Struct NSSKeyManager
pub struct NSSKeyManager { /* private fields */ }Expand description
Use the NSSKeyManager to use NSS for key management.
NSS stores keys in key4.db within the profile and wraps the key with a key derived from the
primary password, if set. It defers to the provided PrimaryPasswordAuthenticator
implementation to handle user authentication. Note that if no primary password is set, the
wrapping key is deterministically derived from an empty string.
Make sure to initialize NSS using ensure_initialized_with_profile_dir before creating a
NSSKeyManager.
The key is cached after the first retrieval, since fetching it from NSS costs at least one token round-trip. The cache is dropped whenever the token turns out to be locked again.
§Examples
use async_trait::async_trait;
use db_crypto::KeyManager;
use db_crypto::{PrimaryPasswordAuthenticator, DbCryptoApiError, NSSKeyManager};
use std::sync::Arc;
struct MyPrimaryPasswordAuthenticator {}
#[async_trait]
impl PrimaryPasswordAuthenticator for MyPrimaryPasswordAuthenticator {
async fn get_primary_password(&self) -> Result<String, DbCryptoApiError> {
// Most likely, you would want to prompt for a password.
// let password = prompt_string("primary password").unwrap_or_default();
Ok("secret".to_string())
}
async fn on_authentication_success(&self) -> Result<(), DbCryptoApiError> {
println!("success");
Ok(())
}
async fn on_authentication_failure(&self) -> Result<(), DbCryptoApiError> {
println!("this did not work, please try again:");
Ok(())
}
}
let key_manager = NSSKeyManager::new(String::from("example"), Arc::new(MyPrimaryPasswordAuthenticator {}));
assert_eq!(key_manager.get_key().unwrap().len(), 63);Implementations§
§impl NSSKeyManager
impl NSSKeyManager
pub fn new(
key_name: String,
primary_password_authenticator: Arc<dyn PrimaryPasswordAuthenticator>,
) -> NSSKeyManager
pub fn new( key_name: String, primary_password_authenticator: Arc<dyn PrimaryPasswordAuthenticator>, ) -> NSSKeyManager
Initialize new NSSKeyManager with a given PrimaryPasswordAuthenticator.
There must be a previous initializiation of NSS before initializing
NSSKeyManager, otherwise this panics.
pub fn into_dyn_key_manager(self: Arc<NSSKeyManager>) -> Arc<dyn KeyManager>
Trait Implementations§
§impl KeyManager for NSSKeyManager
Available on crate feature keydb only.
impl KeyManager for NSSKeyManager
keydb only.§impl<UT> LiftRef<UT> for NSSKeyManager
impl<UT> LiftRef<UT> for NSSKeyManager
type LiftType = Arc<NSSKeyManager>
§impl<UT> LowerError<UT> for NSSKeyManager
impl<UT> LowerError<UT> for NSSKeyManager
§fn lower_error(obj: NSSKeyManager) -> RustBuffer
fn lower_error(obj: NSSKeyManager) -> RustBuffer
§impl<UT> LowerReturn<UT> for NSSKeyManager
impl<UT> LowerReturn<UT> for NSSKeyManager
§type ReturnType = <Arc<NSSKeyManager> as LowerReturn<UniFfiTag>>::ReturnType
type ReturnType = <Arc<NSSKeyManager> as LowerReturn<UniFfiTag>>::ReturnType
§fn lower_return(
obj: NSSKeyManager,
) -> Result<<NSSKeyManager as LowerReturn<UT>>::ReturnType, RustCallError>
fn lower_return( obj: NSSKeyManager, ) -> Result<<NSSKeyManager as LowerReturn<UT>>::ReturnType, RustCallError>
§fn handle_failed_lift(
error: LiftArgsError,
) -> Result<Self::ReturnType, RustCallError>
fn handle_failed_lift( error: LiftArgsError, ) -> Result<Self::ReturnType, RustCallError>
§impl<UT> TypeId<UT> for NSSKeyManager
impl<UT> TypeId<UT> for NSSKeyManager
const TYPE_ID_META: MetadataBuffer
Auto Trait Implementations§
impl !Freeze for NSSKeyManager
impl !RefUnwindSafe for NSSKeyManager
impl Send for NSSKeyManager
impl Sync for NSSKeyManager
impl Unpin for NSSKeyManager
impl !UnwindSafe for NSSKeyManager
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T, UT> HandleAlloc<UT> for T
impl<T, UT> HandleAlloc<UT> for T
§fn new_handle(value: Arc<T>) -> Handle
fn new_handle(value: Arc<T>) -> Handle
§unsafe fn clone_handle(handle: Handle) -> Handle
unsafe fn clone_handle(handle: Handle) -> Handle
§unsafe fn consume_handle(handle: Handle) -> Arc<T>
unsafe fn consume_handle(handle: Handle) -> Arc<T>
Arc<> Read more