Skip to main content

Module url_token

Module url_token 

Source
Expand description

Signed URL tokens (SPEC-WRITE-GRANTS §9.4): the mkit-url-token:v1 statement, its <statement>.<signature> encoding, the deployment’s Ed25519 key set and IssueObjectUrl’s mint.

The token key is dedicated: it MUST NOT equal the receipt key, the hook key, the admin key, or any key that signs auth v2 (SPEC-WRITE-GRANTS §9.4). crate::pipeline::Pipeline::new refuses a URL-token seed equal to an upload-ticket secret; the receipt-key check lands with WP-5.8. The token string and the seeds never appear in Debug output or tracing.

Structs§

Binding
What verification phase 2 binds a token to: the request’s audience, repository and target, each compared byte for byte.
BoundToken
A token bound to the request; the epoch comparison is all that is left (§9.4).
MintedToken
A freshly minted token and its expiry. The token string is a credential: MintedToken::expose reads it for the response; Debug never shows it.
Prechecked
A statement that passed UrlTokenConfig::precheck: syntax, key id and signature verified, still unbound to the request. Debug shows neither the token nor its claims.
RetiredKey
A retired verification key: it verifies until retired_at_ms + ttl.
TargetError
An invalid target field: bad ref, path or encoding.
TokenRejected
The one rejection every URL-token verification failure maps to: the reason never survives to the client, so a private repository’s uniform not_found cannot identify which check failed (SPEC-HTTP-OBJECTS §3 step 5).
UrlTokenConfig
The deployment’s URL-token configuration: keys and the longest lifetime it issues (url_token_ttl, §1.1).
UrlTokenKeys
The deployment’s URL-token signing key and its retired verification keys (§9.4). Only key ids appear in Debug; seeds never do.
UrlTokenStatement
A verified mkit-url-token:v1 statement (§9.4).

Enums§

UrlTarget
What IssueObjectUrl binds a token to (§9.4 target).
UrlTokenConfigError
Invalid key-set or lifetime configuration. Never contains secret input.
UrlTokenError
Why a statement, token or key configuration is rejected. Every variant maps to one stable UrlTokenError::reason for the golden vectors.

Constants§

DEFAULT_TTL_MS
The default token lifetime (§1.1 url_token_ttl).
DOMAIN
The statement domain separator (SPEC-WRITE-GRANTS §9.4).
MAX_PATH_BYTES
The longest target path, in bytes.
MAX_TTL_MS
The longest lifetime a statement may encode and a configuration may set (executor bound; §9.4 bounds by url_token_ttl at issue).

Functions§

verify
§9.4 verification for a serving path: UrlTokenConfig::precheck, then Prechecked::check_binding, then exactly one read_epoch call and the epoch comparison. read_epoch never runs when an earlier phase fails — the stored-epoch read is the last step (SPEC-HTTP-OBJECTS §6). A public repository ignores the result; that choice belongs to the serving caller (SPEC-HTTP-OBJECTS §3 step 5).