mkit_server/hooks/sign.rs
1//! Runtime-specific nonce source for remote hooks.
2
3use crate::rt::{MaybeSend, MaybeSync};
4
5/// The source of the fresh 32-byte nonce every attempt carries.
6pub trait NonceSource: MaybeSend + MaybeSync {
7 /// Fill `nonce` with 32 fresh random bytes; `false` on failure.
8 fn fill(&self, nonce: &mut [u8; 32]) -> bool;
9}
10
11/// The operating system's CSPRNG.
12#[derive(Debug, Clone, Copy, Default)]
13pub struct OsNonces;
14
15impl NonceSource for OsNonces {
16 fn fill(&self, nonce: &mut [u8; 32]) -> bool {
17 getrandom::fill(nonce).is_ok()
18 }
19}