Skip to content

Commit 73873af

Browse files
committed
feat(stack-encrypt): plan grammar gains two starts, three context sources, encrypt_into and pickers
The derive is to emit the plan, so the plan must say everything the narrowed derive says. This adds, Rust-only: - Two starts: Plan::fields() and Plan::value::<S>(), each with an optional .context(c); Plan::context(c).fields()/.with(..) keep working. The FieldPlan iterator on a built plan is renamed field_plans(), since Plan::fields() is now the start. - Exactly one context source: the plan, the call (cipher.encrypt(&v).context(c).using(&plan), and .context(c) on query and open), or a context field of the value (.context_field(field)), carried as a passthrough and checked on open through ExpectedContext. Two is TwoContextSources at build or at the call; none is NoContext when the plan runs, before any key request. - encrypt_into: the field form lowers to the target's own EncryptFrom under <context>/<identity>, exactly as the derive composes a record-typed field; the one-value form takes a target or a tuple of them. A field is a target or data verbs, never both (TargetWithVerbs). A typed field answers the queries its target declares. - Pickers: every verb takes a name (Field<F> lookup) or a name with an accessor; a plan of pickers needs no Fields impl and skips the run-time field-name check. Also the #1071 review: a pinned identity rescues a field name that is not a plain segment (tuple fields "0", renamed columns); a Vec written through a one-value plan opens through it in one request; a query whose match options differ says so (IndexOptions); a failed FieldValues::take keeps the record's order; the over-strong "before any request" claims are scoped; the parameter and doc noun row is now record.
1 parent 2aa83b8 commit 73873af

16 files changed

Lines changed: 3247 additions & 453 deletions

‎packages/stack-encrypt/src/cipher.rs‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -219,8 +219,10 @@ pub enum Error {
219219
#[error("a field declared decryptable was not opened by its DecryptField implementation")]
220220
NotOpened,
221221
/// A [plan](crate::plan) was refused: it did not validate when it was
222-
/// built, or the value, row or query it was run with does not match it.
223-
/// Always raised before any key is requested.
222+
/// built, or the value, record or query it was run with does not match
223+
/// it. A refusal at build or when a plan runs is raised before any key
224+
/// is requested; [`FieldValues::take`](crate::plan::FieldValues::take)
225+
/// also returns one for a record already in hand.
224226
#[error(transparent)]
225227
Plan(#[from] crate::plan::PlanError),
226228
}

0 commit comments

Comments
 (0)