pub struct A2aClientConfig {
pub require_tls: bool,
pub ssrf_protection: bool,
pub card_trust_policy: CardTrustPolicy,
pub trusted_agent_keys: Vec<TrustedAgentKey>,
}Expand description
Client-side security policy for outbound A2A connections made by zeph --connect <URL>
(the remote-TUI-over-A2A-SSE attach feature), nested under [a2a_client] in TOML.
Deliberately separate from A2aServerConfig’s [a2a] section: the two configure
different roles (this process attaching to a remote daemon vs. this process’s own
A2A server accepting inbound connections) and must not share one config subtree — a
default/fresh config previously made every --connect http://... attempt fail with
“TLS required”, even against 127.0.0.1 loopback, because [a2a]’s server-oriented
require_tls = true default was being reused for the client path (#5878).
Loopback targets (127.0.0.1, ::1, localhost — see
is_loopback_host) are always permitted over
plain HTTP with SSRF protection skipped, regardless of these settings: connecting to
your own local daemon is definitionally not an SSRF risk, and the CLI’s documented
--connect http://127.0.0.1:8080/a2a/stream usage example must work out of the box.
Non-loopback targets are governed by require_tls/ssrf_protection below, which
default to the same hardened posture as the server config.
Fields§
§require_tls: boolReject non-loopback endpoints that do not start with https://. Default: true.
ssrf_protection: boolResolve non-loopback endpoint hostnames via DNS and reject private/link-local
ranges. Default: true.
card_trust_policy: CardTrustPolicyTrust policy applied to peer AgentCard signatures and
URL-origin consistency during discovery (A2A 1.0.0 §8.4, #5928). Default: ignore
— byte-identical to pre-#5928 discovery behavior. See
CardTrustPolicy doc comments for the prefer/require semantics, and
Config::validate for the require-without-the-
card-signing-feature fail-fast check.
trusted_agent_keys: Vec<TrustedAgentKey>Public keys trusted to sign peer AgentCards, keyed by kid. Empty by default —
prefer/require with no entries treats every peer as unverifiable (see
SignatureVerification::Unverifiable in zeph-a2a).
These are public verification keys, not secrets, so (unlike
A2aServerConfig::ibct_signing_key_vault_ref) they are stored inline rather than
via a vault reference.
Trait Implementations§
Source§impl Clone for A2aClientConfig
impl Clone for A2aClientConfig
Source§fn clone(&self) -> A2aClientConfig
fn clone(&self) -> A2aClientConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for A2aClientConfig
impl Debug for A2aClientConfig
Source§impl Default for A2aClientConfig
impl Default for A2aClientConfig
Source§impl<'de> Deserialize<'de> for A2aClientConfigwhere
A2aClientConfig: Default,
impl<'de> Deserialize<'de> for A2aClientConfigwhere
A2aClientConfig: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for A2aClientConfig
Source§impl PartialEq for A2aClientConfig
impl PartialEq for A2aClientConfig
Source§impl Serialize for A2aClientConfig
impl Serialize for A2aClientConfig
impl StructuralPartialEq for A2aClientConfig
Auto Trait Implementations§
impl Freeze for A2aClientConfig
impl RefUnwindSafe for A2aClientConfig
impl Send for A2aClientConfig
impl Sync for A2aClientConfig
impl Unpin for A2aClientConfig
impl UnsafeUnpin for A2aClientConfig
impl UnwindSafe for A2aClientConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.