pub const STATE_MTLS_CA_SECRET: &str = "polychrome-state-mtls-ca";
pub const STATE_MTLS_SERVER_SECRET: &str = "polychrome-state-mtls-server";
pub const STATE_MTLS_CLIENT_SECRET: &str = "polychrome-state-mtls-client";
pub const STATE_ATTESTATION_SECRET: &str = "polychrome-state-attestation";
pub const SCAFFOLD_TLS_SECRET: &str = "polychrome-scaffold-tls";
pub const RESERVED_SECRET_NAMES: [&str; 5] = [
STATE_MTLS_CA_SECRET,
STATE_MTLS_SERVER_SECRET,
STATE_MTLS_CLIENT_SECRET,
STATE_ATTESTATION_SECRET,
SCAFFOLD_TLS_SECRET,
];
pub const CONTROL_KEY_SECRET_PREFIX: &str = "polychrome-wallet-key-";
#[derive(Debug, Clone, PartialEq, Eq, thiserror::Error)]
#[error(
"Secret \"{secret}\" is a name Polychrome reserves for its own key material, so a tool \
service cannot read it. Point spec.auth.bearerSecretRef.name at a Secret you created for \
this connector's token."
)]
pub struct ReservedSecret {
pub secret: String,
}
pub fn check_secret_ref(name: &str) -> Result<(), ReservedSecret> {
if RESERVED_SECRET_NAMES.contains(&name) || name.starts_with(CONTROL_KEY_SECRET_PREFIX) {
return Err(ReservedSecret {
secret: name.to_owned(),
});
}
Ok(())
}
#[cfg(test)]
mod tests {
#![allow(clippy::pedantic, clippy::nursery, missing_docs)]
use super::*;
#[test]
fn each_state_secret_is_refused_by_name() {
for name in RESERVED_SECRET_NAMES {
let err = check_secret_ref(name).expect_err("reserved name must be refused");
assert_eq!(err.secret, name);
assert!(
err.to_string().contains(name),
"the refusal must name the Secret it refused"
);
}
}
#[test]
fn the_scaffold_tls_secret_is_refused_by_name() {
let err = check_secret_ref(SCAFFOLD_TLS_SECRET)
.expect_err("the scaffold TLS Secret must be refused");
assert_eq!(err.secret, SCAFFOLD_TLS_SECRET);
assert!(
RESERVED_SECRET_NAMES.contains(&SCAFFOLD_TLS_SECRET),
"the guard's list must name it, so every resolver test covers it"
);
}
#[test]
fn the_control_signing_key_prefix_is_refused() {
let name = format!("{CONTROL_KEY_SECRET_PREFIX}{}", "ab".repeat(32));
let err = check_secret_ref(&name).expect_err("a control signing key must be refused");
assert_eq!(err.secret, name);
}
#[test]
fn an_author_chosen_secret_still_resolves() {
for name in [
"acme-mcp-token",
"polychrome-state-mtls",
"my-polychrome-state-attestation",
"polychrome-wallet",
"",
] {
assert!(
check_secret_ref(name).is_ok(),
"{name} is not reserved and must resolve"
);
}
}
}