Expand description
The OAuth confidential-client signing key, and the documents derived from it.
A production atproto OAuth client is a confidential client: it authenticates
to the PDS with private_key_jwt, signing a client assertion with a long-lived
ES256 key. That key must
- survive restarts (it anchors
client_id, so regenerating it invalidates in-flight authorizations), - be published in public form at
jwks_uriso the PDS can verify assertions, - and not sit on disk in the clear whenever a codec key is configured.
So it is persisted as a JWK, AEAD-encrypted with super::crypto. The JWK
format is deliberately the same one the Node sidecar writes, so a rollback
to the sidecar can still read a key this module created, and vice versa.
That third requirement is conditional, and the condition is load-bearing:
super::crypto::Codec::Null is a pass-through, so a deployment with no key
configured writes the private JWK as plaintext. The sidecar refuses to boot
in production without a key; the equivalent guard for this path belongs in
config validation at cutover, and until then Codec::Null is a dev-only
arrangement rather than an enforced one.
The thumbprint is RFC 7638 and is computed over the PUBLIC members only
(crv, kty, x, y) in lexicographic order — never over the raw JWK
text, and never including d.
Structs§
- Signing
Key - The confidential client’s long-lived ES256 signing key.
Functions§
- load_
or_ create - Load the signing key from
path, generating and persisting one if absent.