pub struct ReloadableVerifier { /* private fields */ }Expand description
A hot-reloadable Verifier holder for key rotation: the
active verifier (its published Ed25519 key set) can be swapped at
runtime — e.g. by a periodic re-fetch of /.well-known/paseto-keys —
without a restart, while the per-request verify path stays
lock-light.
It wraps an Arc<Verifier> behind an RwLock (the same shape as
ReloadablePolicy). Per request a guard
calls current — a brief read-lock returning a cheap
Arc clone it verifies against; a refresh calls
store — a brief write-lock swapping the Arc. A
verification in flight during a refresh finishes against its snapshot.
Poison-safe: a panic elsewhere never makes current/store panic.
The refresh trigger (a periodic timer, a signal) is the service’s concern — this type only holds and swaps the value. A refresh should keep the current verifier on a fetch failure (never swap to an empty key set), so a transient auth-service outage cannot lock everyone out.
(No Debug — Verifier deliberately does not derive it, so its key
material never lands in a debug log.)
Implementations§
Source§impl ReloadableVerifier
impl ReloadableVerifier
Sourcepub fn new(verifier: Verifier) -> Self
pub fn new(verifier: Verifier) -> Self
Wrap an initial verifier (e.g. the one built/fetched at boot).