The encoded certificate this identity presents, if it is an agent. Management calls are normally made by a human and this returns `None`. It exists so the few paths an agent legitimately drives — reading its own project list, say — carry the certificate too, rather than failing with a puzzling 401 that says the request was delegated but presented nothing.
(identity: &atomic_identity::Identity, server: &str)
| 116 | /// project list, say — carry the certificate too, rather than failing with a |
| 117 | /// puzzling 401 that says the request was delegated but presented nothing. |
| 118 | fn delegation_for(identity: &atomic_identity::Identity, server: &str) -> Option<String> { |
| 119 | if !identity.identity_type.is_delegated() { |
| 120 | return None; |
| 121 | } |
| 122 | let store = IdentityStore::open_default().ok()?; |
| 123 | let resolved = crate::commands::delegation::active_for(&store, identity, Some(server)).ok()?; |
| 124 | Some(atomic_canonical::delegation::encode_for_transport( |
| 125 | &resolved.document, |
| 126 | )) |
| 127 | } |
| 128 | |
| 129 | /// Resolve just the apex server URL for a server override. |
| 130 | /// |
no test coverage detected