//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `vta/webvh/dids/create`. Version: `1.0`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Mint a did:webvh: the VTA generates the keys, writes the log's first entry, and either hands it to a hosting server or returns it for the caller to serve.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/vta/webvh/dids/create/1.0",
/// "title": "Payload",
/// "description": "Mint a did:webvh: the VTA generates the keys, writes the log's first entry, and either hands it to a hosting server or returns it for the caller to serve.",
/// "type": "object",
/// "required": [
/// "contextId"
/// ],
/// "properties": {
/// "addMediatorService": {
/// "description": "Add a DIDComm mediator service entry to the document.",
/// "type": "boolean"
/// },
/// "addTspService": {
/// "description": "Add a TSP transport service entry to the document.",
/// "type": "boolean"
/// },
/// "additionalServices": {
/// "description": "Further service entries, verbatim.",
/// "type": "array",
/// "items": {
/// "type": "object"
/// }
/// },
/// "contextId": {
/// "description": "Context the DID belongs to. Its keys are minted here, and deleting the context destroys the DID.",
/// "type": "string",
/// "minLength": 1
/// },
/// "didDocument": {
/// "description": "A DID document to publish rather than one the VTA composes.",
/// "type": "object"
/// },
/// "didLog": {
/// "description": "An existing log to adopt, for importing a DID minted elsewhere.",
/// "type": "string"
/// },
/// "domain": {
/// "description": "Hosting domain to publish under, when the server serves more than one.",
/// "type": "string"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "kaKeyId": {
/// "description": "Existing key-agreement key to publish. Absent mints a new one.",
/// "type": "string"
/// },
/// "label": {
/// "type": "string"
/// },
/// "path": {
/// "description": "Explicit path label under the host. Shorthand for pathMode `explicit`; supplying both is an error.",
/// "type": "string"
/// },
/// "pathMode": {
/// "description": "How the path under the host is chosen. Absent means `autoAssign`.",
/// "$ref": "#/definitions/WebvhPathMode"
/// },
/// "portable": {
/// "description": "Whether this DID may later move to another domain and keep its identity. **Fixed at creation** — portability is committed in the first log entry and cannot be added afterwards. A DID created non-portable is tied to where it was published for its whole life.",
/// "default": false,
/// "type": "boolean"
/// },
/// "preRotationCount": {
/// "description": "How many successor keys to commit in advance. **`0` disables pre-rotation**, which means a compromise of the current key cannot be recovered from by rotating: the successor was never committed, so a thief can rotate to their own key as convincingly as the owner can.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "serverId": {
/// "description": "Hosting server to publish through. Absent means **serverless**: the caller serves the log itself at `url`, and the VTA holds no hosting registration for it.",
/// "type": "string"
/// },
/// "setPrimary": {
/// "description": "Make this the context's primary DID.",
/// "type": "boolean"
/// },
/// "signingKeyId": {
/// "description": "Existing key to sign log entries with. Absent mints a new one.",
/// "type": "string"
/// },
/// "template": {
/// "description": "DID template to render the document from (see vta/did-templates/*).",
/// "type": "string"
/// },
/// "templateContext": {
/// "description": "Context whose templates to resolve `template` against. Absent uses the global scope, which is a different namespace and may hold a different template of the same name.",
/// "type": "string"
/// },
/// "templateVars": {
/// "description": "Variables for the template's placeholders.",
/// "type": "object",
/// "additionalProperties": {
/// "type": "string"
/// }
/// },
/// "url": {
/// "description": "Where the log will be served, for the serverless case. The DID's identity derives from this location, so changing it later is only possible for a `portable` DID.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Payload {
///Add a DIDComm mediator service entry to the document.
#[serde(
rename = "addMediatorService",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub add_mediator_service: ::std::option::Option<bool>,
///Add a TSP transport service entry to the document.
#[serde(
rename = "addTspService",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub add_tsp_service: ::std::option::Option<bool>,
///Further service entries, verbatim.
#[serde(
rename = "additionalServices",
default,
skip_serializing_if = "::std::vec::Vec::is_empty"
)]
pub additional_services:
::std::vec::Vec<::serde_json::Map<::std::string::String, ::serde_json::Value>>,
///Context the DID belongs to. Its keys are minted here, and deleting the context destroys the DID.
#[serde(rename = "contextId")]
pub context_id: PayloadContextId,
///A DID document to publish rather than one the VTA composes.
