Skip to main content

Custody

Struct Custody 

Source
pub struct Custody {
    pub mode: CustodyMode,
    pub signer: String,
    pub on_behalf_of: String,
    pub reason: Option<String>,
}
Expand description

Who signed, when that is not the actor itself.

This is a separate axis from attestation_class, and keeping them separate is the point. attestation_class grades how evidence was captured (self / runtime / countersigned). Custody grades who held the key. They vary independently: a service-mediated room can have excellent runtime-captured evidence and still be custodially signed, and an agent signing for itself can have nothing but its own word.

Collapsing them is the same error EffectConfidence and EffectFinality exist to avoid – one label carrying two unrelated questions, where a reader cannot tell which one a value is answering.

The distinction is not cosmetic. Under self-custody, forging a participant’s action requires that participant’s key. Under delegated custody, a compromised service can mint any history it likes for every actor it signs for. Same receipt shape, different threat model, so the receipt says which.

Fields§

§mode: CustodyMode

Custody mode. Only delegated is ever serialized – self-custody is represented by the whole section being absent, so existing receipts stay byte-identical and “no custody block” cannot be misread as “custody unknown”.

§signer: String

The identity whose key actually produced the signature, e.g. svc://gateway-rooms. This is who a verifier is really trusting.

§on_behalf_of: String

The actor the signature is claimed to be for, e.g. agent://fizz. A verifier can confirm signer signed; it cannot confirm this actor agreed, and must not present it as though it could.

§reason: Option<String>

Optional human-readable reason the actor did not sign for itself (e.g. “browser-mediated room; participants hold no local key”).

Implementations§

Source§

impl Custody

Source

pub fn delegated( signer: impl Into<String>, on_behalf_of: impl Into<String>, ) -> Self

A service signing for an actor that holds no key of its own.

Source

pub fn with_reason(self, reason: impl Into<String>) -> Self

Attach the reason the actor did not sign for itself.

Trait Implementations§

Source§

impl Clone for Custody

Source§

fn clone(&self) -> Custody

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Custody

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for Custody

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for Custody

Source§

impl PartialEq for Custody

Source§

fn eq(&self, other: &Custody) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for Custody

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for Custody

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V