Skip to main content

load_or_create

Function load_or_create 

Source
pub fn load_or_create(
    path: &Path,
    codec: &Codec,
    kid: &str,
) -> Result<SigningKey>
Expand description

Load the signing key from path, generating and persisting one if absent.

A file that exists but cannot be decrypted or parsed is a hard ERROR, never a silent regeneration: the key anchors client_id, so quietly replacing it would invalidate every in-flight authorization and every cached JWKS entry. Refusing to boot is the safer failure.

Migrate-on-read: a legacy PLAINTEXT key file is loaded and immediately re-written encrypted, without changing the key.