Skip to main content

Module write_auth

Module write_auth 

Source
Expand description

Destination-bound signed request contract (SPEC-TRANSPORT-CONNECT, auth v2).

This module is pure: it neither reads configuration nor reserves nonces. Callers supply trusted destination context and persist the verified operation alongside its effects. A valid signature alone does not prevent replay.

Structs§

AuthError
A malformed envelope, wrong destination, expired request or bad signature.
Authorized
Validated identity and operation binding for a transactional effect adapter.
Context
Trusted server identity. Values come from deployment configuration and the decoded request target, never from unverified forwarded headers.
Headers
Transport-independent v2 header values. Adapters must not normalize signed fields on read; noncanonical representations are rejected.
Operation
Fields authenticated by a v2 request signature. All string fields are bounded and newline-free, making the newline-separated encoding unambiguous.
PartCommitment
The fields of a part: commitment (SPEC-TRANSPORT-CONNECT §7.6).

Enums§

CommitmentKind
The kind of a ContentCommitment, without its fields.
ContentCommitment
A parsed auth v2 content commitment (SPEC-TRANSPORT-CONNECT §7.1, §7.6).
ExpectedCommitment
What a verifier expects the signed content commitment to be.

Constants§

DOMAIN
Domain/version. v1 requests are never interpreted as v2 requests.
MAX_CLOCK_LEAD_MS
Maximum permitted clock lead of the sender.
MAX_VALIDITY_MS
Maximum validity interval; replay records must survive at least until expiry.

Functions§

is_hex
Whether a value is the fixed-length canonical lowercase hexadecimal form.
validate_audience
Validate the canonical deployment origin. DNS names are ASCII lowercase; international names must be their ASCII URL form. No userinfo, path, query, fragment, trailing dot or default port is accepted.
verify_headers
Verify adapter headers against deployment-owned context and actual content. expected_commitment is required for unary operations; with None, an UploadPack handler may defer that comparison until the first header, before attributed effects. Same as verify_headers_with with ExpectedCommitment::Exact, or ExpectedCommitment::PackStream for None.
verify_headers_with
Verify adapter headers against deployment-owned context and actual content, with the commitment expectation of a unary call, an UploadPack stream or an UploadPart stream.