Files
mytheclipse/crates/mytheclipse-crypto
asepharyana 1dfc6d6865 fix(ci): restore full CI green — test-matrix, clippy, rustfmt, and rustdoc gates
Root cause of the failing CI run was that examples/tests referencing
feature-gated items were auto-detected (no required-features), so
`--all-targets` compiled them under feature combinations where those
modules didn't exist. Fixes:

- mytheclipse Cargo.toml: declare the `high_level` example and
  `race_stress` integration test with required-features = ["full"];
  `cargo build --all-targets` now skips them when full is off. This
  clears the whole test-matrix (workspace default, all-features, and
  every single-feature config) which all failed on E0432/E0433.
- lib.rs: auto_metrics_service depends on service_builder, so regate it
  behind all(observability, resiliency) instead of observability alone
  (observability-only build compiled the module without resiliency).
- mytheclipse-tracing: gate `pub mod fmt` behind any
  tracing-subscriber-providing feature so --no-default-features compiles.
- mytheclipse-queue: gate `pub mod worker` behind in-memory (worker.rs
  requires tokio, only provided by in-memory).
- clippy -D warnings fixes: deprecated base64 0.22 free fns -> Engine
  (paseto), unused key field, needless mut (service_builder), unused
  import/dead var/missing is_empty (bg_join), dead is_expired (dlock),
  while-let-iterator->for (parallel_map), type_complexity (shutdown_guard),
  MutexGuard held across await (middleware, now clones Arc'd layers),
  if-let-Err->is_err (queue), unused CliBuilder fields now wired into clap.
- rustdoc -D warnings: resolve retry/MetricsBridge/CircuitBreaker/KeyRing
  intra-doc links and fix the unparseable lifecycle.rs code fence.
- cargo fmt --all to satisfy the Rustfmt gate.
2026-08-30 00:33:21 +07:00
..
2026-08-29 17:00:18 +00:00

mytheclipse-crypto

Safe, one-line security helpers that are easy to get wrong when hand-rolled:

  • Argon2id password hashing & verification (PHC-encoded, RFC 9106-style).
  • AES-256-GCM authenticated encryption with a fresh random nonce per op.
  • JWT (HS256) token generation & validation.
  • Key rotation via KeyRing — reads keep working with the previous key during a rotation window.

Features

  • password (default) — Argon2id hashing.
  • encryption (default) — AES-256-GCM.
  • tokens (default) — JSON Web Tokens.

Zero features enabled by default? No — all three are on, but each is cheap and independent.

Usage

use mytheclipse_crypto::{PasswordHasher, Encryptor, TokenSigner};

let hasher = PasswordHasher::new();
let hash = hasher.hash("letmein").unwrap();
assert!(hasher.verify(&hash, "letmein"));

let enc = Encryptor::new(&[0u8; 32]);
let (nonce, ct) = enc.encrypt(b"secret");
assert_eq!(enc.decrypt(&nonce, &ct).unwrap(), b"secret");

let signer = TokenSigner::new("my-secret");
let token = signer.sign(&serde_json::json!({"sub":"u1"}), std::time::Duration::from_secs(3600)).unwrap();
assert_eq!(signer.verify(&token).unwrap()["sub"], "u1");