MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / delegate_from_request

Method delegate_from_request

atomic-cli/src/commands/identity/delegate.rs:315–359  ·  view source on GitHub ↗

Verify a self-signed request and turn it into a delegate identity. The verification is the point: it proves whoever produced the request holds the private half of the key it names. Without it, `--request` would be a way to talk someone into signing a certificate for a key chosen by an attacker.

(&self, path: &str)

Source from the content-addressed store, hash-verified

313 /// would be a way to talk someone into signing a certificate for a key
314 /// chosen by an attacker.
315 fn delegate_from_request(&self, path: &str) -> CliResult<Identity> {
316 let raw = if path == "-" {
317 use std::io::Read;
318 let mut buf = String::new();
319 std::io::stdin().read_to_string(&mut buf)?;
320 buf
321 } else {
322 std::fs::read_to_string(path)?
323 };
324
325 let value: serde_json::Value =
326 serde_json::from_str(&raw).map_err(|e| CliError::InvalidArgument {
327 message: format!("{path} is not valid JSON: {e}"),
328 })?;
329
330 let request = cert::verify_request(&value).map_err(|e| CliError::DelegationError {
331 message: format!(
332 "The request in {path} does not verify: {e}\n \
333 Only countersign a request whose self-signature checks out — it is the \
334 only evidence the far end actually holds that key."
335 ),
336 })?;
337
338 let public_key =
339 atomic_identity::PublicKey::from_did_key(&request.delegate_key).map_err(|e| {
340 CliError::DelegationError {
341 message: format!("Request carries a malformed key: {e}"),
342 }
343 })?;
344
345 print_hint(&format!(
346 "Countersigning a verified request from '{}' ({})",
347 request.delegate_name, request.delegate
348 ));
349
350 let mut builder = Identity::builder(&request.delegate_name)
351 .identity_type(IdentityType::Agent)
352 .public_key(public_key);
353 if let Some(agent) = &request.software_agent {
354 builder = builder.description(format!("software-agent:{agent}"));
355 }
356 builder
357 .build()
358 .map_err(|e| CliError::Internal(anyhow::anyhow!("Failed to build delegate: {e}")))
359 }
360}
361
362/// Recover the software-agent URN we stash in an identity description.

Callers 1

runMethod · 0.80

Calls 6

verify_requestFunction · 0.85
print_hintFunction · 0.85
public_keyMethod · 0.45
identity_typeMethod · 0.45
descriptionMethod · 0.45
buildMethod · 0.45

Tested by

no test coverage detected