MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / save_secret_key

Method save_secret_key

atomic-identity/src/store.rs:458–498  ·  view source on GitHub ↗

Save a secret key (with optional encryption).

(
        &self,
        identity_dir: &Path,
        secret_key: &SecretKey,
        password: Option<&str>,
    )

Source from the content-addressed store, hash-verified

456
457 /// Save a secret key (with optional encryption).
458 fn save_secret_key(
459 &self,
460 identity_dir: &Path,
461 secret_key: &SecretKey,
462 password: Option<&str>,
463 ) -> Result<(), IdentityError> {
464 let secret_path = identity_dir.join(Self::SECRET_KEY_FILE);
465
466 if let Some(_password) = password {
467 // TODO: Implement proper password-based encryption
468 // For now, we'll store it with a marker that it should be encrypted
469 let stored = StoredSecretKey {
470 data: data_encoding::BASE64.encode(secret_key.as_bytes()),
471 encryption: "none".to_string(), // TODO: Change to "argon2id+chacha20poly1305"
472 salt: None,
473 nonce: None,
474 };
475 let content = toml::to_string_pretty(&stored)?;
476 fs::write(&secret_path, content)?;
477 } else {
478 // Store unencrypted (not recommended for production)
479 let stored = StoredSecretKey {
480 data: data_encoding::BASE64.encode(secret_key.as_bytes()),
481 encryption: "none".to_string(),
482 salt: None,
483 nonce: None,
484 };
485 let content = toml::to_string_pretty(&stored)?;
486 fs::write(&secret_path, content)?;
487 }
488
489 // Set restrictive permissions on Unix
490 #[cfg(unix)]
491 {
492 use std::os::unix::fs::PermissionsExt;
493 let permissions = fs::Permissions::from_mode(0o600);
494 fs::set_permissions(&secret_path, permissions)?;
495 }
496
497 Ok(())
498 }
499
500 /// Load an identity by ID.
501 pub fn load(&self, id: &IdentityId) -> Result<Identity, IdentityError> {

Callers 1

save_with_secretMethod · 0.80

Calls 4

writeFunction · 0.85
set_permissionsFunction · 0.85
encodeMethod · 0.45
as_bytesMethod · 0.45

Tested by

no test coverage detected