Skip to main content

RecordWithNonce

Struct RecordWithNonce 

pub struct RecordWithNonce {
    pub record: EncryptedRecord,
    pub selector: [u8; 16],
}
Expand description

A Decryptable pairing an EncryptedRecord with the tokenized selector that binds it.

The SteVec envelope wire format stores one key header per document and ties each entry to its stored selector instead of the data key’s IV. A consumer decrypting such an entry reconstructs the record from the header + the entry’s ciphertext and pairs it with the entry’s 16-byte selector here. The selector is the single source of both bindings: the AEAD nonce is its first 12 bytes (Decryptable::nonce_override) and the full 16 bytes are bound into the AAD (Decryptable::aad_selector), so the ciphertext is authenticated against the entire selector. Every decrypt pipeline honours both.

Fields§

§record: EncryptedRecord§selector: [u8; 16]

Trait Implementations§

§

impl Debug for RecordWithNonce

§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
§

impl Decryptable for RecordWithNonce

§

type Error = Infallible

§

fn keyset_id(&self) -> Option<Uuid>

The keyset ID associated with the record, if any.
§

fn retrieve_key_payload<'a>( &'a self, ) -> Result<RetrieveKeyPayload<'a>, Self::Error>

The payload used to retrieve the key for decryption.
§

fn into_encrypted_record(self) -> Result<EncryptedRecord, Self::Error>

Convert the record into an EncryptedRecord.
§

fn nonce_override(&self) -> Option<[u8; 12]>

The explicit AEAD nonce for this record, when the wire format derives it from something other than the data key’s IV. SteVec entries under the envelope wire format derive it from the entry’s stored selector (nonce = selector_bytes[..12]); classic records return None and decrypt with the IV-derived nonce.
§

fn aad_selector(&self) -> Option<[u8; 16]>

The full 16-byte tokenized selector to bind into the AEAD AAD, when the wire format ties the ciphertext to a selector. The nonce only covers the first 12 selector bytes, so binding all 16 here authenticates the whole selector — a stored selector cannot be mutated (even in its last 4 bytes) without the entry failing to decrypt. SteVec entries return their selector; classic records return None and add nothing to the AAD.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> AuthStrategyBounds for T
where T: Send + Sync + 'static,

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: Rng + ?Sized, Self: FakeBase<U>,

Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: Rng + ?Sized, Self: FakeBase<U>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more