Skip to main content

Handoff

Struct Handoff 

Source
pub struct Handoff {
    pub api: String,
    pub secret: String,
    pub acl: Option<String>,
    pub accounts: Option<String>,
}
Expand description

Where the shim sends the sequencer callback, and the loopback secret that callback authenticates with.

Written by the daemon at startup (crate::Node::write_ssh_handoff) and read by the shim on each invocation. It exists because both values are runtime state: the port may be ephemeral and the secret is minted per process, so neither can be written into an authorized_keys line that has to survive restarts.

Fields§

§api: String

Base URL of the running daemon, e.g. http://127.0.0.1:8417.

§secret: String

The daemon’s loopback secret, sent as X-Choir-Internal.

§acl: Option<String>

The ACL file the daemon itself is enforcing, when it has one.

A forced command whose --acl-file was forgotten would otherwise be an authenticated key reaching every repository on a node that authorizes every HTTP request — the ACL bypassed by the transport rather than by a grant. Shim::decide falls back to this path, so forgetting the flag costs an operator nothing and grants nobody anything.

§accounts: Option<String>

The self-service credential store the daemon is enforcing (D36), when it has one.

The grants a token was issued with live there rather than in the ACL file, so a shim that read only the file would refuse every self-served account — the transport disagreeing with the daemon about who holds what. Read-only here: the shim never writes an account, and takes only the grants.

Implementations§

Source§

impl Handoff

Source

pub fn parse(text: &str) -> Result<Self, String>

Parses the two-key file format: <key> <value> lines, # comments, blank lines ignored.

§Errors

Returns a message when a line is malformed, a key is unknown, or either key is missing. A half-read handoff is refused rather than used, because the failure it produces downstream is a push that silently misses the sequencer.

Source

pub fn load(path: &Path) -> Result<Self, String>

Reads and parses the file at path.

§Errors

Returns a message when the file cannot be read or does not parse.

Trait Implementations§

Source§

impl Clone for Handoff

Source§

fn clone(&self) -> Handoff

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Handoff

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl PartialEq for Handoff

Source§

fn eq(&self, other: &Handoff) -> bool

Tests for self and other values to be equal, and is used by ==.
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Tests for !=. The default implementation is almost always sufficient, and should not be overridden without very good reason.
Source§

impl Eq for Handoff

Source§

impl StructuralPartialEq for Handoff

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.