Skip to main content

ApprovalBinding

Struct ApprovalBinding 

Source
pub struct ApprovalBinding {
    pub chain_id: u64,
    pub payee_address: String,
    pub amount_minor_units: u128,
    pub token_symbol: String,
    pub token_contract: Option<String>,
    pub approval_expires_at: u64,
}
Expand description

Approval-bound settlement parameters the caller MUST supply.

EIP-3009 authorizations are independently replay-able and are not, by themselves, tied to the approval that governs the spend. This binding requires the prepared authorization to be bound to its governing approval so a captured signature cannot be redirected to a different payee, inflated to a different amount, or replayed on a different chain.

This type is the seam to the governed-approval layer: once a verified [chio_core_types::capability::governance::GovernedApprovalToken] is available at the settlement layer, the caller derives these bound values from that token’s governed intent and passes them here. Until then, the caller is the trust boundary that MUST extract the values from the verified approval before calling prepare_transfer_with_authorization. Either way the bound values are asserted against the authorization and any mismatch fails closed.

The GovernedApprovalToken itself does not carry chain/amount/payee/token as discrete fields (they are folded into its governed_intent_hash), so this layer cannot re-derive them from the token alone; it asserts the explicitly-bound values the caller resolved from the verified intent.

Fields§

§chain_id: u64

Chain id the governing approval authorized the spend on. Must equal the EIP-3009 domain chain_id.

§payee_address: String

Payee the governing approval authorized. Must equal the EIP-3009 authorization to address (case-insensitive hex / checksum).

§amount_minor_units: u128

Amount in token minor units the governing approval authorized. Must equal the EIP-3009 authorization value.

§token_symbol: String

Token/currency symbol the governing approval authorized (for example "USDC"). The chain id alone does not pin the token: a captured authorization for one token contract can otherwise be redirected to a different token on the same chain with the same payee and numeric amount. Each lane asserts its lane-specific token identity against this symbol (x402 accepted tokens, Circle token symbol). Compared case-insensitively after trimming.

§token_contract: Option<String>

Token contract address the governing approval authorized (for example the USDC contract on the target chain). It is asserted against the EIP-3009 domain verifying_contract, which is the contract the signed transfer actually targets, so a captured authorization cannot be redirected to a different token contract on the same chain. Compared as parsed Address bytes so checksum vs lowercase hex compare equal.

REQUIRED for the EIP-3009 lane: prepare_transfer_with_authorization fails closed when this is None, because a symbol alone cannot pin the on-chain token. The field stays Option only because lanes that identify their token by symbol and have no contract to compare against (the x402 accepted-token list and the Circle token symbol) still bind via token_symbol and legitimately leave this None.

§approval_expires_at: u64

Approval expiry as a Unix timestamp in seconds. The prepared authorization MUST NOT outlive the governing approval: when an EIP-3009 valid_before would let a signed transfer stay broadcastable past this instant, preparation fails closed. Binds the off-chain authorization window to the approval window so a captured signature cannot be broadcast after the approval that governs it has expired.

Implementations§

Source§

impl ApprovalBinding

Source

pub fn assert_dispatch( &self, lane: &str, dispatch: &Web3SettlementDispatchArtifact, ) -> Result<(), SettlementError>

Assert that a settlement dispatch matches the approval-bound spend.

Source

pub fn assert_token_symbol( &self, lane: &str, lane_token_symbol: &str, ) -> Result<(), SettlementError>

Assert that a lane’s token symbol matches the approval-bound token.

Trait Implementations§

Source§

impl Clone for ApprovalBinding

Source§

fn clone(&self) -> ApprovalBinding

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ApprovalBinding

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for ApprovalBinding

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for ApprovalBinding

Source§

impl PartialEq for ApprovalBinding

Source§

fn eq(&self, other: &ApprovalBinding) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for ApprovalBinding

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for ApprovalBinding

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more