pub struct Verified {
pub principal: Principal,
pub reusable_until: Option<Timestamp>,
}Expand description
A successful verification: who presented the credential, and how long that answer may be reused without asking again.
Fields§
§principal: PrincipalWho presented the credential: the identity it authenticates as, and nothing about what that identity may do.
reusable_until: Option<Timestamp>The instant from which this answer must be re-derived.
None means the credential does not expire of its own accord — a
digest of a server-issued key is valid until it is withdrawn, and
withdrawal travels by snapshot rather than by clock.
A scheme that carries an expiry must put it here. A PASETO or JWT
exp, a certificate’s notAfter: without it, a session that
authenticated once would keep spending an expired token for as long as
it stayed connected, and admission could not compensate because expiry
is a property of the credential and not of the account snapshot.
Implementations§
Source§impl Verified
impl Verified
Sourcepub const fn indefinite(principal: Principal) -> Self
pub const fn indefinite(principal: Principal) -> Self
A credential that does not expire on its own.
Sourcepub const fn until(principal: Principal, until: Timestamp) -> Self
pub const fn until(principal: Principal, until: Timestamp) -> Self
A credential whose verification stops being reusable at until.
Sourcepub fn is_reusable_at(&self, now: Timestamp) -> bool
pub fn is_reusable_at(&self, now: Timestamp) -> bool
Whether this answer may still be reused at now.