The delegation certificate currently authorizing this agent, as a URN. Recorded on the change envelope so a reader months later can ask the server whether that specific certificate was still good, rather than inferring authority from an author string. Returns `None` when no agent identity is configured or none of its certificates is currently in force — the plus-tag path has no certificate to nam
(
agent_identity: Option<&str>,
identity_dir: Option<&Path>,
)
| 140 | /// configured or none of its certificates is currently in force — the plus-tag |
| 141 | /// path has no certificate to name. |
| 142 | pub fn active_delegation_urn( |
| 143 | agent_identity: Option<&str>, |
| 144 | identity_dir: Option<&Path>, |
| 145 | ) -> Option<String> { |
| 146 | let name = agent_identity |
| 147 | .map(str::to_string) |
| 148 | .or_else(|| std::env::var(AGENT_IDENTITY_ENV).ok()) |
| 149 | .map(|n| n.trim().to_string()) |
| 150 | .filter(|n| !n.is_empty())?; |
| 151 | |
| 152 | let store = match identity_dir { |
| 153 | Some(dir) => atomic_identity::IdentityStore::open(dir), |
| 154 | None => atomic_identity::IdentityStore::open_default(), |
| 155 | } |
| 156 | .ok()?; |
| 157 | |
| 158 | let identity = store.load_by_name(&name).ok()?; |
| 159 | atomic_canonical::delegation::active_for_delegate(&store, &identity) |
| 160 | .map(|d| d.delegation.id.to_urn()) |
| 161 | } |
| 162 | |
| 163 | /// Environment variable naming the delegated agent identity to sign as. |
| 164 | /// |
no test coverage detected