#[serde(
rename = "didDocument",
default,
skip_serializing_if = "::serde_json::Map::is_empty"
)]
pub did_document: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
///An existing log to adopt, for importing a DID minted elsewhere.
#[serde(
rename = "didLog",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub did_log: ::std::option::Option<::std::string::String>,
///Hosting domain to publish under, when the server serves more than one.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub domain: ::std::option::Option<::std::string::String>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Existing key-agreement key to publish. Absent mints a new one.
#[serde(
rename = "kaKeyId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub ka_key_id: ::std::option::Option<::std::string::String>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub label: ::std::option::Option<::std::string::String>,
///Explicit path label under the host. Shorthand for pathMode `explicit`; supplying both is an error.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub path: ::std::option::Option<::std::string::String>,
///How the path under the host is chosen. Absent means `autoAssign`.
#[serde(
rename = "pathMode",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub path_mode: ::std::option::Option<WebvhPathMode>,
///Whether this DID may later move to another domain and keep its identity. **Fixed at creation** — portability is committed in the first log entry and cannot be added afterwards. A DID created non-portable is tied to where it was published for its whole life.
#[serde(default)]
pub portable: bool,
///How many successor keys to commit in advance. **`0` disables pre-rotation**, which means a compromise of the current key cannot be recovered from by rotating: the successor was never committed, so a thief can rotate to their own key as convincingly as the owner can.
#[serde(
rename = "preRotationCount",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub pre_rotation_count: ::std::option::Option<u64>,
///Hosting server to publish through. Absent means **serverless**: the caller serves the log itself at `url`, and the VTA holds no hosting registration for it.
#[serde(
rename = "serverId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub server_id: ::std::option::Option<::std::string::String>,
///Make this the context's primary DID.
#[serde(
rename = "setPrimary",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub set_primary: ::std::option::Option<bool>,
///Existing key to sign log entries with. Absent mints a new one.
#[serde(
rename = "signingKeyId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub signing_key_id: ::std::option::Option<::std::string::String>,
///DID template to render the document from (see vta/did-templates/*).
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub template: ::std::option::Option<::std::string::String>,
///Context whose templates to resolve `template` against. Absent uses the global scope, which is a different namespace and may hold a different template of the same name.
#[serde(
rename = "templateContext",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub template_context: ::std::option::Option<::std::string::String>,
///Variables for the template's placeholders.
#[serde(
rename = "templateVars",
default,
skip_serializing_if = ":: std :: collections :: HashMap::is_empty"
)]
pub template_vars: ::std::collections::HashMap<::std::string::String, ::std::string::String>,
///Where the log will be served, for the serverless case. The DID's identity derives from this location, so changing it later is only possible for a `portable` DID.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub url: ::std::option::Option<::std::string::String>,
}
///Context the DID belongs to. Its keys are minted here, and deleting the context destroys the DID.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Context the DID belongs to. Its keys are minted here, and deleting the context destroys the DID.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadContextId(::std::string::String);
impl ::std::ops::Deref for PayloadContextId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadContextId> for ::std::string::String {
fn from(value: PayloadContextId) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadContextId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadContextId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadContextId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadContextId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadContextId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Success response to vta/webvh/dids/create. Type https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "Success response to vta/webvh/dids/create. Type https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response.",
/// "type": "object",
/// "required": [
/// "contextId",
/// "createdAt",
/// "did",
/// "kaKeyId",
/// "portable",
/// "preRotationKeyCount",
/// "scid",
/// "signingKeyId"
/// ],
/// "properties": {
/// "contextId": {
/// "type": "string"
/// },
/// "createdAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "did": {
/// "type": "string"
/// },
/// "didDocument": {
/// "description": "The published document, when the VTA composed one.",
/// "type": "object"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "kaKeyId": {
/// "type": "string"
/// },
/// "logEntry": {
/// "description": "The log's first entry. For a serverless DID this is what the caller must serve — the DID does not resolve until they do.",
/// "type": "string"
/// },
/// "mnemonic": {
/// "description": "The hosting server's handle for the record. Absent for a serverless DID.",
/// "type": "string"
/// },
/// "portable": {
/// "type": "boolean"
/// },
/// "preRotationKeyCount": {
/// "description": "Successor keys committed. `0` means pre-rotation is off for this DID.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "scid": {
/// "description": "Self-certifying identifier committing to the log's first entry.",
/// "type": "string"
/// },
/// "serverId": {
/// "type": "string"
/// },
/// "signingKeyId": {
/// "type": "string"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Response {
#[serde(rename = "contextId")]
pub context_id: ::std::string::String,
#[serde(rename = "createdAt")]
pub created_at: ::chrono::DateTime<::chrono::offset::Utc>,
pub did: ::std::string::String,
///The published document, when the VTA composed one.
