Expand description
Signed URL tokens (SPEC-WRITE-GRANTS §9.4): the mkit-url-token:v1
statement, its <statement>.<signature> encoding, the deployment’s
Ed25519 key set and IssueObjectUrl’s mint.
The token key is dedicated: it MUST NOT equal the receipt key, the
hook key, the admin key, or any key that signs auth v2
(SPEC-WRITE-GRANTS §9.4). crate::pipeline::Pipeline::new refuses a
URL-token seed equal to an upload-ticket secret; the receipt-key check
lands with WP-5.8. The token string and the seeds never appear in
Debug output or tracing.
Structs§
- Binding
- What verification phase 2 binds a token to: the request’s audience, repository and target, each compared byte for byte.
- Bound
Token - A token bound to the request; the epoch comparison is all that is left (§9.4).
- Minted
Token - A freshly minted token and its expiry. The token string is a
credential:
MintedToken::exposereads it for the response;Debugnever shows it. - Prechecked
- A statement that passed
UrlTokenConfig::precheck: syntax, key id and signature verified, still unbound to the request.Debugshows neither the token nor its claims. - Retired
Key - A retired verification key: it verifies until
retired_at_ms + ttl. - Target
Error - An invalid
targetfield: bad ref, path or encoding. - Token
Rejected - The one rejection every URL-token verification failure maps to: the
reason never survives to the client, so a private repository’s
uniform
not_foundcannot identify which check failed (SPEC-HTTP-OBJECTS §3 step 5). - UrlToken
Config - The deployment’s URL-token configuration: keys and the longest
lifetime it issues (
url_token_ttl, §1.1). - UrlToken
Keys - The deployment’s URL-token signing key and its retired verification
keys (§9.4). Only key ids appear in
Debug; seeds never do. - UrlToken
Statement - A verified
mkit-url-token:v1statement (§9.4).
Enums§
- UrlTarget
- What
IssueObjectUrlbinds a token to (§9.4target). - UrlToken
Config Error - Invalid key-set or lifetime configuration. Never contains secret input.
- UrlToken
Error - Why a statement, token or key configuration is rejected. Every variant
maps to one stable
UrlTokenError::reasonfor the golden vectors.
Constants§
- DEFAULT_
TTL_ MS - The default token lifetime (§1.1
url_token_ttl). - DOMAIN
- The statement domain separator (SPEC-WRITE-GRANTS §9.4).
- MAX_
PATH_ BYTES - The longest target path, in bytes.
- MAX_
TTL_ MS - The longest lifetime a statement may encode and a configuration may
set (executor bound; §9.4 bounds by
url_token_ttlat issue).
Functions§
- verify
- §9.4 verification for a serving path:
UrlTokenConfig::precheck, thenPrechecked::check_binding, then exactly oneread_epochcall and the epoch comparison.read_epochnever runs when an earlier phase fails — the stored-epoch read is the last step (SPEC-HTTP-OBJECTS §6). A public repository ignores the result; that choice belongs to the serving caller (SPEC-HTTP-OBJECTS §3 step 5).