1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
//! [`Disclosure`] — how restricted a field is, and the key a disclosure set gets.
use ;
/// How restricted a field is — the counterpart to [`Audience`](crate::disclosure::Audience).
///
/// Named for the Annex XIII point each class corresponds to, and kept
/// product group-agnostic so non-battery product groups reuse the same vocabulary.
/// Disclosure class of every top-level passport field that is not public.
///
/// **The single source for this fact.** `Passport::redact` and the crypto
/// layer's `ProductGroupAccessPolicy::passport_default()` both read it, because they
/// previously each carried their own copy and drifted: the policy classified
/// `lintResult` as restricted while `redact` never removed it, so a public view
/// built through the domain path disclosed it.
///
/// Fields absent from this list are [`Disclosure::Public`].
pub const PASSPORT_FIELD_DISCLOSURE: & = &;
/// The envelope fields a product group's schema may open to the public, and
/// no others.
///
/// # Why a product group can open these at all
///
/// Access to passport data is decided per product group. Regulation (EU)
/// 2024/1781 Art. 10(1)(g) regulates it *"with the specific access rights at
/// product group level as specified in the applicable delegated act"*, and a
/// group's own legislation can put an identifier on the public side. Batteries
/// do: Art. 38(6) of Regulation (EU) 2023/1542 has a battery bear *"a model
/// identification and batch or serial number, or product number or another
/// element allowing their identification"*, Annex VI Part A point 2 puts that
/// on the label, and Annex XIII point 1(a) makes Annex VI Part A publicly
/// accessible in the passport. A universal `Restricted` on the envelope would
/// withhold what that act requires to be shown.
///
/// # Why only these two
///
/// An opening is declared by a schema, and a schema is the product group's to
/// write — so the list is the whole of what one can reach. It holds the two
/// identity fields a product group's law can require to be public, and nothing
/// that carries a proof or another audience's data. A schema naming anything
/// else is refused when its policy is built, rather than opening it.
///
/// The opening applies to the envelope key itself, at the top of the document,
/// never to a field of the same name nested anywhere else.
pub const GROUP_OPENABLE_ENVELOPE_FIELDS: & = &;
/// Every disclosure class, in the fixed order a [`disclosure_key`] uses.
///
/// Ordering is by Annex XIII point number, and it is part of the key format:
/// two nodes must produce byte-identical keys for the same set.
pub const DISCLOSURE_ORDER: & = &;
/// Name a set of disclosure classes: the classes' tokens in Annex XIII order,
/// joined with `+` — e.g. `public+restricted+individual`.
///
/// **This is how durable artefacts are keyed, and it must never be an audience
/// name.** ESPR uses a ~14-class actor vocabulary that is not battery's
/// three-audience lattice, and the delegated act mapping actors to data does not
/// exist yet. A signature or audit row keyed `"legitimateInterest"` would have
/// to be migrated the day that mapping lands; one keyed by the disclosure set it
/// actually covers keeps meaning exactly what it always meant, and a new actor
/// taxonomy becomes a new mapping onto the same keys.