#[serde(
rename = "didDocument",
default,
skip_serializing_if = "::serde_json::Map::is_empty"
)]
pub did_document: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
#[serde(rename = "kaKeyId")]
pub ka_key_id: ::std::string::String,
///The log's first entry. For a serverless DID this is what the caller must serve — the DID does not resolve until they do.
#[serde(
rename = "logEntry",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub log_entry: ::std::option::Option<::std::string::String>,
///The hosting server's handle for the record. Absent for a serverless DID.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub mnemonic: ::std::option::Option<::std::string::String>,
pub portable: bool,
///Successor keys committed. `0` means pre-rotation is off for this DID.
#[serde(rename = "preRotationKeyCount")]
pub pre_rotation_key_count: u64,
///Self-certifying identifier committing to the log's first entry.
pub scid: ::std::string::String,
#[serde(
rename = "serverId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub server_id: ::std::option::Option<::std::string::String>,
#[serde(rename = "signingKeyId")]
pub signing_key_id: ::std::string::String,
}
///Where under the host the DID is served. `wellKnown` puts it at the host root (`/.well-known/did.jsonl`) — at most one DID per host can hold that. `explicit` names the path. `autoAssign` lets the server allocate one.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "WebvhPathMode",
/// "description": "Where under the host the DID is served. `wellKnown` puts it at the host root (`/.well-known/did.jsonl`) — at most one DID per host can hold that. `explicit` names the path. `autoAssign` lets the server allocate one.",
/// "oneOf": [
/// {
/// "type": "object",
/// "required": [
/// "mode"
/// ],
/// "properties": {
/// "mode": {
/// "const": "wellKnown"
/// }
/// },
/// "additionalProperties": false
/// },
/// {
/// "type": "object",
/// "required": [
/// "mode",
/// "path"
/// ],
/// "properties": {
/// "mode": {
/// "const": "explicit"
/// },
/// "path": {
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
/// },
/// {
/// "type": "object",
/// "required": [
/// "mode"
/// ],
/// "properties": {
/// "mode": {
/// "const": "autoAssign"
/// }
/// },
/// "additionalProperties": false
/// }
/// ]
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(tag = "mode", content = "path")]
pub enum WebvhPathMode {
#[serde(rename = "wellKnown")]
WellKnown,
#[serde(rename = "explicit")]
Explicit(WebvhPathModePath),
#[serde(rename = "autoAssign")]
AutoAssign,
}
impl ::std::convert::From<WebvhPathModePath> for WebvhPathMode {
fn from(value: WebvhPathModePath) -> Self {
Self::Explicit(value)
}
}
///`WebvhPathModePath`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct WebvhPathModePath(::std::string::String);
impl ::std::ops::Deref for WebvhPathModePath {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<WebvhPathModePath> for ::std::string::String {
fn from(value: WebvhPathModePath) -> Self {
value.0
}
}
impl ::std::str::FromStr for WebvhPathModePath {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for WebvhPathModePath {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for WebvhPathModePath {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for WebvhPathModePath {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for WebvhPathModePath {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/vta/webvh/dids/create/1.0";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to vta/webvh/dids/create. Type https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response.\",\n \"properties\": {\n \"contextId\": {\n \"type\": \"string\"\n },\n \"createdAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"did\": {\n \"type\": \"string\"\n },\n \"didDocument\": {\n \"description\": \"The published document, when the VTA composed one.\",\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"kaKeyId\": {\n \"type\": \"string\"\n },\n \"logEntry\": {\n \"description\": \"The log's first entry. For a serverless DID this is what the caller must serve — the DID does not resolve until they do.\",\n \"type\": \"string\"\n },\n \"mnemonic\": {\n \"description\": \"The hosting server's handle for the record. Absent for a serverless DID.\",\n \"type\": \"string\"\n },\n \"portable\": {\n \"type\": \"boolean\"\n },\n \"preRotationKeyCount\": {\n \"description\": \"Successor keys committed. `0` means pre-rotation is off for this DID.