(&self)
| 76 | |
| 77 | impl IntentVerify { |
| 78 | async fn execute(&self) -> CliResult<()> { |
| 79 | let root = find_repository_root()?; |
| 80 | let repo = Repository::open(&root).map_err(CliError::Repository)?; |
| 81 | |
| 82 | let inputs = bridge::read_intent(&repo, &self.id)?; |
| 83 | let node = match bridge::load_attestation(&repo, &self.id, &inputs)? { |
| 84 | bridge::Attestation::None => { |
| 85 | return Err(CliError::InvalidArgument { |
| 86 | message: format!( |
| 87 | "no attestation found for {}; run `atomic intent attest {}` first", |
| 88 | self.id, self.id |
| 89 | ), |
| 90 | }) |
| 91 | } |
| 92 | bridge::Attestation::Stale(_) => { |
| 93 | return Err(CliError::InvalidArgument { |
| 94 | message: format!( |
| 95 | "the attestation for {} is stale (the intent changed since it was \ |
| 96 | signed); re-run `atomic intent attest {}`", |
| 97 | self.id, self.id |
| 98 | ), |
| 99 | }) |
| 100 | } |
| 101 | bridge::Attestation::Fresh(node) => *node, |
| 102 | }; |
| 103 | |
| 104 | // Resolve the public key to verify against. Local store first; when |
| 105 | // `--identity <name>` is given but not present locally, fall back to |
| 106 | // the configured storage server. |
| 107 | let store = IdentityStore::open_default().map_err(|e| { |
| 108 | CliError::Internal(anyhow::anyhow!("Failed to open identity store: {e}")) |
| 109 | })?; |
| 110 | |
| 111 | let (public_key, source) = if let Some(name) = &self.identity { |
| 112 | match store.load_by_name(name) { |
| 113 | Ok(identity) => { |
| 114 | let did = identity.id.to_base32(); |
| 115 | ( |
| 116 | identity.public_key, |
| 117 | source_line(name, &did, "local identity store"), |
| 118 | ) |
| 119 | } |
| 120 | Err(_) => { |
| 121 | let resolved = self.resolve_remote(name, &node).await?; |
| 122 | (resolved.key, resolved.source) |
| 123 | } |
| 124 | } |
| 125 | } else { |
| 126 | let identity = store |
| 127 | .get_default() |
| 128 | .map_err(|e| { |
| 129 | CliError::Internal(anyhow::anyhow!("Failed to load default identity: {e}")) |
| 130 | })? |
| 131 | .ok_or_else(|| CliError::InvalidArgument { |
| 132 | message: "No default identity set. Create one first:\n \ |
| 133 | atomic identity new <name> --email <email> --set-default" |
| 134 | .to_string(), |
| 135 | })?; |
no test coverage detected