Files
npub1jmc9dt2lyvzu3h0kxlwxt5zg4fxp9476awyxw6gwxn72g6cw7exqs64whmandTyler Longwell 41602ab4d2 docs(auth): annotate AuthError variants with WIRE class — doc-at-source for P1+P2
Pairs with c31307d40 (the audit branch's wire mapper + property tests) and
Eva's [13] ruling: one wire categorization lives in buzz-relay::auth_wire,
and AuthError variants carry doc annotations pointing at it. Doc-only diff;
no behavior change.

The enum-level docstring spells out the wire-mapping contract — the four
AuthErrorWireCategory targets, what each invariant guards (byte-identity
on verification-class collapses an existence oracle; Internal must never
stringify on the wire), and a pointer at the compile-time exhaustiveness
fence in auth_error_wire's match that catches variant-add-then-forget.

Per-variant: each variant carries a "WIRE class:" line naming its
AuthErrorWireCategory target. Nip98Replay calls out the byte-identity
requirement against Nip98Invalid explicitly (community-scoped seen-set
presence oracle). Internal calls out the no-stringify rule explicitly
(community-prefixed Redis keys can ride the inner String).

No intra-doc link to AuthErrorWireCategory: buzz-auth cannot depend on
buzz-relay (would cycle), so the type is referenced by name in prose.

Validation:
- cargo fmt -p buzz-auth --check ✅
- cargo test -p buzz-auth ✅ (40 passed)
- cargo clippy -p buzz-auth --no-deps --lib --tests ✅ (one pre-existing
  warning at nip98_replay.rs:162, not from this diff)
- cargo doc -p buzz-auth --no-deps ✅ (zero new doc warnings; two
  pre-existing broken links in rate_limit.rs/nip98_replay.rs unchanged)
- cargo test -p buzz-relay ✅ in isolation; one known-flaky Redis
  presence test (pubsub_fanout::global_presence_*) intermittently fails
  in full-suite runs and passes when run alone — same flake Eva flagged
  on ed33878b7's push. Doc-only diff cannot affect Redis fanout timing.

Co-authored-by: Tyler Longwell <tlongwell@block.xyz>
Signed-off-by: Tyler Longwell <tlongwell@block.xyz>
2026-06-26 13:41:00 -04:00
..