KeyEntryStatus extension type
Whether an advertised key entry is still offered for new operations.
Use-neutral, because an entry's use already names the operation a key
serves. Retirement withdraws the future, never the past: a retired signing
key still verifies the envelopes it signed, and a retired encapsulation key
still opens the records already sealed to it. What it forbids is a signer
signing with it, or a sender sealing to it, from now on.
Retaining rather than withdrawing is the whole point. Envelopes and chain links are stored durably and verified long after they are written, so dropping a key's entry outright would retroactively unverify everything ever signed with it, and unopenably strand everything ever sealed to it.
It lives here, in at_auth, because at_auth is the lower package. All
three records that advertise keys — the _apsk signing advertisement
composed here, at_client's enrollment key package, and its nskey
advertisement — carry the same field with the same values, and one
vocabulary is better served by one type than by a type per package with a
mapping between them. at_client depends on at_auth and not the reverse, so
this is the only direction the type can be shared in; publicKeyKid sits
here for the same reason.
An open String, and the two questions below are how a caller asks
about it. It was an enum with the values active and retired until
2026-08-22, which made the vocabulary closed in a place it cannot be: this
status travels on records the atServer stores verbatim, and a newer client
may say something about a key that this build has never heard of.
The old enum did not refuse an unknown value — it flattened one, reading anything it did not recognise as retired. Two things went wrong with that:
retiredis the wrong reading for an unknown value, because it is permissive in the direction that matters. A retired key still verifies what it signed; a revoked one must not. Reading an unrecognised token asretiredtherefore left an older build happily verifying signatures made with a key its owner has disowned.- It was lossy where a record is rebuilt from stored state. A key package advertisement is composed afresh on every reconcile from the keyfile, whose own status vocabulary is open for the same reasons this one is; flattening the keyfile's token on the way out republished the owner's record with their statement about a key weakened.
So a token this build does not know is now carried through verbatim and answers no to both questions below: it is not offered for new operations, and it does not vouch for old ones. Unknown means more restrictive than either value here, never less.
Do not change any existing value below. They are published on records that other clients and other at_client implementations already read.
- on
- Implemented types
- Available extensions
Constructors
- KeyEntryStatus.of(String value)
-
A status token read from an advertising record, whatever it says.
const
Properties
-
codeUnits
→ List<
int> -
An unmodifiable list of the UTF-16 code units of this string.
no setterinherited
- hashCode → int
-
A hash code derived from the code units of the string.
no setterinherited
- isEmpty → bool
-
Whether this string is empty.
no setterinherited
- isNotEmpty → bool
-
Whether this string is not empty.
no setterinherited
- isNotNull → bool
-
Available on String?, provided by the NullCheck extension
no setter - isNotNullOrEmpty → bool
-
Available on String?, provided by the NullOrEmptyCheck extension
no setter - isNull → bool
-
Available on String?, provided by the NullCheck extension
no setter - isNullOrEmpty → bool
-
Available on String?, provided by the NullOrEmptyCheck extension
no setter - length → int
-
The length of the string.
no setterinherited
- runes → Runes
-
An Iterable of Unicode code-points of this string.
no setterinherited
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- toJS → JSString
-
Available on String, provided by the StringToJSString extension
Converts this String to a JSString.no setter - value → String
-
final
Methods
-
allMatches(
String string, [int start = 0]) → Iterable< Match> -
Matches this pattern against the string repeatedly.
inherited
-
codeUnitAt(
int index) → int -
Returns the 16-bit UTF-16 code unit at the given
index.inherited -
compareTo(
String other) → int -
Compares this string to
other.inherited -
contains(
Pattern other, [int startIndex = 0]) → bool -
Whether this string contains a match of
other.inherited -
endsWith(
String other) → bool -
Whether this string ends with
other.inherited -
indexOf(
Pattern pattern, [int start = 0]) → int -
Returns the position of the first match of
patternin this string, starting atstart, inclusive:inherited -
lastIndexOf(
Pattern pattern, [int? start]) → int -
The starting position of the last match
patternin this string.inherited -
matchAsPrefix(
String string, [int start = 0]) → Match? -
Matches this pattern against the start of
string.inherited -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
padLeft(
int width, [String padding = ' ']) → String -
Pads this string on the left if it is shorter than
width.inherited -
padRight(
int width, [String padding = ' ']) → String -
Pads this string on the right if it is shorter than
width.inherited -
replaceAll(
Pattern from, String replace) → String -
Replaces all substrings that match
fromwithreplace.inherited -
replaceAllMapped(
Pattern from, String replace(Match match)) → String -
Replace all substrings that match
fromby a computed string.inherited -
replaceFirst(
Pattern from, String to, [int startIndex = 0]) → String -
Creates a new string with the first occurrence of
fromreplaced byto.inherited -
replaceFirstMapped(
Pattern from, String replace(Match match), [int startIndex = 0]) → String -
Replace the first occurrence of
fromin this string.inherited -
replaceRange(
int start, int? end, String replacement) → String -
Replaces the substring from
starttoendwithreplacement.inherited -
split(
Pattern pattern) → List< String> -
Splits the string at matches of
patternand returns a list of substrings.inherited -
splitMapJoin(
Pattern pattern, {String onMatch(Match)?, String onNonMatch(String)?}) → String -
Splits the string, converts its parts, and combines them into a new
string.
inherited
-
startsWith(
Pattern pattern, [int index = 0]) → bool -
Whether this string starts with a match of
pattern.inherited -
substring(
int start, [int? end]) → String -
The substring of this string from
start, inclusive, toend, exclusive.inherited -
toAtsign(
) → Atsign -
Available on String, provided by the AtsignString extension
Format and validate string to a fully qualified atSign throws InvalidAtSignException on failed validation -
toLowerCase(
) → String -
Converts all characters in this string to lower case.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
-
toUpperCase(
) → String -
Converts all characters in this string to upper case.
inherited
-
trim(
) → String -
The string without any leading and trailing whitespace.
inherited
-
trimLeft(
) → String -
The string without any leading whitespace.
inherited
-
trimRight(
) → String -
The string without any trailing whitespace.
inherited
Operators
-
operator *(
int times) → String -
Creates a new string by concatenating this string with itself a number
of times.
inherited
-
operator +(
String other) → String -
Creates a new string by concatenating this string with
other.inherited -
operator ==(
Object other) → bool -
Whether
otheris aStringwith the same sequence of code units.inherited -
operator [](
int index) → String -
The character (as a single-code-unit String) at the given
index.inherited
Static Methods
-
fromWire(
Object? value) → KeyEntryStatus -
Reads a wire
status. Absent is active; anything else is the token itself, verbatim. -
offersNewOperations(
KeyEntryStatus status) → bool -
Whether
statusmay be chosen for something new — a signer picking a key to sign with, a sender picking a key to seal to. -
vouchesForPastOperations(
KeyEntryStatus status) → bool -
Whether
statusstill vouches for what the key already did — verifying a stored envelope or chain link that names it.
Constants
- active → const KeyEntryStatus
- Offered for new operations. The default when a record omits the field, which is how every record that has never rotated spells it.
-
known
→ const Set<
KeyEntryStatus> - The tokens this version knows about. For warn-level tooling only — never reject a value for not being in this set, and never decide with it (see vouchesForPastOperations).
- retired → const KeyEntryStatus
- Withdrawn from new operations, kept because it is what verifies or opens what it already produced.