pub enum AccountRefProvenance {
LiveClaim,
StoredLogin,
}Expand description
The two ways an account identity reaches the wire, with opposite staleness properties.
The discriminant says a value could be wrong, not that it is: the
frozen branch goes stale only if a record is re-pointed without a
re-login. A consumer holding a Self::StoredLogin value knows it needs
watching; a Self::LiveClaim value re-corrects on every read.
This enum is CLOSED on purpose — identity-bearing, not diagnostic. An unknown provenance must refuse to decode rather than default: a wrong guess here poisons joins silently, which is worse than a loud decode error on a version skew.
WHAT CLOSURE COSTS: because decoders refuse unknown spellings, adding a variant is a WIRE-BREAKING change for every consumer on an older crate version — a coordinated version boundary across all adopters, never an additive edit. That cost is deliberate. It is also a boundary nobody should be crossing:
This enum discriminates STALENESS AMONG CUSTODIAN-VOUCHED VALUES. A
consumer-derived identity — parsed from a logged-in page, say — is not a
third staleness case: it changes WHO VOUCHES, and belongs in its own
field rather than as a variant here. AccountIdentity::account_ref
means “the custodian observed this”; a value the custodian did not vouch
for does not belong in it at any spelling, because then a provenance tag
does load-bearing work AGAINST its own field’s semantics — the shape
that fails quietly. A separate field is additive and breaks no decoder;
a variant here is the coordinated wire boundary AND an unattested value
in an attested field — the expensive mistake and the semantic one at
once.
Variants§
LiveClaim
Parsed from the served token at read time — re-derived on every get, self-correcting.
StoredLogin
Stored at login time and returned unchanged — frozen, can go stale silently if the account is re-pointed without a re-login.