pub enum Request {
Hello {
nonce: String,
},
Put {
token: String,
repo: String,
passphrase: String,
},
Get {
token: String,
repo: String,
},
Drop {
token: String,
repo: Option<String>,
},
Status {
token: String,
},
Shutdown {
token: String,
},
}Expand description
What a client sends. Every variant that reads or changes what the agent
holds carries the token: there is no unauthenticated operation on the store,
not even Status, because whether an agent holds a passphrase for a given
repository is itself worth not answering.
Hello is the one exception and carries no token, because it is how the
client checks the server before trusting it with anything — a check that
cannot itself require the check to have happened.
That does make Hello answerable by anyone who can reach the port, which on
loopback is every account on the machine. What it gives them is an HMAC over
a nonce of their choosing under a 256-bit key, and the knowledge that an
agent is running. Neither is a route to the token or to a passphrase, but
“the port answers nothing without the token” is not true and should not be
relied on as though it were.
Variants§
Hello
Ask the peer to prove it holds the token, by returning a MAC over a nonce the client chose.
Put
Store a passphrase for repo.
Get
Retrieve the passphrase for repo, if one is held and unexpired.
Drop
Forget one repository’s passphrase, or all of them when repo is None.
Status
How many entries are held, and with what idle timeout.
Shutdown
Stop the agent, clearing everything it holds.