Skip to main content

Crate vault_core

Crate vault_core 

Source
Expand description

vault-core — shared encryption, storage, and tooling for UnENVerse.

Used by the Tauri desktop app, the HTTP server (unv-server), and the CLI (unv-cli). Has no dependency on Tauri; accepts &Path for all I/O.

Re-exports§

pub use generators::generate_certificate;
pub use generators::generate_ssh_keypair;
pub use permex::eval as eval_perm_expr;
pub use permex::parse as parse_perm_expr;
pub use permex::EntryView;
pub use permex::Expr as PermExpr;
pub use permex::Field as PermField;
pub use users::assign_user_class;
pub use users::authority_tier;
pub use users::class_authority_tier;
pub use users::create_user;
pub use users::create_user_class;
pub use users::create_user_token;
pub use users::delete_user;
pub use users::delete_user_class;
pub use users::effective_permission_expr;
pub use users::ensure_owner_user;
pub use users::filter_vault_for_user;
pub use users::get_class_permissions;
pub use users::get_permission_expr;
pub use users::get_user_capabilities;
pub use users::get_user_permissions;
pub use users::glob_matches;
pub use users::init_users_schema;
pub use users::list_user_classes;
pub use users::list_user_tokens;
pub use users::list_users;
pub use users::merge_user_vault_write;
pub use users::rename_user;
pub use users::revoke_user_token;
pub use users::seed_default_admin;
pub use users::set_class_permissions;
pub use users::set_permission_expr;
pub use users::set_user_password;
pub use users::set_user_permissions;
pub use users::token_user_id;
pub use users::update_user_class;
pub use users::user_authority_tier;
pub use users::verify_user_password;
pub use users::verify_user_token;
pub use users::AdminSeed;
pub use users::ClassPermission;
pub use users::PermissionRecord;
pub use users::TokenRecord;
pub use users::UserClass;
pub use users::UserRecord;

Modules§

blast
Phase 36 — blast radius (ADR-0142).
bundle_import
Import a Python config module as bundle-local variables (Phase 24.1).
bundle_scope
Bundle-local template resolution (Phase 24.1, step 4).
calendar
iCalendar (RFC 5545) feed for the vault’s dates — the Rust twin of src/ts/calendar.ts.
catalogue
The provider catalogue: a signed, public table of issuer key prefixes that unv enrich consults before the table compiled into the binary.
composite
Composite secrets (Phase 24.1) — one value with secrets inside it.
config_check
Cross-chunk, cross-format checks for a project (Phase 29, “the config compiler”; ADR-0137).
config_history
Phase 35 — the config time machine (ADR-0141).
cxf
FIDO Credential Exchange (CXF) import and export — Phase 24.5.
entropy
Entropy sources for secret generation.
generators
Cryptographic key and certificate generators.
ics_feeds
Calendar feed tokens — Phase 24.3.
jwks
The public half of a signing_key as a JSON Web Key Set (Phase 24.5).
nodes
Phase 34 — Nodes: the protocol, the hub’s registry and the node’s config.
nodes_apply
Phase 34 — the filesystem half of a node: hash a target, apply bytes to it transactionally, and keep the last few versions.
oauth
OAuth refresh-token grants, shared by unv oauth refresh and the desktop app’s “Refresh access token” (Phase 24.5). Pure over JSON: the HTTP call is the caller’s (the CLI’s blocking client, the app’s pinned remote_request), so there is exactly one reading of what an issuer’s answer means and one rule for what gets stored.
permex
Permission expressions — a small boolean language over vault entries.
pgp
What an OpenPGP key says about itself: fingerprint, key id, user ids and, the reason this exists, when it expires (Phase 24.5, gpg_key).
php_config
A reader for PHP array literals, enough for application config files such as Nextcloud’s config/config.php (Phase 38.1, ADR-0148).
pool
The key-pool state file: pools.json.
secret_types
The secret-type registry — Phase 24.5.
session_import
Web-session capture parsers (Phase 24.5, step 3).
stack
Phase 38 — stack integrations as data (ADR-0144).
storage
Row-per-entry storage, schema v2 (Phase 30, review-01 section 2.1; ADR-0138).
telemetry
Structured logging, shared by all three binaries.
templates
Secret templates: predefined field presets for common services (a GitHub PAT, an AWS key, a Postgres DSN). One JSON file at the repo root, secret-templates.json, compiled in here and imported by the app’s Templates pane, so unv entry add --template ID and the pane offer the same presets (Phase 33.6).
textdiff
A small line diff for rendered config files (Phase 35).
tls
Shared TLS client policy — the one place that decides whether a server is trusted.
toml_import
Import TOML config values as environment-style name/value pairs.
totp
RFC 6238 time-based one-time passwords.
totp_import
Reading and writing the export files other authenticator apps produce.
type_emit
Per-type emitters and validators for the Phase 24.5 credential types.
uid_registry
The unique-ID registry — Phase 24.4.
users
User management, token management, and RBAC for UnENVerse.

