diff --git a/crates/buzz-auth/src/context/authority.rs b/crates/buzz-auth/src/context/authority.rs index e3941ea38..390273ecb 100644 --- a/crates/buzz-auth/src/context/authority.rs +++ b/crates/buzz-auth/src/context/authority.rs @@ -14,7 +14,7 @@ use super::{ pub type AuthorityAdapterFuture<'a, T> = Pin + Send + 'a>>; /// Failure while invoking or validating a federated authority adapter. -#[derive(Debug, PartialEq, Eq)] +#[derive(PartialEq, Eq)] pub enum AuthorityAdapterError { /// The storage adapter failed before producing authoritative state. Adapter(E), @@ -24,6 +24,21 @@ pub enum AuthorityAdapterError { PolicyChanged, } +impl fmt::Debug for AuthorityAdapterError { + fn fmt(&self, formatter: &mut fmt::Formatter<'_>) -> fmt::Result { + let variant = match self { + Self::Adapter(_) => "Adapter", + Self::Contract(_) => "Contract", + Self::PolicyChanged => "PolicyChanged", + }; + formatter + .debug_struct("AuthorityAdapterError") + .field("variant", &variant) + .field("detail", &"[redacted]") + .finish() + } +} + impl AuthorityAdapterError { /// Wrap a storage-adapter failure. pub const fn adapter(error: E) -> Self { diff --git a/crates/buzz-auth/src/context/mod.rs b/crates/buzz-auth/src/context/mod.rs index 397e037d7..95883be42 100644 --- a/crates/buzz-auth/src/context/mod.rs +++ b/crates/buzz-auth/src/context/mod.rs @@ -193,6 +193,16 @@ impl AuthContextInput { self.tenant.community() } + #[allow(dead_code)] + pub(crate) const fn nostr_proof_authorization_domain(&self) -> CommunityId { + self.nostr_proof.authorization_domain() + } + + #[allow(dead_code)] + pub(crate) const fn community_access_authorization_domain(&self) -> CommunityId { + self.community_access.authorization_domain() + } + #[allow(dead_code)] pub(crate) const fn correlation_id(&self) -> Uuid { self.correlation_id diff --git a/crates/buzz-auth/src/context/tests.rs b/crates/buzz-auth/src/context/tests.rs index 2b5419736..528e04e5f 100644 --- a/crates/buzz-auth/src/context/tests.rs +++ b/crates/buzz-auth/src/context/tests.rs @@ -766,6 +766,18 @@ fn evidence_value_debug_output_redacts_numeric_values() { ); } +#[test] +fn authority_adapter_error_debug_output_redacts_storage_detail() { + let error = AuthorityAdapterError::adapter("private-storage-detail"); + + let rendered = format!("{error:?}"); + assert_eq!( + rendered, + "AuthorityAdapterError { variant: \"Adapter\", detail: \"[redacted]\" }" + ); + assert!(!rendered.contains("private-storage-detail")); +} + #[test] fn zero_owner_admission_expiry_is_rejected() { assert_eq!(