pub enum KeyError {
UnknownKey,
UnknownAccount,
AlreadyExists,
ActiveKeyLimit {
limit: NonZeroUsize,
},
Storage(StoreError),
}Expand description
Refusals from credential lifecycle operations.
Variants§
UnknownKey
No such credential. Never a silent no-op — an operator revoking a key that does not exist has either the wrong id or a false belief about what is live, and both are worth surfacing.
UnknownAccount
The credential’s account does not exist, so nothing could authenticate as it. Refused at issuance rather than producing a key that verifies and is then denied by every admission.
AlreadyExists
This key_id is already recorded. Issuance is never destructive, for
the reason account creation is not (CreateAccountError): an
overwrite would silently retire a live credential.
This is also the retry answer. A caller that supplies the key_id and
loses the response resends the same one and is told the credential
exists — which is the truth, and which discloses no secret. That is why
issuance must never become an upsert (GL-121).
ActiveKeyLimit
The account already holds limit live credentials, so issuing another
would exceed the bound the caller supplied.
“Live” excludes revoked keys and keys whose not_after has passed: a
bound that counted expired credentials would strand an account behind
keys nobody can authenticate with.
Fields
limit: NonZeroUsizeThe bound the caller supplied.
Storage(StoreError)
A backend failure unrelated to domain rules; see StoreError.
Trait Implementations§
impl Eq for KeyError
Source§impl Error for KeyError
impl Error for KeyError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()