Skip to main content

pigeon/commands/keyring/
encryption_key.rs

1use serde::{Deserialize, Serialize};
2
3/// A configured symmetric encryption key's non-secret metadata (ADR-0026).
4/// The secret key material itself lives in the OS keychain, keyed by
5/// `alias` -- see `crate::core::keyring::credentials` -- exactly like every
6/// other secret this codebase stores.
7#[derive(Debug, Clone, Serialize, Deserialize)]
8pub struct EncryptionKey {
9    pub alias: String,
10    /// RFC3339, set once at creation; never updated by `modify` -- rotating
11    /// the secret changes the key, not when the entry was made.
12    pub created_at: String,
13}
14
15impl crate::core::keyring::KeyringEntry for EncryptionKey {
16    fn alias(&self) -> &str {
17        &self.alias
18    }
19    fn kind(&self) -> &'static str {
20        "encryption-key"
21    }
22    fn detail(&self) -> String {
23        format!("created {}", self.created_at)
24    }
25}