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"scid\": {\n \"description\": \"Self-certifying identifier committing to the log's first entry.\",\n \"type\": \"string\"\n },\n \"serverId\": {\n \"type\": \"string\"\n },\n \"signingKeyId\": {\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"did\",\n \"contextId\",\n \"scid\",\n \"portable\",\n \"signingKeyId\",\n \"kaKeyId\",\n \"preRotationKeyCount\",\n \"createdAt\"\n ],\n \"title\": \"VTA WebVH DIDs Create — response payload\",\n \"type\": \"object\"\n },\n \"WebvhPathMode\": {\n \"description\": \"Where under the host the DID is served. `wellKnown` puts it at the host root (`/.well-known/did.jsonl`) — at most one DID per host can hold that. `explicit` names the path. `autoAssign` lets the server allocate one.\",\n \"oneOf\": [\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"wellKnown\"\n }\n },\n \"required\": [\n \"mode\"\n ],\n \"type\": \"object\"\n },\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"explicit\"\n },\n \"path\": {\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"mode\",\n \"path\"\n ],\n \"type\": \"object\"\n },\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"autoAssign\"\n }\n },\n \"required\": [\n \"mode\"\n ],\n \"type\": \"object\"\n }\n ],\n \"title\": \"WebvhPathMode\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/vta/webvh/dids/create/1.0\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Mint a did:webvh: the VTA generates the keys, writes the log's first entry, and either hands it to a hosting server or returns it for the caller to serve.\",\n \"properties\": {\n \"addMediatorService\": {\n \"description\": \"Add a DIDComm mediator service entry to the document.\",\n \"type\": \"boolean\"\n },\n \"addTspService\": {\n \"description\": \"Add a TSP transport service entry to the document.\",\n \"type\": \"boolean\"\n },\n \"additionalServices\": {\n \"description\": \"Further service entries, verbatim.\",\n \"items\": {\n \"type\": \"object\"\n },\n \"type\": \"array\"\n },\n \"contextId\": {\n \"description\": \"Context the DID belongs to. Its keys are minted here, and deleting the context destroys the DID.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"didDocument\": {\n \"description\": \"A DID document to publish rather than one the VTA composes.\",\n \"type\": \"object\"\n },\n \"didLog\": {\n \"description\": \"An existing log to adopt, for importing a DID minted elsewhere.\",\n \"type\": \"string\"\n },\n \"domain\": {\n \"description\": \"Hosting domain to publish under, when the server serves more than one.\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"kaKeyId\": {\n \"description\": \"Existing key-agreement key to publish. Absent mints a new one.\",\n \"type\": \"string\"\n },\n \"label\": {\n \"type\": \"string\"\n },\n \"path\": {\n \"description\": \"Explicit path label under the host. Shorthand for pathMode `explicit`; supplying both is an error.\",\n \"type\": \"string\"\n },\n \"pathMode\": {\n \"$ref\": \"#/$defs/WebvhPathMode\",\n \"description\": \"How the path under the host is chosen. Absent means `autoAssign`.\"\n },\n \"portable\": {\n \"default\": false,\n \"description\": \"Whether this DID may later move to another domain and keep its identity. **Fixed at creation** — portability is committed in the first log entry and cannot be added afterwards. A DID created non-portable is tied to where it was published for its whole life.\",\n \"type\": \"boolean\"\n },\n \"preRotationCount\": {\n \"description\": \"How many successor keys to commit in advance. **`0` disables pre-rotation**, which means a compromise of the current key cannot be recovered from by rotating: the successor was never committed, so a thief can rotate to their own key as convincingly as the owner can.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"serverId\": {\n \"description\": \"Hosting server to publish through. Absent means **serverless**: the caller serves the log itself at `url`, and the VTA holds no hosting registration for it.\",\n \"type\": \"string\"\n },\n \"setPrimary\": {\n \"description\": \"Make this the context's primary DID.\",\n \"type\": \"boolean\"\n },\n \"signingKeyId\": {\n \"description\": \"Existing key to sign log entries with. Absent mints a new one.\",\n \"type\": \"string\"\n },\n \"template\": {\n \"description\": \"DID template to render the document from (see vta/did-templates/*).