Expand description
Turning command-line spellings into the canonical statements of SPEC-WRITE-GRANTS §3, §5.1 and §9.1.
The statement codecs in mkit-attest never sort or repair, so this
module does the canonicalizing a person expects: --cap write,read becomes
read,write, audiences and ref scopes are sorted and deduplicated, and ref
flags are put in cufd order.
Structs§
- Grant
Spec - Everything
mkit grant createcollects before the owner is known.
Enums§
- Repo
Selector - The repositories a new grant covers.
Constants§
- DEFAULT_
GRANT_ TTL - Default
--ttlof a grant. - DEFAULT_
STATEMENT_ TTL_ MS - Default lifetime of an epoch or visibility statement. Short on purpose: the statement is signed for one command, and a shorter window narrows what a leaked statement can do.
- MAX_
TTL_ SECS - Longest lifetime
--ttlaccepts (§1.1): 30 days.
Functions§
- build_
epoch - Build an epoch statement raising
namespacetonew_epoch. - build_
grant - Build the grant for
namespace, created atnow_ms. - build_
visibility - Build a visibility statement for
repository. - canonical_
audiences - Sort and deduplicate audiences, and check each against §3.2.
- canonical_
capabilities - Accept
read,writeor both in either order, and spell them canonically (§3.2):read,read,writeorwrite. - canonical_
ref_ scopes - Parse
pattern=flagsentries, put the flags incufdorder, merge entries with the same pattern (a union, which is what §8.1 computes anyway) and sort. - check_
ref_ scopes - §3.3: ref scopes go with write and only with write.
- parse_
ttl 30d,12h,90m,3600s, or bare seconds; at most 30 days. Returns milliseconds.- statement_
error - A statement the codec refused, phrased for a person.
- statement_
lifetime_ ms - How long an epoch or visibility statement stays valid: the default, or,
when the command will wait longer than that for the server, the wait plus a
little slack, so a re-send late in a long
--timeoutis not rejected as expired. Never above the 30-day statement maximum.