Skip to main content

SecretString

Struct SecretString 

Source
pub struct SecretString { /* private fields */ }
Expand description

UTF-8 secret stored in guarded, zeroizing memory.

The value intentionally implements neither Display nor direct string access. Use SecureString::with_str or SecureString::with_bytes and do not retain copies beyond the callback.

Implementations§

Source§

impl SecureString

Source

pub fn new() -> SecureString

Creates an empty secure string without allocating secret pages.

Source

pub fn try_from_bytes(bytes: Vec<u8>) -> Result<SecureString, Error>

Moves bytes into secure memory and zeroizes the input vector.

UTF-8 is validated when text access is requested. Prefer SecureString::try_from_utf8 when invalid input should fail eagerly.

Source

pub fn try_from_slice(bytes: &[u8]) -> Result<SecureString, Error>

Copies bytes into a new secure string.

Source

pub fn from_secure_vec(bytes: SecureVec) -> SecureString

Wraps an existing secure byte vector without copying it.

Source

pub fn try_from_utf8(bytes: Vec<u8>) -> Result<SecureString, Error>

Validates UTF-8, moves the bytes into secure memory, and zeroizes input.

Source

pub fn try_from_env(name: &str) -> Result<Option<SecureString>, Error>

Reads an environment variable directly into a secure string when set.

Source

pub fn try_from_os_string(value: OsString) -> Result<SecureString, Error>

Converts an operating-system string into a secure UTF-8 representation.

Source

pub fn try_clone(&self) -> Result<SecureString, Error>

Creates an independent secure copy of this string.

Source

pub fn with_str<R>(&self, f: impl FnOnce(&str) -> R) -> Result<R, Error>

Exposes valid UTF-8 text only for the duration of f.

Source

pub fn with_str_in<R>( &self, access: &SecureReadAccess<'_>, f: impl FnOnce(&str) -> R, ) -> Result<R, Error>

Exposes valid UTF-8 text using an existing secure read scope.

Source

pub fn with_bytes<R>(&self, f: impl FnOnce(&[u8]) -> R) -> Result<R, Error>

Exposes the encoded bytes only for the duration of f.

Source

pub fn with_bytes_in<R>( &self, access: &SecureReadAccess<'_>, f: impl FnOnce(&[u8]) -> R, ) -> Result<R, Error>

Exposes encoded bytes using an existing secure read scope.

Source

pub fn append_to_secure_vec(&self, target: &mut SecureVec) -> Result<(), Error>

Appends this value to target without copying through normal heap memory.

Source

pub fn try_push_byte(&mut self, byte: u8) -> Result<(), Error>

Appends one byte to the secure string.

This low-level operation does not validate that the resulting value is UTF-8; subsequent text access will fail if the sequence is invalid.

Source

pub fn try_extend_from_slice(&mut self, bytes: &[u8]) -> Result<(), Error>

Appends bytes without intermediate normal-memory allocation.

Source

pub fn try_push_utf8_char(&mut self, ch: char) -> Result<(), Error>

Encodes and appends one Unicode scalar value.

Source

pub fn try_pop_byte(&mut self) -> Result<Option<u8>, Error>

Removes, zeroes, and returns the final encoded byte, if present.

Source

pub fn is_empty(&self) -> bool

Returns true when the string contains no bytes.

Source

pub fn zeroize(&mut self) -> Result<(), Error>

Overwrites the allocation and resets the string to empty.

Trait Implementations§

Source§

impl Debug for SecureString

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl Default for SecureString

Source§

fn default() -> SecureString

Returns the “default value” for a type. Read more
Source§

impl Eq for SecureString

Source§

impl PartialEq for SecureString

Source§

fn eq(&self, other: &SecureString) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> NoneValue for T
where T: Default,

Source§

type NoneType = T

Source§

fn null_value() -> T

The none-equivalent value.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more