MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / decode_from_transport

Function decode_from_transport

atomic-canonical/src/delegation.rs:303–317  ·  view source on GitHub ↗

Decode a certificate presented in a request header. Checks the size cap first, then base64, then JSON. Does **not** verify — [`verify`] against the delegator's registered key is a separate, mandatory step, and keeping them apart means no call site can accidentally treat a well-formed certificate as a trusted one.

(encoded: &str)

Source from the content-addressed store, hash-verified

301/// step, and keeping them apart means no call site can accidentally treat a
302/// well-formed certificate as a trusted one.
303pub fn decode_from_transport(encoded: &str) -> Result<Value> {
304 if encoded.len() > MAX_ENCODED_DELEGATION {
305 return Err(CanonicalError::Proof(format!(
306 "delegation is {} bytes, over the {MAX_ENCODED_DELEGATION}-byte limit",
307 encoded.len()
308 )));
309 }
310
311 let bytes = data_encoding::BASE64URL_NOPAD
312 .decode(encoded.trim().as_bytes())
313 .map_err(|e| CanonicalError::Proof(format!("delegation is not valid base64url: {e}")))?;
314
315 serde_json::from_slice(&bytes)
316 .map_err(|e| CanonicalError::Proof(format!("delegation is not valid JSON: {e}")))
317}
318
319/// A stable fingerprint of an encoded certificate, for caching a verified
320/// result without re-running the Ed25519 check on every request.

Calls 4

ProofClass · 0.85
lenMethod · 0.45
decodeMethod · 0.45
as_bytesMethod · 0.45