pub struct MintedKey {
pub key_id: KeyId,
pub principal: Principal,
pub digest: [u8; 32],
pub secret: Zeroizing<Vec<u8>>,
}Expand description
A freshly minted credential, returned exactly once.
The secret is Zeroizing, so the only copy the process holds is wiped
when this value drops. The digest is suitable for durable storage; debug
output exposes only the non-secret identifiers.
Nothing can recover the secret from the record. That is the point of storing digests, and it is also the constraint on issuance ordering: the record must be durable before the secret is disclosed, because a crash between the two leaves a credential the server has never heard of and no reconciliation can repair it.
Fields§
§key_id: KeyIdThe non-secret identifier for this credential, used to revoke it.
principal: PrincipalThe principal it authenticates as: the digest’s leading 128 bits.
digest: [u8; 32]HMAC-SHA256 of the secret under the server secret. This is what a
tollgate_store::KeyDirectory stores.
secret: Zeroizing<Vec<u8>>The credential: 64 lowercase hexadecimal characters, exactly the bytes
the digest covers. It is what is disclosed, what a customer presents
(for example after Bearer ), and what a verifier is handed, with no
encoding step anywhere between them. Hand it to its owner and drop it;
it cannot be derived again from anything retained.