KeydbSource owns keydb save + update
Move the keydb save/validation/atomic-write path out of libfreemkv onto KeydbSource. New KeydbSource::save(bytes) validates + decompresses (zip / gz / plain, decompressed-size capped) and crash-safely writes to the source's OWN path (sibling-temp + fsync + rename + parent-dir fsync) — not a hardcoded default, so the caller chooses the destination. KeydbSource::update(fetch, url) calls an INJECTED fetch closure then save, keeping this crate transport-agnostic on the update path (the app supplies its own TLS / SSRF-guarded transport). UpdateResult moves here and is re-exported. Add flate2 + zip (already in the resolved graph via libfreemkv) for decompression; no new HTTP stack.
This commit is contained in:
@@ -16,6 +16,10 @@ libfreemkv = "1.0.0-rc.5.3"
|
||||
ureq = { version = "2", features = ["json"] }
|
||||
serde_json = "1"
|
||||
base64 = "0.22"
|
||||
# KeydbSource::save: decompress a downloaded keydb (.zip / .gz). Same versions
|
||||
# already in the resolved graph via libfreemkv — no new tree, no new HTTP stack.
|
||||
flate2 = "1"
|
||||
zip = { version = "2", default-features = false, features = ["deflate"] }
|
||||
# Structural begin/end logging around the keyserver round-trip (never logs
|
||||
# key material).
|
||||
tracing = "0.1"
|
||||
|
||||
Reference in New Issue
Block a user