Skip to main content

Module token

Module token 

Source
Expand description

Stateless authenticated upload tickets. Stateless upload ticket authentication (STC §7.6). Only the key id is inspected before authenticating the bytes; claims are decoded afterwards.

Structs§

TicketClaims
Authenticated, deployment-bound upload claims. Clients treat their encoding as opaque; no metadata read is needed to verify them.
TicketKeyError
Invalid deployment key configuration. Never contains secret input.
TicketKeys
Signing and accepted keys. The first key signs and every listed key verifies. Secrets, including derived MAC keys, are zeroed when dropped.

Constants§

PART_RECEIPT_CONTEXT
Reserved for WP-1.11: derive receipt keys from the same deployment secret.
TICKET_TOKEN_CONTEXT
Domain separator for the ticket-token MAC key.