(&self)
| 169 | |
| 170 | impl Push { |
| 171 | async fn execute(&self) -> CliResult<()> { |
| 172 | let store = IdentityStore::open_default().map_err(|e| { |
| 173 | CliError::Internal(anyhow::anyhow!("Failed to open identity store: {e}")) |
| 174 | })?; |
| 175 | |
| 176 | let documents = match &self.id { |
| 177 | Some(id) => vec![(normalize_id(id)?, load_document(&store, id)?)], |
| 178 | None => store |
| 179 | .list_delegations() |
| 180 | .map_err(|e| CliError::Internal(anyhow::anyhow!("Failed to list: {e}")))?, |
| 181 | }; |
| 182 | |
| 183 | if documents.is_empty() { |
| 184 | print_hint("No certificates to push."); |
| 185 | return Ok(()); |
| 186 | } |
| 187 | |
| 188 | let mut pushed = 0; |
| 189 | for (id, raw) in documents { |
| 190 | let Ok(value) = serde_json::from_str::<serde_json::Value>(&raw) else { |
| 191 | print_warning(&format!("Skipping {id}: not valid JSON")); |
| 192 | continue; |
| 193 | }; |
| 194 | let Ok(delegation) = cert::verify_self_contained(&value) else { |
| 195 | print_warning(&format!("Skipping {id}: does not verify")); |
| 196 | continue; |
| 197 | }; |
| 198 | if delegation.is_expired() { |
| 199 | continue; |
| 200 | } |
| 201 | |
| 202 | // The delegator must be on this machine — the server authenticates |
| 203 | // the *human*, since only they may enroll on their own behalf. |
| 204 | let Ok(delegator) = store.load_by_name(&delegation.delegator_name) else { |
| 205 | print_warning(&format!( |
| 206 | "Skipping {id}: the delegating identity '{}' is not on this machine", |
| 207 | delegation.delegator_name |
| 208 | )); |
| 209 | continue; |
| 210 | }; |
| 211 | |
| 212 | let (client, url) = |
| 213 | crate::commands::client::build_apex_client_as(&delegator, self.server.as_deref()) |
| 214 | .await?; |
| 215 | let request = PushDelegationRequest { certificate: value }; |
| 216 | match client.push_delegation(&request).await { |
| 217 | Ok(_) => { |
| 218 | println!(" {} → {url}", delegation.id.to_urn()); |
| 219 | pushed += 1; |
| 220 | } |
| 221 | Err(e) => print_warning(&format!("Failed to push {id}: {e}")), |
| 222 | } |
| 223 | } |
| 224 | |
| 225 | if pushed > 0 { |
| 226 | print_success(&format!("Pushed {pushed} certificate(s)")); |
| 227 | } |
| 228 | Ok(()) |
no test coverage detected