Expand description
Destination-bound signed request contract (SPEC-TRANSPORT-CONNECT, auth v2).
This module is pure: it neither reads configuration nor reserves nonces. Callers supply trusted destination context and persist the verified operation alongside its effects. A valid signature alone does not prevent replay.
Structs§
- Auth
Error - A malformed envelope, wrong destination, expired request or bad signature.
- Authorized
- Validated identity and operation binding for a transactional effect adapter.
- Context
- Trusted server identity. Values come from deployment configuration and the decoded request target, never from unverified forwarded headers.
- Headers
- Transport-independent v2 header values. Adapters must not normalize signed fields on read; noncanonical representations are rejected.
- Operation
- Fields authenticated by a v2 request signature. All string fields are bounded and newline-free, making the newline-separated encoding unambiguous.
- Part
Commitment - The fields of a
part:commitment (SPEC-TRANSPORT-CONNECT §7.6).
Enums§
- Commitment
Kind - The kind of a
ContentCommitment, without its fields. - Content
Commitment - A parsed auth v2 content commitment (SPEC-TRANSPORT-CONNECT §7.1, §7.6).
- Expected
Commitment - What a verifier expects the signed content commitment to be.
Constants§
- DOMAIN
- Domain/version. v1 requests are never interpreted as v2 requests.
- MAX_
CLOCK_ LEAD_ MS - Maximum permitted clock lead of the sender.
- MAX_
VALIDITY_ MS - Maximum validity interval; replay records must survive at least until expiry.
Functions§
- is_hex
- Whether a value is the fixed-length canonical lowercase hexadecimal form.
- validate_
audience - Validate the canonical deployment origin. DNS names are ASCII lowercase; international names must be their ASCII URL form. No userinfo, path, query, fragment, trailing dot or default port is accepted.
- verify_
headers - Verify adapter headers against deployment-owned context and actual content.
expected_commitmentis required for unary operations; withNone, anUploadPackhandler may defer that comparison until the first header, before attributed effects. Same asverify_headers_withwithExpectedCommitment::Exact, orExpectedCommitment::PackStreamforNone. - verify_
headers_ with - Verify adapter headers against deployment-owned context and actual
content, with the commitment expectation of a unary call, an
UploadPackstream or anUploadPartstream.