commit 9b137859cb6abbf747eac65cc75c50c4dbf0908a
parent 14c3af9a7aa3974d86c405b487257b5d6ecf1770
Author: triesap <tyson@radroots.org>
Date: Mon, 3 Aug 2026 22:07:01 +0000
domain: separate local signer binding
- model local signer ownership independently from account display identity
- bind signer metadata only to the canonical public-key coordinate
- keep credential material outside the public binding aggregate
- cover binding identity and redaction invariants
Diffstat:
2 files changed, 30 insertions(+), 2 deletions(-)
diff --git a/core/crates/domain/src/account.rs b/core/crates/domain/src/account.rs
@@ -48,6 +48,23 @@ impl AccountIdentity {
}
#[derive(Clone, Copy, Debug, Eq, PartialEq)]
+pub struct LocalSignerBinding {
+ account: PublicKey,
+}
+
+impl LocalSignerBinding {
+ #[must_use]
+ pub const fn new(account: PublicKey) -> Self {
+ Self { account }
+ }
+
+ #[must_use]
+ pub const fn account(self) -> PublicKey {
+ self.account
+ }
+}
+
+#[derive(Clone, Copy, Debug, Eq, PartialEq)]
pub enum SignerKind {
LocalSecret,
WatchOnly,
@@ -220,7 +237,7 @@ mod tests {
use super::{
AccountCreatedAt, AccountIdentity, AccountLabel, AccountSummary, KeyAvailability,
- SignerKind,
+ LocalSignerBinding, SignerKind,
};
const NPUB: &str = "npub10elfcs4fr0l0r8af98jlmgdh9c8tcxjvz9qkw038js35mp4dma8qzvjptg";
@@ -288,4 +305,14 @@ mod tests {
AccountIdentity::verify(PublicKey::from_bytes([8_u8; 32]), NPUB.to_owned()).is_err()
);
}
+
+ #[test]
+ fn local_signer_binding_carries_only_canonical_account_identity() {
+ let public_key = PublicKey::from_bytes([9_u8; 32]);
+ let identity = AccountIdentity::derive(public_key).expect("identity");
+ let binding = LocalSignerBinding::new(public_key);
+
+ assert_eq!(binding.account(), identity.public_key());
+ assert!(!format!("{binding:?}").contains("nsec1"));
+ }
}
diff --git a/core/crates/domain/src/lib.rs b/core/crates/domain/src/lib.rs
@@ -8,7 +8,8 @@ pub mod relay;
pub mod time;
pub use account::{
- AccountCreatedAt, AccountIdentity, AccountLabel, AccountSummary, KeyAvailability, SignerKind,
+ AccountCreatedAt, AccountIdentity, AccountLabel, AccountSummary, KeyAvailability,
+ LocalSignerBinding, SignerKind,
};
pub use error::{SafeError, SafeErrorCode, SafeMessage};
pub use key::{Npub, Nsec, PublicKey, SecretKeyInput, SecretKeyInputKind};