Sigil documentation
ReferenceRust referencesigil-labor-api

sigil-labor-api · auth

Source declarations, signatures and documentation for auth.

Source: sigil/node/../labor-api/src/auth.rs. SHA-256: 394b621dd57390f77fdc00e59c8c06657a89c1344ffa137e206c9c3b96b6504c.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

auth::MAX_CLOCK_SKEW_SECS

Maximum allowed clock skew between client and server.

pub const MAX_CLOCK_SKEW_SECS: i64;

Source line: 65.

auth::AuthDid

The authenticated principal, attached as a request extension after the auth middleware runs. Handlers extract it via axum::Extension<AuthDid>.

#[derive(Debug, Clone)]
pub struct AuthDid {
pub did: String,
pub public_key: [u8; 32]
}

Source line: 73.

auth::AuthDid::as_str

Convenience: returns the DID as a &str.

pub fn as_str(&self) -> &str;

Source line: 80.

auth::AuthError

Errors produced by the auth middleware. Each variant maps to an HTTP 4xx with a stable error code so clients can branch.

#[derive(Debug)]
pub enum AuthError {
    MissingHeader(&'static str),
    BadHeader { name: &'static str, reason: String },
    BadTimestamp(String),
    ClockSkew { skew_secs: i64 },
    BadSignature,
    DidPubkeyMismatch,
    DidRegistryUnavailable(String),
    DidRegistryRejected(String),
    BodyTooLarge,
    InternalError(String),
}

Source line: 88.

auth::canonical_request_bytes

Build the canonical request transcript that the client signs.

pub fn canonical_request_bytes(
    method: &str,
    path: &str,
    timestamp_iso: &str,
    body: &[u8],
) -> Vec<u8>;

Source line: 159.

auth::require_did_signed

Tower middleware that authenticates the request via DID-signed headers.

Read-only routes (HTTP GET, plus the /health probe) bypass auth so observability and probes work without credentials. Mutating routes require the full header set.

pub async fn require_did_signed(req: Request, next: Next) -> Result<Response, AuthError>;

Source line: 185.

On this page