style: fmt + clippy cleanup after Phase C
cargo fmt regroups; three clippy fixes: - F-S-006: hoist MAX_API_KEY_CANDIDATES to module scope to satisfy clippy::items_after_statements. - F-S-009: use map_or instead of map().unwrap_or() per clippy::map_unwrap_or. - F-P-012: replace `|c| c.encode()` closure with the method itself per clippy::redundant_closure_for_method_calls. No behavior change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -53,6 +53,11 @@ pub struct PrincipalCache {
|
||||
/// adjacent requests on a hot key.
|
||||
const PRINCIPAL_CACHE_TTL: Duration = Duration::from_secs(60);
|
||||
|
||||
/// F-S-006: maximum candidate API keys we'll Argon2-verify per
|
||||
/// request. Hoisted to module scope so clippy::items_after_statements
|
||||
/// is happy.
|
||||
const MAX_API_KEY_CANDIDATES: usize = 16;
|
||||
|
||||
impl PrincipalCache {
|
||||
#[must_use]
|
||||
pub fn new() -> Self {
|
||||
@@ -277,7 +282,6 @@ async fn verify_api_key(state: &AuthState, rest: &str) -> Result<Option<Principa
|
||||
// many keys against one indexed prefix could amplify each public
|
||||
// bearer-tagged request into M×Argon2 verifies. Cap at MAX and
|
||||
// log the truncation so operators can spot it.
|
||||
const MAX_API_KEY_CANDIDATES: usize = 16;
|
||||
if candidates.len() > MAX_API_KEY_CANDIDATES {
|
||||
tracing::warn!(
|
||||
prefix,
|
||||
|
||||
@@ -311,7 +311,12 @@ impl Dispatcher {
|
||||
};
|
||||
let outcome = self
|
||||
.executor
|
||||
.execute_with_identity(identity, &script.source, exec_req, async_exec_timeout_from_env())
|
||||
.execute_with_identity(
|
||||
identity,
|
||||
&script.source,
|
||||
exec_req,
|
||||
async_exec_timeout_from_env(),
|
||||
)
|
||||
.await;
|
||||
drop(permit);
|
||||
|
||||
|
||||
@@ -587,7 +587,10 @@ impl UsersService for UsersServiceImpl {
|
||||
.collect();
|
||||
Ok(UsersListPage {
|
||||
items,
|
||||
next_cursor: page.next_cursor.as_ref().map(|c| c.encode()),
|
||||
next_cursor: page
|
||||
.next_cursor
|
||||
.as_ref()
|
||||
.map(crate::app_user_repo::ListCursor::encode),
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
@@ -362,8 +362,7 @@ pub async fn build_app(
|
||||
// Dispatcher — single tokio task that polls the outbox and routes
|
||||
// due rows to the executor. Shares the `ExecutionGate` with sync
|
||||
// HTTP per design notes §2 (one cap for everything).
|
||||
let dispatcher_script_repo: Arc<dyn ScriptRepository> =
|
||||
script_repo.clone();
|
||||
let dispatcher_script_repo: Arc<dyn ScriptRepository> = script_repo.clone();
|
||||
let principals: Arc<dyn PrincipalResolver> =
|
||||
Arc::new(AdminPrincipalResolver::new(auth.users.clone()));
|
||||
// The InboxRegistry is constructed once and shared between the
|
||||
|
||||
@@ -207,7 +207,7 @@ impl MasterKey {
|
||||
let dev_ack = std::env::var("PICLOUD_DEV_INSECURE_KEY")
|
||||
.map(|v| v == "i-understand-this-is-insecure")
|
||||
.unwrap_or(false);
|
||||
if dev_mode && secret.as_deref().map(str::trim).unwrap_or("").is_empty() && !dev_ack {
|
||||
if dev_mode && secret.as_deref().map_or("", str::trim).is_empty() && !dev_ack {
|
||||
return Err(MasterKeyError::DevModeUnacknowledged);
|
||||
}
|
||||
Self::resolve(secret.as_deref(), dev_mode)
|
||||
|
||||
Reference in New Issue
Block a user