Resolve the signing identity for this change. Mirrors `resolve_author`'s precedence: `--identity` flag, then `--usage` default, then the global default identity. Loads the identity's keypair from the store. Returns `None` when no identity is available (the change records unsigned, with a warning).
(
&self,
)
| 119 | /// identity's keypair from the store. Returns `None` when no identity is |
| 120 | /// available (the change records unsigned, with a warning). |
| 121 | pub(super) fn resolve_signing_identity( |
| 122 | &self, |
| 123 | ) -> CliResult<Option<atomic_repository::record::SigningIdentity>> { |
| 124 | use atomic_canonical::did::did_for_public_key; |
| 125 | |
| 126 | let store = match IdentityStore::open_default() { |
| 127 | Ok(store) => store, |
| 128 | Err(_) => return Ok(None), |
| 129 | }; |
| 130 | |
| 131 | // 1. --identity flag |
| 132 | let identity = if let Some(identity_name) = &self.identity { |
| 133 | store |
| 134 | .load_by_name(identity_name) |
| 135 | .map_err(|_| CliError::IdentityNotFound(identity_name.clone()))? |
| 136 | // 2. --usage default |
| 137 | } else if let Some(usage_str) = &self.usage { |
| 138 | let usage = IdentityUsage::parse(usage_str); |
| 139 | match store.get_default_for_usage(&usage) { |
| 140 | Ok(Some(identity)) => identity, |
| 141 | _ => return Ok(None), |
| 142 | } |
| 143 | // 3. Global default |
| 144 | } else { |
| 145 | match store.get_default() { |
| 146 | Ok(Some(identity)) => identity, |
| 147 | _ => return Ok(None), |
| 148 | } |
| 149 | }; |
| 150 | |
| 151 | // Load the private key. A verification-only identity (no secret key |
| 152 | // on disk) cannot sign — record unsigned rather than fail. |
| 153 | let keypair = match store.load_keypair(&identity.id, None) { |
| 154 | Ok(keypair) => keypair, |
| 155 | Err(_) => return Ok(None), |
| 156 | }; |
| 157 | |
| 158 | Ok(Some(atomic_repository::record::SigningIdentity { |
| 159 | signer_did: did_for_public_key(&identity.public_key), |
| 160 | secret_key: *keypair.secret.as_bytes(), |
| 161 | })) |
| 162 | } |
| 163 | |
| 164 | /// Get the commit message, potentially from editor. |
| 165 | pub(super) fn get_message(&self) -> CliResult<String> { |
no test coverage detected