\",\n \"type\": \"string\"\n },\n \"templateContext\": {\n \"description\": \"Context whose templates to resolve `template` against. Absent uses the global scope, which is a different namespace and may hold a different template of the same name.\",\n \"type\": \"string\"\n },\n \"templateVars\": {\n \"additionalProperties\": {\n \"type\": \"string\"\n },\n \"description\": \"Variables for the template's placeholders.\",\n \"type\": \"object\"\n },\n \"url\": {\n \"description\": \"Where the log will be served, for the serverless case. The DID's identity derives from this location, so changing it later is only possible for a `portable` DID.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"contextId\"\n ],\n \"title\": \"VTA WebVH DIDs Create — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to vta/webvh/dids/create. Type https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response.\",\n \"properties\": {\n \"contextId\": {\n \"type\": \"string\"\n },\n \"createdAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"did\": {\n \"type\": \"string\"\n },\n \"didDocument\": {\n \"description\": \"The published document, when the VTA composed one.\",\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"kaKeyId\": {\n \"type\": \"string\"\n },\n \"logEntry\": {\n \"description\": \"The log's first entry. For a serverless DID this is what the caller must serve — the DID does not resolve until they do.\",\n \"type\": \"string\"\n },\n \"mnemonic\": {\n \"description\": \"The hosting server's handle for the record. Absent for a serverless DID.\",\n \"type\": \"string\"\n },\n \"portable\": {\n \"type\": \"boolean\"\n },\n \"preRotationKeyCount\": {\n \"description\": \"Successor keys committed. `0` means pre-rotation is off for this DID.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"scid\": {\n \"description\": \"Self-certifying identifier committing to the log's first entry.\",\n \"type\": \"string\"\n },\n \"serverId\": {\n \"type\": \"string\"\n },\n \"signingKeyId\": {\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"did\",\n \"contextId\",\n \"scid\",\n \"portable\",\n \"signingKeyId\",\n \"kaKeyId\",\n \"preRotationKeyCount\",\n \"createdAt\"\n ],\n \"title\": \"VTA WebVH DIDs Create — response payload\",\n \"type\": \"object\"\n },\n \"WebvhPathMode\": {\n \"description\": \"Where under the host the DID is served. `wellKnown` puts it at the host root (`/.well-known/did.jsonl`) — at most one DID per host can hold that. `explicit` names the path. `autoAssign` lets the server allocate one.\",\n \"oneOf\": [\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"wellKnown\"\n }\n },\n \"required\": [\n \"mode\"\n ],\n \"type\": \"object\"\n },\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"explicit\"\n },\n \"path\": {\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"mode\",\n \"path\"\n ],\n \"type\": \"object\"\n },\n {\n \"additionalProperties\": false,\n \"properties\": {\n \"mode\": {\n \"const\": \"autoAssign\"\n }\n },\n \"required\": [\n \"mode\"\n ],\n \"type\": \"object\"\n }\n ],\n \"title\": \"WebvhPathMode\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"1a2b3c4d-0000-4000-8000-000000000001\",\n \"type\": \"https://trusttasks.org/spec/vta/webvh/dids/create/1.0\",\n \"issuer\": \"did:key:z6MkAdmin\",\n \"recipient\": \"did:web:vta.example\",\n \"issuedAt\": \"2026-08-19T11:00:00Z\",\n \"payload\": {\n \"contextId\": \"personal\",\n \"serverId\": \"prod\",\n \"pathMode\": { \"mode\": \"explicit\", \"path\": \"alice\" },\n \"portable\": true,\n \"preRotationCount\": 3\n },\n \"proof\": {\n \"type\": \"DataIntegrityProof\",\n \"cryptosuite\": \"eddsa-jcs-2022\",\n \"created\": \"2026-08-19T11:00:00Z\",\n \"verificationMethod\": \"did:key:z6MkAdmin#z6MkAdmin\",\n \"proofPurpose\": \"assertionMethod\",\n \"proofValue\": \"z3FXQ...\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"2b3c4d5e-0000-4000-8000-000000000002\",\n \"type\": \"https://trusttasks.org/spec/vta/webvh/dids/create/1.0#response\",\n \"issuer\": \"did:web:vta.example\",\n \"recipient\": \"did:key:z6MkAdmin\",\n \"issuedAt\": \"2026-08-19T11:00:01Z\",\n \"threadId\": \"1a2b3c4d-0000-4000-8000-000000000001\",\n \"payload\": {\n \"did\": \"did:webvh:QmScidAbCdEfGh:example.com:alice\",\n \"contextId\": \"personal\",\n \"serverId\": \"prod\",\n \"mnemonic\": \"alice\",\n \"scid\": \"QmScidAbCdEfGh\",\n \"portable\": true,\n \"signingKeyId\": \"webvh-alice-sign\",\n \"kaKeyId\": \"webvh-alice-ka\",\n \"preRotationKeyCount\": 3,\n \"createdAt\": \"2026-08-19T11:00:01Z\"\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
}