Skip to main content

BindingMode

Enum BindingMode 

Source
pub enum BindingMode {
    DirectWitness,
    DelegatedWitness,
    Unrecognized(String),
}
Expand description

The attestation-binding mode a receipt was produced under.

§Why this is in the payload

-02 required a Verifier to obtain this from a document the Issuer published separately, and simultaneously declined to specify that document. Two problems followed. The obligation could not be discharged, because there was nothing to fetch. And even had there been, a per-receipt fact would have been resolved from a document that describes an Issuer rather than a receipt, so the introduction’s non-extractability property stopped being checkable from the presented bytes.

The mode was fixed at the instant the receipt was signed and was known to the signer. Carrying it costs one string.

§Why an unrecognised value is rejected here and preserved in AckProvenance

The two members answer different questions and the difference is not stylistic. adapter.ackProvenance qualifies a record of something that already happened, so refusing to parse it destroys the reconstruction the receipt exists for, and the honest move is to surface the unknown.

attestation.bindingMode selects which security property a reader is entitled to rely on. There is no safe reading of an unrecognised value: it cannot be treated as direct-witness without asserting a property nobody claimed, and treating it as delegated-witness invents a delegation credential to go looking for. So the profile closes the set and this rejects.

Variants§

§

DirectWitness

The signing key is the TEE signing key. Wire value DIRECT_WITNESS.

§

DelegatedWitness

The signing key is the Issuer’s own, authorised by a TEE-issued delegation credential. Wire value DELEGATED_WITNESS.

A reader of such a receipt obtains a weaker property than the non-extractability one, and the delegation credential is resolved out of band. Nothing in this repository resolves it; see KNOWN-LIMITATIONS.md.

§

Unrecognized(String)

A value outside the closed set, preserved exactly as it appeared.

Retained rather than dropped so a reader can report what was actually present. A payload carrying this fails validation.

Implementations§

Source§

impl BindingMode

Source

pub fn as_wire_str(&self) -> &str

Returns the wire string for this value.

Source

pub const fn is_unrecognized(&self) -> bool

Returns true when the value is outside the closed set the profile names.

Trait Implementations§

Source§

impl Clone for BindingMode

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for BindingMode

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for BindingMode

Source§

fn deserialize<D: Deserializer<'de>>(deserializer: D) -> Result<Self, D::Error>

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for BindingMode

Source§

impl PartialEq for BindingMode

Source§

fn eq(&self, other: &Self) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for BindingMode

Source§

fn serialize<S: Serializer>(&self, serializer: S) -> Result<S::Ok, S::Error>

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for BindingMode

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.