pub struct TicketKeys { /* private fields */ }Expand description
Signing and accepted keys. The first key signs and every listed key verifies. Secrets, including derived MAC keys, are zeroed when dropped.
Implementations§
Source§impl TicketKeys
impl TicketKeys
Sourcepub fn new(keys: Vec<(String, Hash)>) -> Result<Self, TicketKeyError>
pub fn new(keys: Vec<(String, Hash)>) -> Result<Self, TicketKeyError>
Validate an ordered key set. It must be nonempty; ids must be unique,
1–32 ASCII bytes from [A-Za-z0-9._-].
Sourcepub fn parse(text: &str) -> Result<Self, TicketKeyError>
pub fn parse(text: &str) -> Result<Self, TicketKeyError>
Parse <key-id> <64 hex> lines, ignoring blank lines and # comments.
The first line signs; all lines verify. Errors never echo input.
Sourcepub fn parse_secret(text: String) -> Result<Self, TicketKeyError>
pub fn parse_secret(text: String) -> Result<Self, TicketKeyError>
Parse an owned deployment secret, wiping its source text when parsing completes, including on invalid configuration.
Sourcepub fn contains_secret(&self, secret: &[u8; 32]) -> bool
pub fn contains_secret(&self, secret: &[u8; 32]) -> bool
Whether secret is any key’s source secret, in constant time.
Pipeline::new refuses a URL-token key that repeats one
(SPEC-WRITE-GRANTS §9.4’s dedicated-key rule), and the native adapter
refuses a hook seed that does (SPEC-SERVER §7.1).
Sourcepub fn contains_ed25519_public(&self, public: &[u8; 32]) -> bool
pub fn contains_ed25519_public(&self, public: &[u8; 32]) -> bool
Whether a public role key equals a ticket secret or its derived public key. Publishing raw ticket MAC material would disclose it; deriving the same public key also identifies a shared signing seed. Both are forbidden.
Sourcepub fn mint(&self, claims: &TicketClaims) -> Vec<u8> ⓘ
pub fn mint(&self, claims: &TicketClaims) -> Vec<u8> ⓘ
Mint a token from trusted claims.
§Panics
If audience, repository or session exceeds the encoding’s u16 length. RPC callers build claims from validated repository and ticket rows.
Sourcepub fn verify(
&self,
token: &[u8],
now_ms: u64,
) -> Result<TicketClaims, ServerError>
pub fn verify( &self, token: &[u8], now_ms: u64, ) -> Result<TicketClaims, ServerError>
Authenticate first, decode next, then check expiry on the business clock. Malformed, unknown, invalid and expired tokens are failed preconditions.