Skip to main content

KeyHasher

Struct KeyHasher 

Source
pub struct KeyHasher { /* private fields */ }
Expand description

Derives opaque subject keys using HMAC-SHA-256.

Each derivation is domain-separated by the exact policy and scope identifiers. The same normalized subject therefore yields unrelated keys in different policy scopes.

Applications should keep one stable secret per deployment. Rotating it deliberately starts new counters because all derived subject keys change.

Implementations§

Source§

impl KeyHasher

Source

pub const MINIMUM_SECRET_LENGTH: usize = 32

Minimum accepted secret length in bytes.

Source

pub fn new(secret: impl AsRef<[u8]>) -> Result<Self, KeyHasherError>

Constructs a hasher by copying a secret into zeroizing storage.

§Errors

Returns KeyHasherError::SecretTooShort unless the secret contains at least 32 bytes.

Source

pub fn hash( &self, policy_id: &PolicyId, scope_id: &ScopeId, subject: impl AsRef<[u8]>, ) -> SubjectKey

Hashes a normalized subject within an explicit policy and scope.

Normalization is application-owned: two byte strings are treated as distinct subjects even if an application considers them equivalent.

Source

pub fn hash_for( &self, policy: &FixedWindowPolicy, subject: impl AsRef<[u8]>, ) -> SubjectKey

Hashes a normalized subject in a fixed-window policy’s namespace.

Trait Implementations§

Source§

impl Debug for KeyHasher

Source§

fn fmt(&self, formatter: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.