pub struct RetrievalConfig { /* private fields */ }Expand description
Dedicated active/retained MAC keys and the incoming scanner allowlist.
Implementations§
Source§impl RetrievalConfig
impl RetrievalConfig
Sourcepub fn parse(keys: &str, scanners: &str) -> Result<Self, ConfigError>
pub fn parse(keys: &str, scanners: &str) -> Result<Self, ConfigError>
Parse exactly one active <id> <64 hex> line, followed by up to 15
retained <id> <64 hex> <retired_at_ms> lines. Scanner keys are
1–32 distinct, non-weak Ed25519 public keys, one per line.
Blank lines and whole-line comments are ignored.
§Errors
Invalid grammar, duplicate/weak keys or cross-role reuse.
Sourcepub fn scanner_keys(&self) -> impl Iterator<Item = Hash> + '_
pub fn scanner_keys(&self) -> impl Iterator<Item = Hash> + '_
Incoming scanner keys, for authentication and deployment separation.
Sourcepub fn check_secret(&self, secret: &Hash) -> Result<(), ConfigError>
pub fn check_secret(&self, secret: &Hash) -> Result<(), ConfigError>
Refuse reuse of any raw secret in another deployment role.
§Errors
Any active/retained MAC secret or scanner key equals the supplied key.
Sourcepub fn check_role_keys(
&self,
public: &[Hash],
seeds: &[Hash],
) -> Result<(), ConfigError>
pub fn check_role_keys( &self, public: &[Hash], seeds: &[Hash], ) -> Result<(), ConfigError>
Compare all active/retained retrieval and scanner keys with role keys. Public comparisons include Ed25519 public keys derived from MAC secrets, so a signing seed reused as a MAC secret cannot evade startup checks.
§Errors
A cross-role collision, including between scanners and retrieval keys.
Source§impl RetrievalConfig
impl RetrievalConfig
Sourcepub fn mint(
&self,
audience: &str,
inspection_id: &str,
assignment: &Assignment,
timeout: Duration,
now_ms: u64,
) -> Result<InspectRetrieval, ServerError>
pub fn mint( &self, audience: &str, inspection_id: &str, assignment: &Assignment, timeout: Duration, now_ms: u64, ) -> Result<InspectRetrieval, ServerError>
Mint a fresh capability for one Inspect attempt. Its stable inspection id survives retry; the nonce and capability are always freshly minted.
§Errors
Invalid assignment/timeout, unavailable randomness or encoding.