Skip to main content

GhostkeyRequest

Enum GhostkeyRequest 

Source
#[non_exhaustive]
pub enum GhostkeyRequest {
Show 20 variants ImportGhostKey { certificate_pem: String, signing_key_pem: String, master_verifying_key_pem: Option<String>, }, ListGhostKeys, GetGhostKey { fingerprint: String, }, GetCertificate { fingerprint: String, }, DeleteGhostKey { fingerprint: String, }, SetLabel { fingerprint: String, label: String, }, SignMessage { fingerprint: String, message: Vec<u8>, }, SignWithDefault { message: Vec<u8>, }, SetDefaultKey { fingerprint: String, }, GetDefaultKey, VerifySignedMessage { signed_message: Vec<u8>, }, ExportGhostKey { fingerprint: String, }, ExportAllGhostKeys, GrantPermission { fingerprint: String, requestor: SignatureRequestor, }, RevokePermission { fingerprint: String, requestor: SignatureRequestor, }, ListPermissions { fingerprint: String, }, TestPermissionPrompt { fingerprint: String, }, RequestAnyAccess, HasIdentity, MarkBackedUp { fingerprint: String, },
}
Expand description

Requests from UI or other delegates to the ghostkey delegate.

Variants (Non-exhaustive)§

This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
§

ImportGhostKey

Import a ghostkey from PEM-armored certificate and signing key. If master_verifying_key_pem is None, uses the hardcoded Freenet master key.

Fields

§certificate_pem: String
§signing_key_pem: String
§master_verifying_key_pem: Option<String>
§

ListGhostKeys

List all stored ghostkeys.

§

GetGhostKey

Get details for a specific ghostkey.

Fields

§fingerprint: String
§

GetCertificate

Get just the public certificate (for sharing with counterparties).

Fields

§fingerprint: String
§

DeleteGhostKey

Delete a stored ghostkey.

Fields

§fingerprint: String
§

SetLabel

Set a user-friendly label.

Fields

§fingerprint: String
§label: String
§

SignMessage

Sign a message with a specific ghostkey. The delegate scopes the signature to the requestor.

Fields

§fingerprint: String
§message: Vec<u8>
§

SignWithDefault

Sign a message with the user’s default ghostkey (highest-tier key, or user-overridden via SetDefaultKey). Apps should prefer this over SignMessage – it avoids needing to know about specific fingerprints.

Fields

§message: Vec<u8>
§

SetDefaultKey

Set which ghostkey is the default for signing.

Fields

§fingerprint: String
§

GetDefaultKey

Get the current default ghostkey fingerprint.

Returns DefaultKeyResult { fingerprint: None } when the caller has no Sign grant on any key, which is NOT the same as the user having no ghostkey – use HasIdentity for that question. This request never prompts: it is a question, and an app must not be able to put a dialog in front of the user just by asking one. SignWithDefault is the one that prompts, because it acts.

§

VerifySignedMessage

Verify a signed message produced by this delegate.

Fields

§signed_message: Vec<u8>
§

ExportGhostKey

Export a ghostkey’s certificate and signing key for backup. Security-sensitive: returns the private signing key.

Fields

§fingerprint: String
§

ExportAllGhostKeys

Export all ghostkeys for backup.

§

GrantPermission

Grant an application or delegate permission to use a ghostkey.

Fields

§fingerprint: String
§

RevokePermission

Revoke a previously granted permission.

Fields

§fingerprint: String
§

ListPermissions

List permissions for a ghostkey.

Fields

§fingerprint: String
§

TestPermissionPrompt

Debug: force a permission prompt regardless of existing permissions.

Fields

§fingerprint: String
§

RequestAnyAccess

A third-party app asks for any one of the user’s ghostkeys. The delegate emits a user prompt that lets the user pick a key (or deny). On approval the delegate grants {ReadPublic, Sign} to the requesting app for the chosen fingerprint and replies with a single-element GhostKeyList containing that key.

The request takes no fields on purpose: the only identifier the user sees in the prompt is the runtime-attested requestor (a truncated contract id). Letting the app supply free text would open a phishing surface (a hostile app could write text designed to look like Freenet UI chrome). Apps that want to communicate purpose to the user should do so in their own UI before this flow runs.

§

HasIdentity

Ask whether the user holds any ghostkey at all, WITHOUT prompting.

Apps need this and today have no way to get it. RequestAnyAccess always prompts, so it cannot be polled. ListGhostKeys is filtered by permission, so an app with no grant yet sees an empty list and cannot tell “the user has none” from “I have not been granted access”.

The motivating case is the purchase round trip: an app that sends a user off to buy a ghostkey wants to notice when they come back, and polling a prompt is not an option.

What this discloses without consent is a count. That is more than the bare existence bit NoIdentityAvailable already leaks to anyone who asks for a signature, and the trade is deliberate: no fingerprints, labels or tiers are exposed, a count cannot be correlated across users, and the alternative is that the vault cannot tell a half-lost identity from a healthy one.

§

MarkBackedUp

Record that the user has exported this identity, so the vault can stop warning that it is the only copy. Requires Export scope, so only the vault can set it – a third-party app must not be able to silence a warning about a key it does not hold a backup of.

Fields

§fingerprint: String

Trait Implementations§

Source§

impl Clone for GhostkeyRequest

Source§

fn clone(&self) -> GhostkeyRequest

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for GhostkeyRequest

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for GhostkeyRequest

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for GhostkeyRequest

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more