pub struct ServerState<S> {
pub store: Arc<S>,
pub clock: Arc<dyn Clock>,
pub security: Arc<ServerSecurity>,
pub issuer: Option<Arc<dyn CredentialIssuer + Send + Sync>>,
}Expand description
Everything the handlers need. S is the storage backend; the clock is the
single place wall time enters the server.
Fields§
§store: Arc<S>The backend every handler and the serve maintenance sweep act on.
clock: Arc<dyn Clock>The time source for lease and ingest calls, credential page reads, credential and client-certificate validity checks, audit event times, and the maintenance sweep.
security: Arc<ServerSecurity>The live verifier, role map and TLS generation, shared by the
authorization middleware and the listener serve builds. Its
transport mode decides whether serve accepts a non-loopback
listener.
issuer: Option<Arc<dyn CredentialIssuer + Send + Sync>>Who may mint credentials, if this deployment issues them at all (GL-121).
None is a deliberate answer, not an omission: an instance that only
verifies has no business holding the capability to create credentials,
and the issuance routes answer 501 rather than pretending. That is the
shape list_principals already uses for a backend that cannot
enumerate — an unsupported capability is reported, never faked.