#[non_exhaustive]pub struct VerifiedAuth {
pub signer: [u8; 32],
pub replay_scope: Hash,
pub fingerprint: Hash,
pub nonce: String,
pub commitment: Commitment,
pub expires_at_ms: i64,
pub created_at_ms: i64,
}Expand description
A verified auth v2 authorization, decoded from
mkit_core::write_auth::Authorized.
Non-exhaustive: later milestones add fields. Build it with
VerifiedAuth::try_from(&authorized).
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.signer: [u8; 32]The signer’s raw Ed25519 public key.
replay_scope: HashReplay namespace: destination, repository, signer and nonce.
fingerprint: HashDigest of every signed field; a replay with a different fingerprint is rejected.
nonce: StringThe operation nonce (idempotency key).
commitment: CommitmentThe signed content commitment.
expires_at_ms: i64Expiry, Unix epoch milliseconds; replay records outlive it.
created_at_ms: i64The signed x-created-at, Unix epoch milliseconds: when the client
signed, so what it knew of the repository is at least this old
(the ticketless §9.4 lag proxy, WP-4.17). 0 on a value built
without the envelope, which opens no lag window.
Trait Implementations§
Source§impl Clone for VerifiedAuth
impl Clone for VerifiedAuth
Source§impl Debug for VerifiedAuth
impl Debug for VerifiedAuth
impl Eq for VerifiedAuth
Source§impl PartialEq for VerifiedAuth
impl PartialEq for VerifiedAuth
impl StructuralPartialEq for VerifiedAuth
Source§impl TryFrom<&Authorized> for VerifiedAuth
impl TryFrom<&Authorized> for VerifiedAuth
Source§fn try_from(auth: &Authorized) -> Result<Self, Self::Error>
fn try_from(auth: &Authorized) -> Result<Self, Self::Error>
Decode the hex fields. verify_headers only produces canonical
values, so a failure here means a hand-built or corrupted value.