Expand description
Stateless authenticated upload tickets. Stateless upload ticket authentication (STC §7.6). Only the key id is inspected before authenticating the bytes; claims are decoded afterwards.
Structs§
- Ticket
Claims - Authenticated, deployment-bound upload claims. Clients treat their encoding as opaque; no metadata read is needed to verify them.
- Ticket
KeyError - Invalid deployment key configuration. Never contains secret input.
- Ticket
Keys - Signing and accepted keys. The first key signs and every listed key verifies. Secrets, including derived MAC keys, are zeroed when dropped.
Constants§
- PART_
RECEIPT_ CONTEXT - Reserved for WP-1.11: derive receipt keys from the same deployment secret.
- TICKET_
TOKEN_ CONTEXT - Domain separator for the ticket-token MAC key.