pub struct State {
pub schema: u32,
pub machine: String,
pub accounts: Vec<Account>,
pub active: BTreeMap<String, String>,
pub slot: BTreeMap<String, String>,
pub discarded: Vec<String>,
pub foreign: Vec<String>,
}Fields§
§schema: u32§machine: String§accounts: Vec<Account>§active: BTreeMap<String, String>Which account is signed in, per provider.
One string until schema 4, which stopped being true the moment a machine could have a Claude Code login and a Codex login at the same time. They are different programs reading different stores; neither signs the other out.
slot: BTreeMap<String, String>The credential slot each provider’s active was recorded for. One state file serves
every slot a machine uses, and a tool’s own home variable changes which store is the
live one, so a record made in one slot says nothing about another.
discarded: Vec<String>Parked items no account refers to any more. Listed in the same save that drops them and removed once deleted, so a delete that fails or is interrupted is retried.
foreign: Vec<String>Parked items an account here holds that this home never wrote down: logins
pitboard repair found in the store and gave back. On macOS every PITBOARD_HOME
shares the login keychain, so each may be another pitboard’s parked login, and
letting one go unused must leave it where it is. Removed once nothing here holds it.
Always empty where the vault is a directory inside this home, which nobody else
parks in.
Implementations§
Source§impl State
impl State
Sourcepub fn active_for(&self, provider: ProviderId) -> Option<&str>
pub fn active_for(&self, provider: ProviderId) -> Option<&str>
Which account is signed in for this provider, as pitboard last recorded it.
pub fn set_active(&mut self, provider: ProviderId, label: Option<String>)
Sourcepub fn slot_for(&self, provider: ProviderId) -> Option<&str>
pub fn slot_for(&self, provider: ProviderId) -> Option<&str>
The credential slot this provider’s active was recorded for.
pub fn set_slot(&mut self, provider: ProviderId, slot: String)
Sourcepub fn typed(&self, key: &Key) -> String
pub fn typed(&self, key: &Key) -> String
The account’s name as a command would take it here: bare for the tool a bare name means, unless another tool has an account of the same name, in which case a bare name would be refused as ambiguous and the tool is said.
What every message that tells somebody what to type uses, so the command it names is one that works on this machine.
Sourcepub fn labels(&self, provider: ProviderId) -> Enrolled
pub fn labels(&self, provider: ProviderId) -> Enrolled
Every label this tool has enrolled, for a message that would otherwise send someone to another command to find out.
Sourcepub fn names(&self, service: &str) -> bool
pub fn names(&self, service: &str) -> bool
Whether anything in the state refers to this vault item: an account holding it, or the list of ones waiting to be deleted.
Sourcepub fn get(&self, key: &Key) -> Option<&Account>
pub fn get(&self, key: &Key) -> Option<&Account>
The account under this key.
Callers that took a name from a person should go through crate::label::resolve
first, which knows what to do when two tools share a label.
Sourcepub fn by_uuid(&self, provider: ProviderId, uuid: &str) -> Option<&Account>
pub fn by_uuid(&self, provider: ProviderId, uuid: &str) -> Option<&Account>
This tool’s account with this identity.
Sourcepub fn owner_of_park(&self, uuid: &str) -> Option<&Account>
pub fn owner_of_park(&self, uuid: &str) -> Option<&Account>
The account a parked item was written for.
A park’s name carries the account’s identity and not its tool, because names were fixed before there was a second tool and every item already on a machine is filed under one. The identities cannot collide in practice: Claude Code’s and Codex’s are UUIDs, and Gemini’s is Google’s numeric subject.
Sourcepub fn park(&mut self, key: &Key, park: Park)
pub fn park(&mut self, key: &Key, park: Park)
Hold park for the account, releasing whatever it replaces. A newer park does not
use the one before it, so that one is let go rather than consumed.
Sourcepub fn park_foreign(&mut self, key: &Key, park: Park)
pub fn park_foreign(&mut self, key: &Key, park: Park)
Hold a park this home did not write, found in the store and given back. It is used like any other, and deleted only once it has been.
Sourcepub fn is_foreign(&self, service: &str) -> bool
pub fn is_foreign(&self, service: &str) -> bool
Whether an account here holds service without this home having written it.
Sourcepub fn used_here(&mut self, service: &str)
pub fn used_here(&mut self, service: &str)
Take service as this home’s own from now on, because this home has used it: a
renewal presented its refresh token. Letting it go afterwards deletes it.
Sourcepub fn discard(&mut self, service: &str)
pub fn discard(&mut self, service: &str)
Stop holding service because it has been used up, and list it for deletion
whoever wrote it: it has been installed, a renewal has spent it, or it copies a login
that is still signed in. Nothing can use it again, and for a tool whose park may
never be a copy it must not stay beside the login it copies.
Sourcepub fn release(&mut self, service: &str)
pub fn release(&mut self, service: &str)
Stop holding service because nothing here wants it any more: a newer park replaced
it, or its account was dropped. Listed for deletion only when this home wrote it. One
repair gave back may be another pitboard’s parked login, which this one never
used, and deleting it would end that account’s session for somebody who never ran
the command that did it.
pub fn references(&self, service: &str) -> bool
Sourcepub fn used(&mut self, key: &Key, at: i64)
pub fn used(&mut self, key: &Key, at: i64)
Record that the account under key was just put to use.
Sourcepub fn upsert(&mut self, account: Account)
pub fn upsert(&mut self, account: Account)
Add the account, or replace the one this tool already has under its label.