Skip to main content

Module auth_v2

Module auth_v2 

Source
Expand description

Auth v2 glue (SPEC-TRANSPORT-CONNECT §7.1): read the ten headers, run mkit_core::write_auth::verify_headers and decode its result into a VerifiedAuth. Verification itself (canonical fields, validity window, strict Ed25519) stays in mkit-core; nothing here reimplements it.

This is step 1, authenticate, of the signed-write order in §7.1. It writes no state; the replay lookup comes after it.

The canonical copy of apps/vcs-worker’s envelope.rs, hashing.rs, the header reading in worker_impl/auth.rs and the pack commitment check in worker_impl/service.rs. The old copies go when vcs-worker switches in WP-M0-17. apps/repo-worker keeps its own copy (planner decision Q11).

Structs§

AuthV2Config
The trusted audience and Single deployment’s expected repository. In Multi mode the pipeline ignores this repository field and verifies against the resolved request identity instead.
PackCommitmentMismatch
An UploadPack header that differs from the signed commitment. The caller picks the code: unauthenticated for the auth v2 pack: commitment, permission_denied for a ticket (SPEC-TRANSPORT-CONNECT §5).

Constants§

CORS_ALLOW_HEADERS
Access-Control-Allow-Headers for browser clients: the auth v2 headers plus the Connect request headers.
HEADER_NAMES
The auth v2 request headers, lowercase, in Headers field order.

Functions§

check_pack_commitment
Check an UploadPack header against the signed pack: commitment, before any quota is reserved or chunk read.
headers_from
Read the auth v2 headers through get, which looks a header up by its lowercase name. Values are passed through unnormalized.
verify_stream
Authenticate a streaming upload: the signature must carry a pack: commitment, which check_pack_commitment later compares with the stream’s header.
verify_unary
Authenticate a unary request: the signature must commit to body:<BLAKE3 of body> for procedure_path at now_ms.