pub struct SignedRequest<'a> {
pub body_sha256: &'a str,
pub signature_base: &'a str,
pub signature: &'a str,
pub body: Option<&'a str>,
}Expand description
The signed-request material a device-authenticated leaf carries in its
request field: enough for an offline verifier to check the signature
against nothing but the device’s key, itself carried by an earlier
approve or enroll leaf (see docs/design/part5-plan.md’s
“Verifying offline”).
What a signature proves is that the device sent a request with this
method, path, query and body digest — not what the server made of it.
The path and query bind a pull’s project and a revoke’s id; body
binds the rest of a device-management action, whose small body is kept
whole. A push’s or a delete’s body is the file, or names it, and is not
kept, so for those the signature vouches for the request and its
digest, and subject is the server’s word.
Fields§
§body_sha256: &'a strContent-Digest’s sha-256 value, base64 standard: the hash of the
request body — for a push, the JSON that carried the file, not the
file.
signature_base: &'a strThe exact bytes RFC 9421 §2.5 built and the device signed.
signature: &'a strThe signature itself, base64 standard.
body: Option<&'a str>The request body itself, for the actions whose body is a few bytes
of JSON with no secret in it: approve, deny, revoke,
authkey_create and authkey_revoke. None, written null, for
a push, a delete, a pull and the job actions.
Auto Trait Implementations§
impl<'a> Freeze for SignedRequest<'a>
impl<'a> RefUnwindSafe for SignedRequest<'a>
impl<'a> Send for SignedRequest<'a>
impl<'a> Sync for SignedRequest<'a>
impl<'a> Unpin for SignedRequest<'a>
impl<'a> UnsafeUnpin for SignedRequest<'a>
impl<'a> UnwindSafe for SignedRequest<'a>
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more