Structs§

AuditRow
A single audit log row, including the hash-chain fields.
SaveCtx
Who is writing, and what they believe the vault currently is.
SqlConnection
A connection to a SQLite database.

Constants§

CONFLICT_ERR
Marker prefix on the error returned when a compare-and-swap write is refused. Callers match on this to tell “someone else wrote first” from a real failure.
KEY_LEN
MERGED_SUFFIX
Appended to the version returned by a save that folded in other writers’ changes (Phase 30). The part before it is the current version token; a writer that sends the whole thing back as expect_version is understood.
SALT_LEN
SCHEMA_ERR
Marker prefix on the error returned when the stored vault was written by a newer build than this one. Callers match on it to tell “upgrade me” from a real failure.
VAULT_SCHEMA_VERSION
The vault-document schema this build writes.

Traits§

Zeroize
Trait for securely erasing values from memory.

Functions§

apply_row_patch
Phase 30.1: apply a delta to a stored vault document. Shared by PATCH /api/vault and the desktop’s save_vault_rows so they cannot differ.
check_salt_pairing
Refuse to derive a key when a database exists but its salt does not.
check_schema_version
Refuses to touch a vault written by a newer build.
derive_key
Derives a 32-byte AES-256 key from password and salt using Argon2id (m=65536 KiB, t=3, p=1 — OWASP 2023 recommendation).
ensure_current_schema
Refuse a newer schema and convert a v1 vault, so that a version read after this is a version of the converted vault. A caller that reads the version before the data (the safe order, see the server’s PUT handler) must call this first, or it pairs a v1 hash with a v2 document and its first save conflicts.
entry_ck
Canonical identity key for a vault entry.
env_quote
A value as it must appear after the = in a .env (Phase 23, E1).
get_expiring_entries
Returns vault entries whose expires_at date falls within within_days days from today (inclusive of today, exclusive of entries already expired).
get_expiring_entries_for_user
Like get_expiring_entries but first filters the vault to the entries the user is permitted to read. Prevents non-owner sessions from learning about the expiry (and full contents) of secrets outside their RBAC scope.
init_schema
Creates the vault and vault_audit tables if absent; adds hash-chain columns to vault_audit via idempotent ALTER TABLE (errors silently ignored on existing columns).
iso_now
load_audit
Returns all audit rows ordered newest-first.
load_vault
Loads the raw vault JSON from an open connection.
load_vault_lite
The vault document without any entry’s version_history: what a selective read needs, without the 50-revision secret trail per entry that a full read carries (Phase 30).
migrate_legacy_json
Inserts raw JSON from a legacy vault.json into the vault table. Called once on first unlock after a Phase 1 → Phase 2 upgrade.
new_uuid
Returns the current UTC time as an ISO-8601 string (YYYY-MM-DDTHH:MM:SSZ). A random UUID v4, with the version and variant bits set.
open_db
Opens (or creates) the SQLCipher database at db_path using the 32-byte key.
read_or_create_salt
Reads salt from salt_path; generates and writes a fresh 16-byte salt if absent.
record_event
Records a hash-chained audit event with the current timestamp.
restrict_to_owner
Restrict a file to its owner where the platform can express that.
save_vault
Serialises data to the vault, updating version_history on key changes and appending to the vault_audit hash chain. Returns the new version.
vault_schema_version
The schema version stamped on the stored vault, or None for a vault written before versioning existed (or an empty database).
vault_version
Current version of the stored vault, or None when the vault is empty.
verify_vault_integrity
Verifies the stored vault data against its SHA-256 integrity hash. Returns Ok(true) if hash matches, Ok(false) if tampered or hash absent, Err on I/O.

Type Aliases§

VaultKey
In-memory AES-256 vault key.

Derive Macros§

Zeroize
Derive the Zeroize trait.