pub struct CredentialEntry {
pub id: Option<String>,
pub label: Option<String>,
pub sha256: Option<String>,
pub env: Option<String>,
pub principal: String,
pub memories: Option<Vec<String>>,
pub expires_at: Option<String>,
}Fields§
§id: Option<String>Stable, operator-chosen name for THIS credential — not the principal.
Two tokens for one principal (a laptop and a CI runner, or an old and
a new one mid-rotation) are otherwise indistinguishable: revoking one
means identifying a line by its digest, and no log line can ever name
which credential acted. The id appears on successful auth and in
whoami; it is never echoed on a failure, because a refused
secret must not confirm which credential it nearly matched.
Optional, with a derived fallback (CredentialEntry::id) — an
areev-auth.json written before ids existed must keep working across
an upgrade. A console that refuses to start because a new field is
missing is a worse security outcome than an ugly default: it gets
fixed by rolling back.
label: Option<String>Free-text note for humans ("CI runner, rotates quarterly").
sha256: Option<String>Lowercase hex SHA-256 of the bearer token.
env: Option<String>Name of the environment variable holding the bearer token.
principal: StringThe principal this credential authenticates as.
memories: Option<Vec<String>>Per-memory scope (the enterprise plane’s rule): when set, this
credential authenticates ONLY on services whose memory label is in
the list — one auth file shared across server instances, each token
reaching only its memories. None = every memory (the common
single-memory deployment).
expires_at: Option<String>Optional expiry (ISO-8601; "2026-12-31T23:59:59Z"). Past it, the
credential authenticates nobody — indistinguishably from an unknown
token, so an expired credential cannot be used to probe which ids
exist.
Deliberately OPTIONAL. A mandatory lifetime would break a homelab
console at 3am for a threat model it does not have; areev auth mint --expires 90d is the documented path for the deployments that want
one, and the startup banner names credentials expiring within 14 days.
Implementations§
Source§impl CredentialEntry
impl CredentialEntry
Sourcepub fn id(&self) -> String
pub fn id(&self) -> String
This credential’s effective id: the operator’s id when set, else a
stable one derived from what identifies the credential anyway.
Derivation is deliberately not positional (token-0, token-1):
an index shifts when an unrelated line is added, so areev auth revoke --id token-1 would eventually revoke the wrong credential —
the exact failure an id exists to prevent. A digest prefix and an
env-var name are both properties of the credential itself, so they
survive reordering.
Sourcepub fn is_expired_at(&self, now_ms: i64) -> bool
pub fn is_expired_at(&self, now_ms: i64) -> bool
Whether this credential is expired at now_ms.