Expand description
Auth v2 glue (SPEC-TRANSPORT-CONNECT §7.1): read the ten headers, run
mkit_core::write_auth::verify_headers and decode its result into a
VerifiedAuth. Verification itself (canonical fields, validity window,
strict Ed25519) stays in mkit-core; nothing here reimplements it.
This is step 1, authenticate, of the signed-write order in §7.1. It writes no state; the replay lookup comes after it.
The canonical copy of apps/vcs-worker’s envelope.rs, hashing.rs, the
header reading in worker_impl/auth.rs and the pack commitment check in
worker_impl/service.rs. The old copies go when vcs-worker switches in
WP-M0-17. apps/repo-worker keeps its own copy (planner decision Q11).
Structs§
- Auth
V2Config - The trusted audience and Single deployment’s expected repository. In Multi mode the pipeline ignores this repository field and verifies against the resolved request identity instead.
- Pack
Commitment Mismatch - An
UploadPackheader that differs from the signed commitment. The caller picks the code:unauthenticatedfor the auth v2pack:commitment,permission_deniedfor a ticket (SPEC-TRANSPORT-CONNECT §5).
Constants§
- CORS_
ALLOW_ HEADERS Access-Control-Allow-Headersfor browser clients: the auth v2 headers plus the Connect request headers.- HEADER_
NAMES - The auth v2 request headers, lowercase, in
Headersfield order.
Functions§
- check_
pack_ commitment - Check an
UploadPackheader against the signedpack:commitment, before any quota is reserved or chunk read. - headers_
from - Read the auth v2 headers through
get, which looks a header up by its lowercase name. Values are passed through unnormalized. - verify_
stream - Authenticate a streaming upload: the signature must carry a
pack:commitment, whichcheck_pack_commitmentlater compares with the stream’s header. - verify_
unary - Authenticate a unary request: the signature must commit to
body:<BLAKE3 of body>forprocedure_pathatnow_ms.