pub struct SessionTokenAuthority { /* private fields */ }Expand description
Mints, rotates, and validates the composite broker_token ‖ daemon_token
pair described in the module docs.
Implementations§
Source§impl SessionTokenAuthority
impl SessionTokenAuthority
Sourcepub fn new() -> Result<Self, SessionTokenError>
pub fn new() -> Result<Self, SessionTokenError>
Mint a fresh broker token from OS randomness. Call once at broker startup.
Sourcepub fn with_broker_token(broker_token: TokenHalf) -> Self
pub fn with_broker_token(broker_token: TokenHalf) -> Self
Test/deterministic constructor — production code should use
Self::new so the broker half comes from real randomness.
Sourcepub fn broker_token(&self) -> &TokenHalf
pub fn broker_token(&self) -> &TokenHalf
The current broker-half bytes, for a caller (e.g. the front door spawning this broker) to hand to a newly-connecting client alongside the daemon half.
Sourcepub fn rotate_broker_token(&mut self) -> Result<TokenHalf, SessionTokenError>
pub fn rotate_broker_token(&mut self) -> Result<TokenHalf, SessionTokenError>
Rotate the broker token in place — the live-rotation path (e.g. the
spawn-storm guard tripping). Every previously-issued composite token
stops validating immediately: Self::validate compares against
the NEW value from the moment this returns.
Sourcepub fn register_daemon(
&mut self,
daemon_id: DaemonId,
) -> Result<TokenHalf, SessionTokenError>
pub fn register_daemon( &mut self, daemon_id: DaemonId, ) -> Result<TokenHalf, SessionTokenError>
Register (or re-register) a daemon’s token, minted fresh from OS randomness. Call once at that daemon’s startup.
Sourcepub fn invalidate_daemon(&mut self, daemon_id: &str) -> bool
pub fn invalidate_daemon(&mut self, daemon_id: &str) -> bool
Remove a daemon’s token entirely — every session naming this
daemon_id fails Self::validate with SessionTokenRejection::DaemonUnknown
from this call onward. Sessions naming any other daemon_id are
unaffected. Returns whether a token was actually present.
Sourcepub fn daemon_count(&self) -> usize
pub fn daemon_count(&self) -> usize
How many daemons currently hold a registered token.
Sourcepub fn composed_token_for(&self, daemon_id: &str) -> Option<Vec<u8>>
pub fn composed_token_for(&self, daemon_id: &str) -> Option<Vec<u8>>
The current composite broker_token ‖ daemon_token bytes for
daemon_id, or None if it has no registered token (never
registered, or already invalidated) – e.g. for a control-channel
RPC handing the client something to present in a later Hello.
Sourcepub fn validate(
&self,
presented: &[u8],
daemon_id: &str,
) -> Result<(), SessionTokenRejection>
pub fn validate( &self, presented: &[u8], daemon_id: &str, ) -> Result<(), SessionTokenRejection>
Validate a presented composite token against a claimed daemon_id
(which daemon the client’s Hello says it wants — see “Not done yet”
for how that claim reaches here from the wire).
presented is broker_half ‖ daemon_half, SESSION_TOKEN_TOTAL_BYTES
long. Checks the broker half FIRST and independently of daemon
lookup, so a broker cycle reports as
SessionTokenRejection::BrokerHalfMismatch even when the named
daemon_id is also gone — the broker-wide event is the more global
(and more actionable) verdict, and per-daemon state after a broker
cycle is stale by definition, so reporting it would mislead the
client about what happened.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for SessionTokenAuthority
impl RefUnwindSafe for SessionTokenAuthority
impl Send for SessionTokenAuthority
impl Sync for SessionTokenAuthority
impl Unpin for SessionTokenAuthority
impl UnsafeUnpin for SessionTokenAuthority
impl UnwindSafe for SessionTokenAuthority
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more