pub struct OsKeychainBackend { /* private fields */ }Expand description
A KeychainBackend backed by the host OS credential store.
Construct with OsKeychainBackend::open, which returns None when no
usable OS store exists on this host. The crate performs no fallback; the
caller selects an alternative backend, as the example below does.
A storage location, not an access-control primitive: the crate’s own seal is the primary access control, so callers MUST NOT file plaintext secrets here. See the module docs for the per-platform access boundary and for why a machine/system service must not use this backend.
§Example
use std::sync::Arc;
use dig_keystore::backend::{KeychainBackend, OsKeychainBackend, FileBackend, BackendKey};
// Prefer the OS credential store; fall back to a file backend elsewhere.
let backend: Arc<dyn KeychainBackend> = match OsKeychainBackend::open("dig-app") {
Some(os) => Arc::new(os),
None => Arc::new(FileBackend::new("/var/lib/dig/keys")),
};
backend.write(&BackendKey::new("identity"), b"...").unwrap();Implementations§
Source§impl OsKeychainBackend
impl OsKeychainBackend
Sourcepub fn open(_service: impl Into<String>) -> Option<Self>
pub fn open(_service: impl Into<String>) -> Option<Self>
No OS credential store is used on this target (Linux / wasm) — always
returns None. The crate performs no fallback; choosing another
backend is the caller’s responsibility. See the module docs for why
Linux is excluded as a custody primary.
Trait Implementations§
Source§impl Debug for OsKeychainBackend
Redacted Debug — never prints service, account, or secret material.
impl Debug for OsKeychainBackend
Redacted Debug — never prints service, account, or secret material.
Source§impl KeychainBackend for OsKeychainBackend
impl KeychainBackend for OsKeychainBackend
Source§fn read(&self, key: &BackendKey) -> Result<Vec<u8>>
fn read(&self, key: &BackendKey) -> Result<Vec<u8>>
key. Read moreSource§fn write(&self, key: &BackendKey, data: &[u8]) -> Result<()>
fn write(&self, key: &BackendKey, data: &[u8]) -> Result<()>
data to key. Implementations should be atomic — a reader
seeing the key after this call must see either the old bytes or the
new bytes in full, never a torn mix.Source§fn delete(&self, key: &BackendKey) -> Result<()>
fn delete(&self, key: &BackendKey) -> Result<()>
key. Implementations should best-effort overwrite
the storage before removing so residual disk sectors do not retain the
ciphertext.Auto Trait Implementations§
impl !Freeze for OsKeychainBackend
impl !RefUnwindSafe for OsKeychainBackend
impl !UnwindSafe for OsKeychainBackend
impl Send for OsKeychainBackend
impl Sync for OsKeychainBackend
impl Unpin for OsKeychainBackend
impl UnsafeUnpin for OsKeychainBackend
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more