: v1,<base64> over
{webhook-id}.{webhook-timestamp}.{body}. It is beside
authenticated, not instead of it: a bearer
header proves the sender held a token, which is a claim about the
connection and not about the bytes, and that token transits every hop
between here and the receiver.
What the receiver must still do itself — refuse a stale
webhook-timestamp and deduplicate on webhook-id, without which a
captured POST replays — is set out on BodySigning, and a receiver is
being written against those limits whether or not anybody read them.
§Panics
If the key is shorter than 24 bytes, or a whsec_-prefixed secret is
not base64. Both are this deployment’s own configuration, so both are
refused where they are written rather than at the far end of a run.
Use try_signed_with where the secret is read
from configuration inside a builder — a panic there takes the process
down from underneath the code that was assembling it.
Sourcepub fn try_signed_with(self, secret: &Secret) -> Result<Self, SigningKeyError>
pub fn try_signed_with(self, secret: &Secret) -> Result<Self, SigningKeyError>
signed_with, reporting a bad key rather than
aborting.
RuntimeBuilder::build and
try_build in the small. A
deployment reads this secret inside its own build(), so a mistyped one
belongs in that builder’s error path — with the exit code and the log
line naming which destination was wrong, none of which a panic reaches.
§Errors
SigningKeyError — a whsec_ secret that is
not base64, or a key under the 24 bytes Standard Webhooks requires.
Sourcepub fn also_signed_with(self, secret: &Secret) -> Self
pub fn also_signed_with(self, secret: &Secret) -> Self
Sign every delivery under this secret as well — the mid-rotation form. The receiver holding either key verifies, so the old secret can be retired at the receiver’s pace instead of on a flag day.
§Panics
As signed_with; and if no primary secret was
configured first, because “also” without a first key is a wiring
mistake worth naming at configuration.
Sourcepub fn try_also_signed_with(
self,
secret: &Secret,
) -> Result<Self, SigningKeyError>
pub fn try_also_signed_with( self, secret: &Secret, ) -> Result<Self, SigningKeyError>
also_signed_with, reporting rather than
aborting — try_signed_with’s argument, with
the same force: both secrets come from the same file, at the same
moment, inside the same builder.
§Errors
SigningKeyError — a bad key, or
NoPrimary when no primary secret
is configured.
Sourcepub fn registration_id(&self) -> String
pub fn registration_id(&self) -> String
The stored registration id for this destination.
Trait Implementations§
Source§impl Clone for Destination
impl Clone for Destination
Auto Trait Implementations§
impl Freeze for Destination
impl RefUnwindSafe for Destination
impl Send for Destination
impl Sync for Destination
impl Unpin for Destination
impl UnsafeUnpin for Destination
impl UnwindSafe for Destination
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more