export interface TrustStore { grant(project: string, fingerprint: string): Promise; list(project: string): Promise; has(project: string, fingerprint: string): Promise; revoke(project: string, fingerprint: string): Promise; } export function validateTrust(project: string, fingerprint: string): void { if (project.length > 63 || !/^[a-z0-9](?:[-a-z0-9]*[a-z0-9])?$/.test(project)) throw new Error("project must be a Kubernetes name"); if (!/^[a-f0-9]{64}$/.test(fingerprint)) throw new Error("fingerprint is invalid"); } export class MemoryTrustStore implements TrustStore { private readonly fingerprints = new Map>(); async grant(project: string, fingerprint: string): Promise { validateTrust(project, fingerprint); const values = this.fingerprints.get(project) ?? new Set(); values.add(fingerprint); this.fingerprints.set(project, values); } async list(project: string): Promise { return [...(this.fingerprints.get(project) ?? [])]; } async has(project: string, fingerprint: string): Promise { return (await this.list(project)).includes(fingerprint); } async revoke(project: string, fingerprint: string): Promise { const values = this.fingerprints.get(project); if (!values?.delete(fingerprint)) return false; if (!values.size) this.fingerprints.delete(project); return true; } }