Skip to main content

Module spec

Module spec 

Source
Expand description

Turning command-line spellings into the canonical statements of SPEC-WRITE-GRANTS §3, §5.1 and §9.1.

The statement codecs in mkit-attest never sort or repair, so this module does the canonicalizing a person expects: --cap write,read becomes read,write, audiences and ref scopes are sorted and deduplicated, and ref flags are put in cufd order.

Structs§

GrantSpec
Everything mkit grant create collects before the owner is known.

Enums§

RepoSelector
The repositories a new grant covers.

Constants§

DEFAULT_GRANT_TTL
Default --ttl of a grant.
DEFAULT_STATEMENT_TTL_MS
Default lifetime of an epoch or visibility statement. Short on purpose: the statement is signed for one command, and a shorter window narrows what a leaked statement can do.
MAX_TTL_SECS
Longest lifetime --ttl accepts (§1.1): 30 days.

Functions§

build_epoch
Build an epoch statement raising namespace to new_epoch.
build_grant
Build the grant for namespace, created at now_ms.
build_visibility
Build a visibility statement for repository.
canonical_audiences
Sort and deduplicate audiences, and check each against §3.2.
canonical_capabilities
Accept read, write or both in either order, and spell them canonically (§3.2): read, read,write or write.
canonical_ref_scopes
Parse pattern=flags entries, put the flags in cufd order, merge entries with the same pattern (a union, which is what §8.1 computes anyway) and sort.
check_ref_scopes
§3.3: ref scopes go with write and only with write.
parse_ttl
30d, 12h, 90m, 3600s, or bare seconds; at most 30 days. Returns milliseconds.
statement_error
A statement the codec refused, phrased for a person.
statement_lifetime_ms
How long an epoch or visibility statement stays valid: the default, or, when the command will wait longer than that for the server, the wait plus a little slack, so a re-send late in a long --timeout is not rejected as expired. Never above the 30-day statement maximum.