MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / load_for_delegate

Function load_for_delegate

atomic-canonical/src/delegation.rs:516–552  ·  view source on GitHub ↗

Every verified certificate in `store` naming `delegate` as its subject, newest first. Certificates that fail to parse or verify are **skipped**, not returned as errors. This is the one place a corrupt or foreign file in the store could otherwise take down every agent operation, and a certificate that does not verify has no authority to convey in any case. Each skip is logged at warn. Verificatio

(
    store: &atomic_identity::IdentityStore,
    delegate: &Identity,
)

Source from the content-addressed store, hash-verified

514/// Verification is self-contained — it uses the delegator key the certificate
515/// carries — so this works on a machine that holds only the agent's key.
516pub fn load_for_delegate(
517 store: &atomic_identity::IdentityStore,
518 delegate: &Identity,
519) -> Result<Vec<StoredDelegation>> {
520 let delegate_did = delegate.id.to_did();
521 let stored = store
522 .list_delegations()
523 .map_err(|e| CanonicalError::Proof(format!("failed to list delegations: {e}")))?;
524
525 let mut out = Vec::new();
526 for (id, raw) in stored {
527 let Ok(value) = serde_json::from_str::<Value>(&raw) else {
528 continue;
529 };
530 // Cheap discriminator before the Ed25519 verify: most certificates in
531 // a store belong to some other agent.
532 match parse(&value) {
533 Ok(parsed) if parsed.delegate == delegate_did => {}
534 _ => continue,
535 }
536 let Ok(delegation) = verify_self_contained(&value) else {
537 continue;
538 };
539
540 out.push(StoredDelegation {
541 revoked_locally: store.is_revoked_locally(&id),
542 id,
543 delegation,
544 document: value,
545 });
546 }
547
548 // Newest first: when several certificates cover the same ground, the most
549 // recently issued is the one the human meant.
550 out.sort_by_key(|d| std::cmp::Reverse(d.delegation.issued));
551 Ok(out)
552}
553
554/// The certificate currently in force for `delegate`, if any.
555pub fn active_for_delegate(

Callers 1

active_for_delegateFunction · 0.70

Calls 7

ProofClass · 0.85
verify_self_containedFunction · 0.85
to_didMethod · 0.80
is_revoked_locallyMethod · 0.80
parseFunction · 0.70
list_delegationsMethod · 0.45
pushMethod · 0.45

Tested by

no test coverage detected