codec_pem/types.rs
1// SPDX-FileCopyrightText: 2026 ReallyMe LLC
2//
3// SPDX-License-Identifier: MIT OR Apache-2.0
4
5use zeroize::{ZeroizeOnDrop, Zeroizing};
6
7use crate::PemLabel;
8
9/// A decoded PEM document.
10pub struct PemDocument {
11 /// The exact label from the BEGIN/END boundaries.
12 pub label: PemLabel,
13 /// The decoded DER payload.
14 pub der: Zeroizing<Vec<u8>>,
15}
16
17// The DER owner already wipes its full capacity on drop. Exposing the marker
18// lets generic secret-owner code enforce that lifetime guarantee at compile
19// time without making the document Clone or Debug.
20impl ZeroizeOnDrop for PemDocument {}