pub struct UrlTokenConfig { /* private fields */ }Expand description
The deployment’s URL-token configuration: keys and the longest
lifetime it issues (url_token_ttl, §1.1).
Implementations§
Source§impl UrlTokenConfig
impl UrlTokenConfig
Sourcepub fn new(keys: UrlTokenKeys) -> Self
pub fn new(keys: UrlTokenKeys) -> Self
keys with the default lifetime cap, DEFAULT_TTL_MS (15
minutes).
Sourcepub fn with_ttl_ms(
keys: UrlTokenKeys,
ttl_ms: u64,
) -> Result<Self, UrlTokenConfigError>
pub fn with_ttl_ms( keys: UrlTokenKeys, ttl_ms: u64, ) -> Result<Self, UrlTokenConfigError>
keys with an explicit issued-token lifetime cap.
§Errors
UrlTokenConfigError::Ttl for ttl_ms outside 1..=MAX_TTL_MS.
Sourcepub fn keys(&self) -> &UrlTokenKeys
pub fn keys(&self) -> &UrlTokenKeys
The signing and verification key set.
Sourcepub fn mint(
&self,
audience: &str,
repository: &str,
target: &UrlTarget,
epoch: u64,
now_ms: i64,
requested_ttl_s: u32,
) -> Result<MintedToken, ServerError>
pub fn mint( &self, audience: &str, repository: &str, target: &UrlTarget, epoch: u64, now_ms: i64, requested_ttl_s: u32, ) -> Result<MintedToken, ServerError>
Mint a token binding audience, repository and target at
epoch, issued at now_ms. A requested_ttl_s of 0 asks for the
configured lifetime; any request is clamped to it, never refused.
§Errors
internal when the statement cannot encode (a caller’s clock far
outside its range).
Sourcepub fn precheck(
&self,
token: &str,
now_ms: i64,
) -> Result<Prechecked, TokenRejected>
pub fn precheck( &self, token: &str, now_ms: i64, ) -> Result<Prechecked, TokenRejected>
Verification phase 1, before any repository lookup
(SPEC-HTTP-OBJECTS §6): strict token decode, the statement rules, a
key id in the verification set (the active key, or a retired key
before retired_at_ms + ttl_ms) and the strict Ed25519 signature
over blake3(statement).
§Errors
TokenRejected for any failure; the reason never escapes.