tollgate_store/lib.rs
1//! Storage abstraction for tollgate.
2//!
3//! Narrow traits separate the data plane from lifecycle authority:
4//!
5//! - [`LeaseAllocator`] — atomically debit an account's balance into fenced,
6//! TTL-bounded leases; settle them by release or expiry reclaim.
7//! - [`SnapshotSource`] — fetch compiled account snapshots and subscribe to
8//! pushes.
9//! - [`UsageSink`] — idempotent, fencing-checked batch ingest of usage
10//! events.
11//! - [`KeySource`] — validated, revisioned pages of active credential digests.
12//! - [`KeyDirectory`] — durable credential lifecycle; instances do not need
13//! this mutation authority.
14//!
15//! Every method takes `now` as an argument: the store, like the core, never
16//! reads a clock. That keeps backends deterministic under test and puts the
17//! clock decision in exactly one place (the client runtime / server).
18//!
19//! [`MemoryStore`] is the reference implementation: it exists to prove the
20//! traits aren't secretly shaped like any particular database, to make the
21//! correctness suite run without infrastructure, and to serve as executable
22//! documentation of the settlement rules a real backend must reproduce.
23
24#![deny(missing_docs)]
25
26pub mod audit;
27pub mod clock;
28pub mod credentials;
29mod leases;
30pub mod memory;
31pub mod traits;
32#[cfg(feature = "wire")]
33pub mod wire;
34
35pub use audit::{AdminAuthority, AdminReceipt, AdminState};
36pub use clock::{Clock, ManualClock, SystemClock};
37pub use credentials::{
38 CredentialRecord, CredentialSet, DEFAULT_KEY_PAGE_LIMIT, KeyPage, KeySource,
39 MAX_KEY_PAGE_LIMIT, MAX_KEY_REVISION, validate_key_page_limit,
40};
41pub use memory::{MemoryStore, StoredRecords};
42pub use traits::{
43 AccountConfig, AccountView, AdminStore, AllocateError, Allocation, BudgetError, Conservation,
44 CreateAccountError, CredentialActivity, CredentialActivityState, DEFAULT_RECLAIM_BATCH_LIMIT,
45 DEFAULT_ROLLOVER_BATCH_LIMIT, GrantPolicy, GrantPolicyError, IngestError, IngestReport,
46 KeyDirectory, KeyError, KeyRecord, KeySnapshotError, KeySummary, LeaseAllocator,
47 MAX_INGEST_BATCH, PUSH_CHANNEL_CAPACITY, PublishSnapshotError, ReclaimBatch, ReclaimedLease,
48 Revocation, RolledAccount, RolloverBatch, SetStatusError, SnapshotPush, SnapshotResolution,
49 SnapshotSource, StatusChange, StoreError, StoreHealth, UsageSink, drain_reclaim_expired,
50 pushes_exceed_capacity,
51};
52
53// Compiles and runs the README's examples as doctests without adding them to
54// the rendered documentation, so the README cannot drift from the API.
55#[doc = include_str!("../README.md")]
56#[cfg(doctest)]
57pub struct ReadmeDoctests;