MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / compute_verifies

Function compute_verifies

atomic-cli/src/commands/intent/list.rs:203–222  ·  view source on GitHub ↗

The DID-match-then-verify rule for an intent. Pure over its inputs so it can be unit-tested without a global `IdentityStore`. - `attested` None ⇒ `Na`. - `attested` Stale ⇒ `Na` (staleness is surfaced by the attested column; there is nothing fresh to cryptographically verify — do NOT feed a Stale node to `verify`, which would report `✗` on a changed-but-validly-signed node). - `attested` Fresh: -

(attested: &bridge::Attestation, verifier: Option<&Verifier>)

Source from the content-addressed store, hash-verified

201/// would be a false negative);
202/// - same signer ⇒ run `verify`: `Ok` ⇒ `Yes`, `Err` ⇒ `No`.
203fn compute_verifies(attested: &bridge::Attestation, verifier: Option<&Verifier>) -> Verifies {
204 let node = match attested {
205 bridge::Attestation::Fresh(node) => node,
206 bridge::Attestation::Stale(_) | bridge::Attestation::None => return Verifies::Na,
207 };
208 let verifier = match verifier {
209 Some(v) => v,
210 None => return Verifies::Na,
211 };
212 // DID pre-check FIRST: a different (or absent) signer is `–`, not `✗`.
213 match node.attributed_to.as_deref() {
214 Some(signer) if signer == verifier.did => {}
215 _ => return Verifies::Na,
216 }
217 // Same signer ⇒ the only path that can yield `✗` is a real hash/sig failure.
218 match atomic_canonical::verify(node, &verifier.public_key) {
219 Ok(()) => Verifies::Yes,
220 Err(_) => Verifies::No,
221 }
222}
223
224/// Classify a loaded attestation into the `attested` column token.
225fn classify(attested: &bridge::Attestation) -> Attested {

Callers 1

compute_rowFunction · 0.70

Calls 1

verifyFunction · 0.50

Tested by

no test coverage detected