pigeon/commands/keyring/encryption_key.rs
1use serde::{Deserialize, Serialize};
2
3/// A configured symmetric encryption key's non-secret metadata (ADR-0026).
4/// The secret key material itself lives in the OS keychain, keyed by
5/// `alias` -- see `crate::core::keyring::credentials` -- exactly like every
6/// other secret this codebase stores.
7#[derive(Debug, Clone, Serialize, Deserialize)]
8pub struct EncryptionKey {
9 pub alias: String,
10 /// RFC3339, set once at creation; never updated by `modify` -- rotating
11 /// the secret changes the key, not when the entry was made.
12 pub created_at: String,
13}
14
15impl crate::core::keyring::KeyringEntry for EncryptionKey {
16 fn alias(&self) -> &str {
17 &self.alias
18 }
19 fn kind(&self) -> &'static str {
20 "encryption-key"
21 }
22 fn detail(&self) -> String {
23 format!("created {}", self.created_at)
24 }
25}