Oregami
Repositories/oxedyne/fe2o3

oxedyne/fe2o3/fe2o3_pearlite/src/collab/keyring.rs

2.0 KiB, 1 run

created by r1870400018:59040, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1//! Who a signer is, in a form a reader can show.
2//!
3//! An operation is attributed to the key that signed it, not to a name written in its body -- a name
4//! is free text and any key can claim any name. What a person needs to see, though, is a name and not a
5//! key, so a document carries a keyring: a map from a signer's [`fingerprint`](super::fingerprint) to
6//! the display name that signer goes by in this document. A signer the keyring does not name is shown
7//! by its fingerprint, which is unforgeable and unambiguous even if it is not friendly.
8//!
9//! # What this is not, yet
10//!
11//! This is not a membership model. It says what to *call* a signer, not whether that signer is
12//! *allowed* to annotate the document -- who may write to a document, and who may say so, is a
13//! governance question the next increment answers with a first-class, signed keyring object. Here the
14//! rule is only that the signer is the identity and the keyring supplies its name; an unknown signer is
15//! displayed, not rejected.
16
17use oxedyne_fe2o3_core::prelude::*;
18
19use std::collections::BTreeMap;
20
21
22/// The names the signers of a document's operations go by, keyed by signer fingerprint.
23#[derive(Clone, Debug, Default, Eq, PartialEq)]
24pub struct Keyring {
25 names: BTreeMap<String, String>, // signer fingerprint -> display name
26}
27
28impl Keyring {
29 pub fn new() -> Self {
30 Self::default()
31 }
32
33 /// Records the name a signer, named by its public key, goes by in this document.
34 pub fn insert<S: Into<String>>(&mut self, pubkey: &[u8], name: S) {
35 self.names.insert(super::fingerprint(pubkey), name.into());
36 }
37
38 /// The name to display for the signer whose public key this is: the keyring's name where it holds
39 /// one, and otherwise the fingerprint itself, which names the signer unambiguously if not amiably.
40 pub fn display(&self, pubkey: &[u8]) -> String {
41 let fp = super::fingerprint(pubkey);
42 match self.names.get(&fp) {
43 Some(name) => name.clone(),
44 None => fp,
45 }
46 }
47
48 pub fn is_empty(&self) -> bool {
49 self.names.is_empty()
50 }
51
52 pub fn len(&self) -> usize {
53 self.names.len()
54 }
55}