pub struct UrlTokenKeys { /* private fields */ }Expand description
The deployment’s URL-token signing key and its retired verification
keys (§9.4). Only key ids appear in Debug; seeds never do.
Implementations§
Source§impl UrlTokenKeys
impl UrlTokenKeys
Sourcepub fn contains_secret(&self, material: &[u8; 32]) -> bool
pub fn contains_secret(&self, material: &[u8; 32]) -> bool
Check candidate role material without exposing the active signing seed.
Sourcepub fn new(
active_seed: Zeroizing<[u8; 32]>,
retired: Vec<RetiredKey>,
) -> Result<Self, UrlTokenConfigError>
pub fn new( active_seed: Zeroizing<[u8; 32]>, retired: Vec<RetiredKey>, ) -> Result<Self, UrlTokenConfigError>
Signing active seed plus the retired verification set.
§Errors
UrlTokenConfigError::Keys for a malformed or weak retired public
key, a retired key equal to the active key, or a duplicate key id.
Sourcepub fn parse_key_file(text: &str) -> Result<Self, UrlTokenConfigError>
pub fn parse_key_file(text: &str) -> Result<Self, UrlTokenConfigError>
Parse a key file: blank lines and # comments are ignored; exactly
one active <64 hex seed> line and zero or more
retired <64 hex public key> <retired_at_ms> lines follow the §3.1
decimal and hex rules. Errors never echo input.
§Errors
As UrlTokenKeys::new, plus malformed lines.
Sourcepub fn parse_key_file_secret(text: String) -> Result<Self, UrlTokenConfigError>
pub fn parse_key_file_secret(text: String) -> Result<Self, UrlTokenConfigError>
Self::parse_key_file over an owned secret, wiping the source text.
§Errors
Sourcepub fn active_key_id(&self) -> String
pub fn active_key_id(&self) -> String
The active key’s id: hex(blake3(public)[..16]).
Sourcepub fn public_keys(&self) -> impl Iterator<Item = [u8; 32]> + '_
pub fn public_keys(&self) -> impl Iterator<Item = [u8; 32]> + '_
Active and retained public keys for deployment role-separation checks. This never exposes seeds; adapters compare hook/enc/receipt/admin keys.
Sourcepub fn key_set_json(&self, ttl_ms: u64) -> String
pub fn key_set_json(&self, ttl_ms: u64) -> String
The published key list (SPEC-SERVER §7.2): version 1, the active
key unbounded, each retired key bounded by notAfterMs
(retired_at_ms + ttl_ms). Mounting it at
/.well-known/mkit-url-token-keys.json is WP-4.16.