pub struct CredentialMap {
pub version: u32,
pub tokens: Vec<CredentialEntry>,
}Expand description
The host-side credential map (areev-auth.json): tokens → principal
names, nothing else. No verbs, no namespaces, no raw secrets — a token is
referenced by its SHA-256 or by the env var that holds it, so the file is
inert if stolen or synced.
Fields§
§version: u32§tokens: Vec<CredentialEntry>Implementations§
Source§impl CredentialMap
impl CredentialMap
Sourcepub fn from_json(s: &str) -> Result<CredentialMap>
pub fn from_json(s: &str) -> Result<CredentialMap>
Parse and validate. Fail closed: unknown keys, a bad version, an entry with both or neither credential form, or a malformed digest all refuse the whole map.
Sourcepub fn resolve(&self, presented: &str) -> Result<&str>
pub fn resolve(&self, presented: &str) -> Result<&str>
Resolve a presented bearer token to its principal. The error carries no part of the token — a refused secret must not leak into logs.
Sourcepub fn resolve_for_memory(&self, presented: &str, memory: &str) -> Result<&str>
pub fn resolve_for_memory(&self, presented: &str, memory: &str) -> Result<&str>
Resolve a token FOR ONE MEMORY: like resolve, but
a credential carrying a memories scope only authenticates when
memory is listed. The refusal is indistinguishable from an unknown
token — a scoped credential must not confirm which memories exist.
Sourcepub fn knows_principal(&self, principal: &str) -> Result<()>
pub fn knows_principal(&self, principal: &str) -> Result<()>
Whether any credential authenticates as this principal — surfaces that require a known principal name use this to refuse typos early.