pub struct Handoff {
pub api: String,
pub secret: String,
pub acl: Option<String>,
pub accounts: Option<String>,
}Expand description
Where the shim sends the sequencer callback, and the loopback secret that callback authenticates with.
Written by the daemon at startup (crate::Node::write_ssh_handoff)
and read by the shim on each invocation. It exists because both values
are runtime state: the port may be ephemeral and the secret is minted
per process, so neither can be written into an authorized_keys line
that has to survive restarts.
Fields§
§api: StringBase URL of the running daemon, e.g. http://127.0.0.1:8417.
secret: StringThe daemon’s loopback secret, sent as X-Choir-Internal.
acl: Option<String>The ACL file the daemon itself is enforcing, when it has one.
A forced command whose --acl-file was forgotten would otherwise
be an authenticated key reaching every repository on a node that
authorizes every HTTP request — the ACL bypassed by the transport
rather than by a grant. Shim::decide falls back to this path,
so forgetting the flag costs an operator nothing and grants
nobody anything.
accounts: Option<String>The self-service credential store the daemon is enforcing (D36), when it has one.
The grants a token was issued with live there rather than in the ACL file, so a shim that read only the file would refuse every self-served account — the transport disagreeing with the daemon about who holds what. Read-only here: the shim never writes an account, and takes only the grants.
Implementations§
Source§impl Handoff
impl Handoff
Sourcepub fn parse(text: &str) -> Result<Self, String>
pub fn parse(text: &str) -> Result<Self, String>
Parses the two-key file format: <key> <value> lines, #
comments, blank lines ignored.
§Errors
Returns a message when a line is malformed, a key is unknown, or either key is missing. A half-read handoff is refused rather than used, because the failure it produces downstream is a push that silently misses the sequencer.