Skip to main content

ReloadableVerifier

Struct ReloadableVerifier 

Source
pub struct ReloadableVerifier { /* private fields */ }
Expand description

A hot-reloadable Verifier holder for key rotation: the active verifier (its published Ed25519 key set) can be swapped at runtime — e.g. by a periodic re-fetch of /.well-known/paseto-keys — without a restart, while the per-request verify path stays lock-light.

It wraps an Arc<Verifier> behind an RwLock (the same shape as ReloadablePolicy). Per request a guard calls current — a brief read-lock returning a cheap Arc clone it verifies against; a refresh calls store — a brief write-lock swapping the Arc. A verification in flight during a refresh finishes against its snapshot. Poison-safe: a panic elsewhere never makes current/store panic.

The refresh trigger (a periodic timer, a signal) is the service’s concern — this type only holds and swaps the value. A refresh should keep the current verifier on a fetch failure (never swap to an empty key set), so a transient auth-service outage cannot lock everyone out.

(No Debug — Verifier deliberately does not derive it, so its key material never lands in a debug log.)

Implementations§

Source§

impl ReloadableVerifier

Source

pub fn new(verifier: Verifier) -> Self

Wrap an initial verifier (e.g. the one built/fetched at boot).

Source

pub fn current(&self) -> Arc<Verifier> ⓘ

The currently active verifier — a cheap Arc clone taken under a brief read-lock. Verify against the returned snapshot; a concurrent store does not affect it.

Source

pub fn store(&self, verifier: Verifier)

Atomically replace the active verifier (a brief write-lock) — e.g. after re-fetching a rotated key set. New requests verify against the new key set; in-flight ones finish against their snapshot.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.