style: fmt + clippy cleanup after Phase C

cargo fmt regroups; three clippy fixes:
- F-S-006: hoist MAX_API_KEY_CANDIDATES to module scope to satisfy
  clippy::items_after_statements.
- F-S-009: use map_or instead of map().unwrap_or() per
  clippy::map_unwrap_or.
- F-P-012: replace `|c| c.encode()` closure with the method itself
  per clippy::redundant_closure_for_method_calls.

No behavior change.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-06-07 21:19:00 +02:00
parent a8094067eb
commit adc719975f
5 changed files with 17 additions and 6 deletions

View File

@@ -53,6 +53,11 @@ pub struct PrincipalCache {
/// adjacent requests on a hot key.
const PRINCIPAL_CACHE_TTL: Duration = Duration::from_secs(60);
/// F-S-006: maximum candidate API keys we'll Argon2-verify per
/// request. Hoisted to module scope so clippy::items_after_statements
/// is happy.
const MAX_API_KEY_CANDIDATES: usize = 16;
impl PrincipalCache {
#[must_use]
pub fn new() -> Self {
@@ -277,7 +282,6 @@ async fn verify_api_key(state: &AuthState, rest: &str) -> Result<Option<Principa
// many keys against one indexed prefix could amplify each public
// bearer-tagged request into M×Argon2 verifies. Cap at MAX and
// log the truncation so operators can spot it.
const MAX_API_KEY_CANDIDATES: usize = 16;
if candidates.len() > MAX_API_KEY_CANDIDATES {
tracing::warn!(
prefix,

View File

@@ -311,7 +311,12 @@ impl Dispatcher {
};
let outcome = self
.executor
.execute_with_identity(identity, &script.source, exec_req, async_exec_timeout_from_env())
.execute_with_identity(
identity,
&script.source,
exec_req,
async_exec_timeout_from_env(),
)
.await;
drop(permit);

View File

@@ -587,7 +587,10 @@ impl UsersService for UsersServiceImpl {
.collect();
Ok(UsersListPage {
items,
next_cursor: page.next_cursor.as_ref().map(|c| c.encode()),
next_cursor: page
.next_cursor
.as_ref()
.map(crate::app_user_repo::ListCursor::encode),
})
}

View File

@@ -362,8 +362,7 @@ pub async fn build_app(
// Dispatcher — single tokio task that polls the outbox and routes
// due rows to the executor. Shares the `ExecutionGate` with sync
// HTTP per design notes §2 (one cap for everything).
let dispatcher_script_repo: Arc<dyn ScriptRepository> =
script_repo.clone();
let dispatcher_script_repo: Arc<dyn ScriptRepository> = script_repo.clone();
let principals: Arc<dyn PrincipalResolver> =
Arc::new(AdminPrincipalResolver::new(auth.users.clone()));
// The InboxRegistry is constructed once and shared between the

View File

@@ -207,7 +207,7 @@ impl MasterKey {
let dev_ack = std::env::var("PICLOUD_DEV_INSECURE_KEY")
.map(|v| v == "i-understand-this-is-insecure")
.unwrap_or(false);
if dev_mode && secret.as_deref().map(str::trim).unwrap_or("").is_empty() && !dev_ack {
if dev_mode && secret.as_deref().map_or("", str::trim).is_empty() && !dev_ack {
return Err(MasterKeyError::DevModeUnacknowledged);
}
Self::resolve(secret.as_deref(), dev_mode)