pub struct AuthorityFence { /* private fields */ }Expand description
Optional deployment fencing configuration. Construction validates all keys.
Implementations§
Source§impl AuthorityFence
impl AuthorityFence
Sourcepub fn new(keys: Vec<AuthorityKey>) -> Result<Self, ServerError>
pub fn new(keys: Vec<AuthorityKey>) -> Result<Self, ServerError>
Validate a bounded set of dedicated keys, each with namespace permissions.
§Errors
Empty/oversized lists, malformed, weak or duplicate keys, and owner keys.
Sourcepub fn parse(text: &str) -> Result<Self, ServerError>
pub fn parse(text: &str) -> Result<Self, ServerError>
Parse one <key-id> <64 lowercase hex public key> <namespace[,namespace...]>
per line. Keys authorize exact namespaces; the list is bounded before decoding.
§Errors
Any malformed or unauthorized key configuration.
Sourcepub fn public_keys(&self) -> impl Iterator<Item = [u8; 32]> + '_
pub fn public_keys(&self) -> impl Iterator<Item = [u8; 32]> + '_
All configured role keys, for adapter key separation.
Sourcepub fn verify(
&self,
wire: &str,
audience: &str,
now_ms: i64,
) -> Result<AuthorityStatement, ServerError>
pub fn verify( &self, wire: &str, audience: &str, now_ms: i64, ) -> Result<AuthorityStatement, ServerError>
Verify <unpadded-base64url statement>.<unpadded-base64url signature>.
Fields: domain, key id, namespace, generation, audience, created, expiry,
nonce; UTF-8, LF separated, no final LF. Signature covers BLAKE3(bytes).
§Errors
Every malformed, wrongly bound, expired or unauthorized statement.