1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
[]
= ["macula-rust-ffi"]
[]
= "macula-rust"
= "0.2.3"
= "2021"
= "1.85"
= ["Macula <raf.lefever@erlef.org>"]
= "Rust port of macula's SDK (client/leaf) wire protocol — mobile first, not mobile-only. See plans/PLAN_WIRE_PROTOCOL.md."
= "Apache-2.0"
= "https://github.com/macula-io/macula-rust"
= "https://github.com/macula-io/macula-rust"
= "README.md"
= ["mesh-network", "quic", "p2p", "ed25519", "decentralized"]
= ["network-programming", "cryptography"]
[]
= "forbid"
[]
= { = "deny", = -1 }
[]
= { = "3.0", = ["rand_core"] }
= "0.10"
= "0.11"
= "0.11"
= { = "0.23", = false, = ["ring", "logging", "std", "tls12"] }
= "1.0"
= "0.18"
# cert_chain.rs: pure X.509 path validation (no hostname/SAN check, unlike
# rustls's own ServerCertVerifier machinery in cert.rs) to a caller-supplied
# realm CA — already transitively pulled in by rustls, declared directly
# here since cert_chain.rs uses its EndEntityCert::verify_for_usage API.
= { = "0.103", = ["ring"] }
= { = "1", = ["full"] }
= { = "1", = ["v7"] }
= "1.5"
# ucan.rs: JWT-shaped token (de)serialization, matching the reference
# macula_ucan_nif's own dependency choices exactly (its Cargo.toml has no
# UCAN-spec crate either, only these same generic primitives).
= { = "1", = ["derive"] }
= "1"
= "0.23"
# keystore.rs: platform-native secure storage for a persisted seed
# (Keychain via Security.framework on macOS/iOS, Secret Service via D-Bus
# on Linux, Credential Manager on Windows, Keystore via JNI on Android —
# each selected automatically per target by keyring's own Cargo.toml
# target-cfg blocks, not by any feature switching we do here). `v1`
# (default) already covers macOS/iOS/Windows/Linux; `android-native-keyring-store`
# is added explicitly since it is NOT part of `v1`'s default set.
= { = "4", = ["android-native-keyring-store"] }
# keystore.rs's LinuxKeyutilsStore: a second, independently-selectable
# KeyStore backend demonstrating the trait is genuinely overridable, not
# just declared to be — uses the kernel's own keyutils facility directly
# (no D-Bus/secret-service daemon required), which is what makes it real-
# world useful on headless Linux (containers, CI, this dev sandbox) where
# no secret-service provider is running. Built via keyring-core's
# CredentialStoreApi::build() directly against one Store instance, NOT
# through keyring's own v1::Entry/set_default_store (a process-global,
# would collide with KeyringStore's own default-store selection if both
# were used in one process).
[]
= "1"
= "1"
[]
= "0.4"
= "3"
# Test-only: generates synthetic Ed25519 certs to unit-test
# PubkeyPinVerifier's matching logic without needing a live station that
# happens to present that cert type — see src/cert.rs's tests. Not a
# runtime dependency of the crate itself (see src/cert.rs's module doc:
# a dialing client never generates or presents a cert of its own).
# Test-only, cert_chain.rs's own tests: signed_by() needs a SubjectPublicKeyInfo
# constructed from a raw advertiser Ed25519 pubkey rather than a freshly
# rcgen-generated one (the leaf must bind the SAME key that signed the
# advertisement) — SubjectPublicKeyInfo::from_der needs this feature.
= { = "0.14", = false, = ["pem", "ring", "x509-parser"] }
# Test-only, cert_chain.rs's own tests: rcgen's CertificateParams
# not_before/not_after fields take this crate's OffsetDateTime directly;
# not re-exported by rcgen, so declared explicitly (already transitively
# present via rcgen itself).
= "0.3"