Skip to main content

DbKeyStore

Struct DbKeyStore 

Source
pub struct DbKeyStore { /* private fields */ }

Implementations§

Source§

impl DbKeyStore

Source

pub fn new(config: DbKeyStoreConfig) -> Result<Arc<DbKeyStore>>

Source

pub fn new_with_modifiers( modifiers: &HashMap<&str, &str>, ) -> Result<Arc<DbKeyStore>>

Source

pub fn is_encrypted(&self) -> bool

Returns true if the db file is encrypted

Source

pub fn path(&self) -> String

Returns path to database file

Source

pub fn rekey( source_path: impl AsRef<Path>, source_opts: Option<EncryptionOpts>, dest_path: impl AsRef<Path>, dest_opts: Option<EncryptionOpts>, ) -> Result<RekeyOutcome>

Rekey a keystore out-of-place: read every credential from the source database and write it into a freshly created destination database.

This is used to add, remove, or rotate the on-disk encryption key (a DEK rotation): pass dest_opts = Some(..) to add or rotate encryption, or dest_opts = None to write an unencrypted copy. source_opts must supply the cipher/key the source was written with (or None if the source is unencrypted).

The operation is non-destructive to the source: the source database is opened read-only-ish (no rows are mutated) and left fully intact, and the destination is fully written before returning. Callers that own a verify-then-swap-then-delete sequence (for example secret-vault rotate-dek) should treat the returned destination as the new candidate and only retire the source after independently verifying it.

Each credential is copied with its service, user, uuid, comment, and secret preserved. Whether the source enforced (service, user) uniqueness is detected from the source schema and mirrored on the destination so ambiguous keystores round-trip unchanged.

dest_path must not already exist. Returns a RekeyOutcome describing how many credentials were copied. No secret material is logged or included in any returned value.

Trait Implementations§

Source§

impl Clone for DbKeyStore

Source§

fn clone(&self) -> DbKeyStore

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl CredentialStoreApi for DbKeyStore

Source§

fn build( &self, service: &str, user: &str, modifiers: Option<&HashMap<&str, &str>>, ) -> Result<Entry>

Create a credential entry for service and user. Service and user must be non-empty, and within the length limits. (<=1024 chars) Supported modifiers: uuid, comment.

Source§

fn vendor(&self) -> String

The name of the “vendor” that provides this store. Read more
Source§

fn id(&self) -> String

The ID of this credential store instance. Read more
Source§

fn search(&self, spec: &HashMap<&str, &str>) -> Result<Vec<Entry>>

Search for credentials that match the given spec. Read more
Source§

fn as_any(&self) -> &dyn Any

Return the inner store object cast to Any. Read more
Source§

fn persistence(&self) -> CredentialPersistence

The lifetime of credentials produced by this builder. Read more
Source§

fn debug_fmt(&self, f: &mut Formatter<'_>) -> Result

The Debug trait call for the object. Read more
Source§

impl Debug for DbKeyStore

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<K, Q> Comparable<Q> for K
where K: Borrow<Q> + ?Sized, Q: Ord + ?Sized,

Source§

fn compare(&self, key: &Q) -> Ordering

Compare self to key and return their ordering.
Source§

impl<K, Q> Equivalent<Q> for K
where K: Borrow<Q> + ?Sized, Q: Eq + ?Sized,

Source§

fn equivalent(&self, key: &Q) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more