Skip to main content

Meta

Struct Meta 

Source
pub struct Meta {
    pub recipients: HashMap<String, String>,
    pub mac: String,
    pub signers: BTreeMap<String, String>,
    pub sig: Option<VaultSignature>,
    pub mac_key: Option<String>,
    pub github_pins: HashMap<String, Vec<String>>,
    pub groups: BTreeMap<String, Vec<String>>,
    pub grants: BTreeMap<String, GrantEntry>,
}

Fields§

§recipients: HashMap<String, String>

Maps pubkey → display name. The only place names are stored.

§mac: String

Integrity MAC over secrets + schema.

§signers: BTreeMap<String, String>

Registered Ed25519 verifying keys: recipient pubkey → base64 verifying key. A signer’s key must be listed here for its signature to verify. Populated when a signing-capable identity saves. Empty for vaults only ever written by SSH/hardware identities. Integrity of this map is anchored by the local TOFU pin and signed git history (see crate::signing).

§sig: Option<VaultSignature>

Ed25519 signature over the vault’s canonical content. Absent when the last writer had no signing-capable identity; a present signature must verify or load fails as tampering.

§mac_key: Option<String>

BLAKE3 keyed MAC key (hex-encoded, 32 bytes). Generated at init, stored encrypted.

§github_pins: HashMap<String, Vec<String>>

Pinned GitHub key fingerprints: username → [SHA256:…]. Used for TOFU (Trust On First Use) verification on authorize github:user.

§groups: BTreeMap<String, Vec<String>>

Named recipient groups: group name → member pubkeys. Stored here (not in the plaintext header) so org structure — who is in which group — does not leak. Members are a subset of Vault::recipients. Covered by the keyed MAC (blake3v4:) so membership cannot be tampered with undetected.

§grants: BTreeMap<String, GrantEntry>

Short-lived agent grants: grant name → metadata. Stored here (encrypted) so an agent’s existence and scope do not leak. Covered by the keyed MAC (blake3v5:) so TTL/scope/issuer are tamper-evident.

Trait Implementations§

Source§

impl Clone for Meta

Source§

fn clone(&self) -> Meta

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Meta

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for Meta

Source§

fn default() -> Meta

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for Meta

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for Meta

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

§

impl Freeze for Meta

§

impl RefUnwindSafe for Meta

§

impl Send for Meta

§

impl Sync for Meta

§

impl Unpin for Meta

§

impl UnsafeUnpin for Meta

§

impl UnwindSafe for Meta

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V