Public declaration syntax from forge-rs/crates/forge-core/src/replay.rs Original source SHA-256: 4337670e29371fa1a58cfed5f3f40d372d7db9bbb3719b1d4a679dce518afc68 Function bodies and constant values are omitted. This is not the complete implementation. Source line 59 pub const DEFAULT_CLOCK_SKEW: Duration; Source line 62 pub const DEFAULT_NONCE_CACHE_SIZE: usize; Source line 69 #[derive(Debug, Clone)] pub struct ReplayConfig { /// Maximum allowed clock skew between sender and receiver, applied in /// both directions. A timestamp that is more than this far in the past /// or future (relative to the receiver's wall clock) is rejected. pub max_clock_skew: Duration, /// Maximum number of nonces to remember. When full, the least-recently-used /// nonce is evicted to make room for a new entry. Must be non-zero. pub nonce_cache_size: usize, /// If `true`, messages lacking a nonce/timestamp (legacy wire format) /// are accepted with a `WARN` log line. If `false` (default), legacy /// messages are rejected with [`ReplayError::LegacyMessageFormat`]. /// /// This flag is also controllable via the `FORGE_ACCEPT_LEGACY_MESSAGES` /// environment variable; see [`legacy_accept_from_env`]. pub accept_legacy: bool } Source line 100 pub fn with_max_clock_skew(mut self, skew: Duration) -> Self; Source line 106 pub fn with_nonce_cache_size(mut self, size: usize) -> Self; Source line 112 pub fn with_accept_legacy(mut self, accept: bool) -> Self; Source line 125 pub fn legacy_accept_from_env() -> bool; Source line 133 #[derive(Debug, Error, PartialEq, Eq)] pub enum ReplayError { /// The envelope timestamp is outside the accepted clock-skew window. #[error( "replay protection rejected message: timestamp {timestamp_ms}ms is outside the \ ±{max_skew_ms}ms clock-skew window (now={now_ms}ms)" )] TimestampExpired { /// The timestamp carried by the message, in milliseconds since epoch. timestamp_ms: i64, /// The receiver's current wall-clock time, in milliseconds since epoch. now_ms: i64, /// The configured maximum skew, in milliseconds. max_skew_ms: i64, }, /// The envelope's nonce was already seen within the validity window. #[error( "replay protection rejected message: nonce {nonce_hex} has already been accepted \ within the clock-skew window" )] NonceReplay { /// Hex-encoded nonce, included for operator diagnostics. nonce_hex: String, }, /// The envelope is missing nonce and/or timestamp and legacy acceptance /// is disabled. #[error( "replay protection rejected message: legacy wire format (no nonce/timestamp); \ set FORGE_ACCEPT_LEGACY_MESSAGES=true to opt into legacy acceptance" )] LegacyMessageFormat, /// The validator's internal cache lock was poisoned. This indicates that /// another thread panicked while holding the lock; callers should treat /// this as an unrecoverable condition for that validator instance. #[error("replay validator internal lock poisoned (a prior thread panicked)")] LockPoisoned, } Source line 185 pub struct ReplayValidator { } Source line 196 pub fn new(config: ReplayConfig) -> Self; Source line 208 pub fn config(&self) -> &ReplayConfig; Source line 227 pub fn validate(&self, timestamp_ms: i64, nonce: &[u8; 16]) -> Result<(), ReplayError>; Source line 263 pub fn accept_legacy(&self, context: &str) -> Result<(), ReplayError>; Source line 278 #[doc(hidden)] pub fn nonce_cache_len(&self) -> usize;