mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
Pairs with c31307d40 (the audit branch's wire mapper + property tests) and Eva's [13] ruling: one wire categorization lives in buzz-relay::auth_wire, and AuthError variants carry doc annotations pointing at it. Doc-only diff; no behavior change. The enum-level docstring spells out the wire-mapping contract — the four AuthErrorWireCategory targets, what each invariant guards (byte-identity on verification-class collapses an existence oracle; Internal must never stringify on the wire), and a pointer at the compile-time exhaustiveness fence in auth_error_wire's match that catches variant-add-then-forget. Per-variant: each variant carries a "WIRE class:" line naming its AuthErrorWireCategory target. Nip98Replay calls out the byte-identity requirement against Nip98Invalid explicitly (community-scoped seen-set presence oracle). Internal calls out the no-stringify rule explicitly (community-prefixed Redis keys can ride the inner String). No intra-doc link to AuthErrorWireCategory: buzz-auth cannot depend on buzz-relay (would cycle), so the type is referenced by name in prose. Validation: - cargo fmt -p buzz-auth --check ✅ - cargo test -p buzz-auth ✅ (40 passed) - cargo clippy -p buzz-auth --no-deps --lib --tests ✅ (one pre-existing warning at nip98_replay.rs:162, not from this diff) - cargo doc -p buzz-auth --no-deps ✅ (zero new doc warnings; two pre-existing broken links in rate_limit.rs/nip98_replay.rs unchanged) - cargo test -p buzz-relay ✅ in isolation; one known-flaky Redis presence test (pubsub_fanout::global_presence_*) intermittently fails in full-suite runs and passes when run alone — same flake Eva flagged on ed33878b7's push. Doc-only diff cannot affect Redis fanout timing. Co-authored-by: Tyler Longwell <tlongwell@block.xyz> Signed-off-by: Tyler Longwell <tlongwell@block.xyz>