nupp.mac.spi

Implementation interfaces for keyed authentication algorithm catalogs.

The facade chooses the unique highest priority during initialization. Its entries override matching built-ins and may add names; empty discovery uses the built-in catalog. Descriptors are retained once, so context operations perform no SPI resolution. Importing this declaration creates no keyed or storage state.

Algorithm names match their map keys. digestSize is a positive fixed byte count; hmac-sha256 always produces 32 bytes. create receives the retained descriptor and a raw-byte key and returns independently owned State using the shared digest protocol. Updates must not retain input views. finish writes exactly digestSize bytes without consuming state; the facade closes state on success and failure. Cleanup consumes ownership without suspension. Providers define private records satisfying the canonical State interface rather than substituting its identity.

Module contents

Types

TypeKindDescription
AlgorithminterfaceFixed-output authentication algorithm and a factory for keyed state.
ProviderinterfaceA selectable catalog of keyed algorithm descriptors.

Types#

Algorithminterface#

interface Algorithm ...

Fixed-output authentication algorithm and a factory for keyed state.

Members

NameKindDescription
namefieldCanonical algorithm name matching the catalog key.
digestSizefieldFixed output size in bytes.
createmethodCreates independent owned state from the raw-byte secret key.

namefield#

name: string
@readonly

Canonical algorithm name matching the catalog key.

digestSizefield#

digestSize: integer
@readonly

Fixed output size in bytes.

createmethod#

create: function(self: Algorithm, key: string): State

Creates independent owned state from the raw-byte secret key.

Arguments
NameTypeDescription
selfAlgorithm
keystring
Returns
TypeDescription
State

Providerinterface#

interface Provider ...

A selectable catalog of keyed algorithm descriptors.

Members

NameKindDescription
priorityfield
algorithmsfieldAlgorithms keyed by canonical name; additional descriptor fields are allowed.

priorityfield#

priority: integer?
@readonly

algorithmsfield#

algorithms: {[string]: Algorithm}
@readonly

Algorithms keyed by canonical name; additional descriptor fields are allowed.