1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
//! [`UnmodelledPayload`] — the data of a product group this build has no typed
//! variant for.
use crateProductIdentifier;
use crateProductGroupPayload;
use SvhcSubstance;
/// The payload of a product group this build has no typed variant for: the
/// wire tag, the whole object as received, and the identifier it carries.
///
/// # Why the fields are private
///
/// Three facts about this value have to hold together, and public fields let
/// any caller break each of them:
///
/// - `data` is a JSON **object** carrying its own `productGroup` key. The
/// serialiser only stamps the tag onto an object, so an array or scalar
/// would serialise untagged — and slip past the fail-closed reduction a
/// passport view applies to a product group it has no policy for.
/// - the tag names a group this build does **not** type. `Other("battery")`
/// would be a second representation of battery that compares unequal to the
/// first and misses every typed match.
/// - the identifier is the one `data` carries. It is read once, when the value
/// is built, and a caller able to replace `data` afterwards would leave a
/// carrier or a registration naming an identifier the signed passport does
/// not contain.
///
/// So the only ways to build one are deserialising a `ProductGroupData` and
/// [`ProductGroupData::other`](super::ProductGroupData::other), which enforce
/// the first two, and `data` is read-only, which keeps the third.
/// An untyped payload answers the one question every product group asks the
/// same way — which product it identifies — and nothing else.
///
/// The identifier's key and shape are fixed by EN 18219 clause 5 rather than
/// by any one act, which is why it can be read without a typed variant. The
/// other three are named differently by each act, or not defined at all, so
/// no key in an untyped object can be taken to mean them.