style: fmt + clippy cleanup after Phase C
cargo fmt regroups; three clippy fixes: - F-S-006: hoist MAX_API_KEY_CANDIDATES to module scope to satisfy clippy::items_after_statements. - F-S-009: use map_or instead of map().unwrap_or() per clippy::map_unwrap_or. - F-P-012: replace `|c| c.encode()` closure with the method itself per clippy::redundant_closure_for_method_calls. No behavior change. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -53,6 +53,11 @@ pub struct PrincipalCache {
|
|||||||
/// adjacent requests on a hot key.
|
/// adjacent requests on a hot key.
|
||||||
const PRINCIPAL_CACHE_TTL: Duration = Duration::from_secs(60);
|
const PRINCIPAL_CACHE_TTL: Duration = Duration::from_secs(60);
|
||||||
|
|
||||||
|
/// F-S-006: maximum candidate API keys we'll Argon2-verify per
|
||||||
|
/// request. Hoisted to module scope so clippy::items_after_statements
|
||||||
|
/// is happy.
|
||||||
|
const MAX_API_KEY_CANDIDATES: usize = 16;
|
||||||
|
|
||||||
impl PrincipalCache {
|
impl PrincipalCache {
|
||||||
#[must_use]
|
#[must_use]
|
||||||
pub fn new() -> Self {
|
pub fn new() -> Self {
|
||||||
@@ -277,7 +282,6 @@ async fn verify_api_key(state: &AuthState, rest: &str) -> Result<Option<Principa
|
|||||||
// many keys against one indexed prefix could amplify each public
|
// many keys against one indexed prefix could amplify each public
|
||||||
// bearer-tagged request into M×Argon2 verifies. Cap at MAX and
|
// bearer-tagged request into M×Argon2 verifies. Cap at MAX and
|
||||||
// log the truncation so operators can spot it.
|
// log the truncation so operators can spot it.
|
||||||
const MAX_API_KEY_CANDIDATES: usize = 16;
|
|
||||||
if candidates.len() > MAX_API_KEY_CANDIDATES {
|
if candidates.len() > MAX_API_KEY_CANDIDATES {
|
||||||
tracing::warn!(
|
tracing::warn!(
|
||||||
prefix,
|
prefix,
|
||||||
|
|||||||
@@ -311,7 +311,12 @@ impl Dispatcher {
|
|||||||
};
|
};
|
||||||
let outcome = self
|
let outcome = self
|
||||||
.executor
|
.executor
|
||||||
.execute_with_identity(identity, &script.source, exec_req, async_exec_timeout_from_env())
|
.execute_with_identity(
|
||||||
|
identity,
|
||||||
|
&script.source,
|
||||||
|
exec_req,
|
||||||
|
async_exec_timeout_from_env(),
|
||||||
|
)
|
||||||
.await;
|
.await;
|
||||||
drop(permit);
|
drop(permit);
|
||||||
|
|
||||||
|
|||||||
@@ -587,7 +587,10 @@ impl UsersService for UsersServiceImpl {
|
|||||||
.collect();
|
.collect();
|
||||||
Ok(UsersListPage {
|
Ok(UsersListPage {
|
||||||
items,
|
items,
|
||||||
next_cursor: page.next_cursor.as_ref().map(|c| c.encode()),
|
next_cursor: page
|
||||||
|
.next_cursor
|
||||||
|
.as_ref()
|
||||||
|
.map(crate::app_user_repo::ListCursor::encode),
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -362,8 +362,7 @@ pub async fn build_app(
|
|||||||
// Dispatcher — single tokio task that polls the outbox and routes
|
// Dispatcher — single tokio task that polls the outbox and routes
|
||||||
// due rows to the executor. Shares the `ExecutionGate` with sync
|
// due rows to the executor. Shares the `ExecutionGate` with sync
|
||||||
// HTTP per design notes §2 (one cap for everything).
|
// HTTP per design notes §2 (one cap for everything).
|
||||||
let dispatcher_script_repo: Arc<dyn ScriptRepository> =
|
let dispatcher_script_repo: Arc<dyn ScriptRepository> = script_repo.clone();
|
||||||
script_repo.clone();
|
|
||||||
let principals: Arc<dyn PrincipalResolver> =
|
let principals: Arc<dyn PrincipalResolver> =
|
||||||
Arc::new(AdminPrincipalResolver::new(auth.users.clone()));
|
Arc::new(AdminPrincipalResolver::new(auth.users.clone()));
|
||||||
// The InboxRegistry is constructed once and shared between the
|
// The InboxRegistry is constructed once and shared between the
|
||||||
|
|||||||
@@ -207,7 +207,7 @@ impl MasterKey {
|
|||||||
let dev_ack = std::env::var("PICLOUD_DEV_INSECURE_KEY")
|
let dev_ack = std::env::var("PICLOUD_DEV_INSECURE_KEY")
|
||||||
.map(|v| v == "i-understand-this-is-insecure")
|
.map(|v| v == "i-understand-this-is-insecure")
|
||||||
.unwrap_or(false);
|
.unwrap_or(false);
|
||||||
if dev_mode && secret.as_deref().map(str::trim).unwrap_or("").is_empty() && !dev_ack {
|
if dev_mode && secret.as_deref().map_or("", str::trim).is_empty() && !dev_ack {
|
||||||
return Err(MasterKeyError::DevModeUnacknowledged);
|
return Err(MasterKeyError::DevModeUnacknowledged);
|
||||||
}
|
}
|
||||||
Self::resolve(secret.as_deref(), dev_mode)
|
Self::resolve(secret.as_deref(), dev_mode)
|
||||||
|
|||||||
Reference in New Issue
Block a user