Skip to main content

AuditEnvelope

Struct AuditEnvelope 

Source
pub struct AuditEnvelope<T: Serialize> { /* private fields */ }
Expand description

A signed wrapper around any serializable payload.

The envelope carries the payload plus a chain of signatures. Each signature in the chain signs the canonical bytes of the payload AND all previous signatures, creating a tamper-evident chain:

sig[0] = sign(canonical(payload))
sig[1] = sign(canonical(payload) + sig[0].signature_bytes)
sig[2] = sign(canonical(payload) + sig[0].signature_bytes + sig[1].signature_bytes)

Removing or reordering any signature invalidates all subsequent signatures.

§Security note

Fields are pub for serialization compatibility. Mutating any signed field (payload, subject, timestamp, agent_id, signatures) invalidates status without detection. Always call verify_chain() after deserialization or if the envelope may have been modified. For defense in depth, prefer reading via accessor methods and treat status as advisory until re-verified.

Implementations§

Source§

impl<T: Serialize> AuditEnvelope<T>

Source

pub fn unsigned(payload: T, subject: &str, agent_id: &str) -> Self

Create an unsigned envelope (dev mode / legacy).

Source

pub async fn signed( payload: T, subject: &str, agent_id: &str, signer: &dyn AuditSigner, ) -> Result<Self, CryptoError>

Create a signed envelope with a single author signature.

Source

pub async fn co_sign( &mut self, signer: &dyn AuditSigner, role: SignerRole, signer_id: &str, ) -> Result<(), CryptoError>

Add a co-signature to the chain. The new signer signs the payload canonical bytes + all existing signatures, creating an ordered chain.

Source

pub fn verify_chain( &mut self, registry: &VerifierRegistry, ) -> Result<bool, CryptoError>

Verify the entire signature chain using a verifier registry.

Each signature is verified against the payload canonical bytes + all prior signatures. If any signature fails, the chain is invalid.

Source

pub fn verify( &mut self, registry: &VerifierRegistry, ) -> Result<bool, CryptoError>

Backward-compatible verify (legacy single-signature envelopes). Delegates to verify_chain.

Source

pub fn signature_count(&self) -> usize

Number of signatures in the chain.

Source

pub fn has_role(&self, role: &SignerRole) -> bool

Check if the chain contains a signature with the given role.

Source

pub fn payload(&self) -> &T

Read-only access to the payload.

Source

pub fn subject(&self) -> &str

Read-only access to the subject.

Source

pub fn agent_id(&self) -> &str

Read-only access to the agent_id.

Source

pub fn timestamp(&self) -> u64

Read-only access to the timestamp.

Source

pub fn status(&self) -> &SignatureStatus

Current verification status. Advisory only — always call verify_chain() after deserialization or if the envelope may have been modified externally.

Source

pub fn signatures(&self) -> &[EnvelopeSignature]

Read-only access to the signature chain.

Source

pub fn invalidate(&mut self)

Explicitly invalidate the cached verification status. Call this after any mutation to signed fields.

Trait Implementations§

Source§

impl<T: Clone + Serialize> Clone for AuditEnvelope<T>

Source§

fn clone(&self) -> AuditEnvelope<T>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl<T: Debug + Serialize> Debug for AuditEnvelope<T>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de, T> Deserialize<'de> for AuditEnvelope<T>
where T: Deserialize<'de> + Serialize,

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl<T> Serialize for AuditEnvelope<T>
where T: Serialize + Serialize,

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

§

impl<T> Freeze for AuditEnvelope<T>
where T: Freeze,

§

impl<T> RefUnwindSafe for AuditEnvelope<T>
where T: RefUnwindSafe,

§

impl<T> Send for AuditEnvelope<T>
where T: Send,

§

impl<T> Sync for AuditEnvelope<T>
where T: Sync,

§

impl<T> Unpin for AuditEnvelope<T>
where T: Unpin,

§

impl<T> UnsafeUnpin for AuditEnvelope<T>
where T: UnsafeUnpin,

§

impl<T> UnwindSafe for AuditEnvelope<T>
where T: UnwindSafe,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V