Skip to main content

TicketKeys

Struct TicketKeys 

Source
pub struct TicketKeys { /* private fields */ }
Expand description

Signing and accepted keys. The first key signs and every listed key verifies. Secrets, including derived MAC keys, are zeroed when dropped.

Implementations§

Source§

impl TicketKeys

Source

pub fn new(keys: Vec<(String, Hash)>) -> Result<Self, TicketKeyError>

Validate an ordered key set. It must be nonempty; ids must be unique, 1–32 ASCII bytes from [A-Za-z0-9._-].

Source

pub fn parse(text: &str) -> Result<Self, TicketKeyError>

Parse <key-id> <64 hex> lines, ignoring blank lines and # comments. The first line signs; all lines verify. Errors never echo input.

Source

pub fn parse_secret(text: String) -> Result<Self, TicketKeyError>

Parse an owned deployment secret, wiping its source text when parsing completes, including on invalid configuration.

Source

pub fn contains_secret(&self, secret: &[u8; 32]) -> bool

Whether secret is any key’s source secret, in constant time. Pipeline::new refuses a URL-token key that repeats one (SPEC-WRITE-GRANTS §9.4’s dedicated-key rule), and the native adapter refuses a hook seed that does (SPEC-SERVER §7.1).

Source

pub fn contains_ed25519_public(&self, public: &[u8; 32]) -> bool

Whether a public role key equals a ticket secret or its derived public key. Publishing raw ticket MAC material would disclose it; deriving the same public key also identifies a shared signing seed. Both are forbidden.

Source

pub fn mint(&self, claims: &TicketClaims) -> Vec<u8> ⓘ

Mint a token from trusted claims.

§Panics

If audience, repository or session exceeds the encoding’s u16 length. RPC callers build claims from validated repository and ticket rows.

Source

pub fn verify( &self, token: &[u8], now_ms: u64, ) -> Result<TicketClaims, ServerError>

Authenticate first, decode next, then check expiry on the business clock. Malformed, unknown, invalid and expired tokens are failed preconditions.

Trait Implementations§

Source§

impl Clone for TicketKeys

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for TicketKeys

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for TicketKeys

Source§

impl FromStr for TicketKeys

Source§

type Err = TicketKeyError

The associated error which can be returned from parsing.
Source§

fn from_str(text: &str) -> Result<Self, Self::Err>

Parses a string s to return a value of this type. Read more
Source§

impl PartialEq for TicketKeys

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for TicketKeys

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> MaybeSend for T
where T: Send + ?Sized,

Source§

impl<T> MaybeSync for T
where T: Sync + ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more