//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `keys/import`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Where the private key came from. `derived` means the maintainer generated it from a seed it holds and can reproduce it from `derivationPath`; `imported` means it arrived from outside and exists only as stored material. The distinction is operationally load-bearing: a `derived` key survives a seed restore, an `imported` one is lost unless it was backed up separately.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "KeyOrigin",
/// "description": "Where the private key came from. `derived` means the maintainer generated it from a seed it holds and can reproduce it from `derivationPath`; `imported` means it arrived from outside and exists only as stored material. The distinction is operationally load-bearing: a `derived` key survives a seed restore, an `imported` one is lost unless it was backed up separately.",
/// "default": "derived",
/// "type": "string",
/// "enum": [
/// "derived",
/// "imported"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
pub enum KeyOrigin {
#[serde(rename = "derived")]
Derived,
#[serde(rename = "imported")]
Imported,
}
impl ::std::fmt::Display for KeyOrigin {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Derived => f.write_str("derived"),
Self::Imported => f.write_str("imported"),
}
}
}
impl ::std::str::FromStr for KeyOrigin {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"derived" => Ok(Self::Derived),
"imported" => Ok(Self::Imported),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for KeyOrigin {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for KeyOrigin {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for KeyOrigin {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::default::Default for KeyOrigin {
fn default() -> Self {
KeyOrigin::Derived
}
}
///`KeyRecord`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "KeyRecord",
/// "type": "object",
/// "required": [
/// "createdAt",
/// "keyId",
/// "keyType",
/// "publicKey",
/// "status"
/// ],
/// "properties": {
/// "contextId": {
/// "description": "Scope the key belongs to. **Absence is not 'every scope'** — a key with no context is reachable only by a caller with unrestricted authority over the maintainer, which is the more restrictive reading, and a consumer that treats absence as a wildcard inverts the guarantee.",
/// "type": "string"
/// },
/// "createdAt": {
/// "description": "RFC 3339 timestamp at which the key was created or imported.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "derivationPath": {
/// "description": "Hierarchical-deterministic path the key was derived at, when `origin` is `derived`. Absent for imported keys, which have no path.",
/// "type": "string"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "keyId": {
/// "description": "Maintainer-scoped identifier for the key. Stable for the key's lifetime except through an explicit `keys/rename`.",
/// "type": "string",
/// "minLength": 1
/// },
/// "keyType": {
/// "$ref": "#/definitions/KeyType"
/// },
/// "label": {
/// "description": "Optional human-readable label. Operator-facing only; carries no authorization meaning.",
/// "type": "string"
/// },
/// "origin": {
/// "$ref": "#/definitions/KeyOrigin"
/// },
/// "publicKey": {
/// "description": "The public half, multibase-encoded. The private half is never carried by any keys/* response.",
/// "type": "string",
/// "minLength": 1
/// },
/// "seedId": {
/// "description": "Identifier of the seed the key was derived from, when the maintainer holds more than one. Absent for imported keys.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "status": {
/// "$ref": "#/definitions/KeyStatus"
/// },
/// "updatedAt": {
/// "description": "RFC 3339 timestamp of the last change to the record (rename, revocation).",
/// "type": "string",
/// "format": "date-time"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct KeyRecord {
///Scope the key belongs to. **Absence is not 'every scope'** — a key with no context is reachable only by a caller with unrestricted authority over the maintainer, which is the more restrictive reading, and a consumer that treats absence as a wildcard inverts the guarantee.
#[serde(
rename = "contextId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub context_id: ::std::option::Option<::std::string::String>,
///RFC 3339 timestamp at which the key was created or imported.
#[serde(rename = "createdAt")]
pub created_at: ::chrono::DateTime<::chrono::offset::Utc>,
///Hierarchical-deterministic path the key was derived at, when `origin` is `derived`. Absent for imported keys, which have no path.
#[serde(
rename = "derivationPath",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub derivation_path: ::std::option::Option<::std::string::String>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Maintainer-scoped identifier for the key. Stable for the key's lifetime except through an explicit `keys/rename`.
#[serde(rename = "keyId")]
pub key_id: KeyRecordKeyId,
#[serde(rename = "keyType")]
pub key_type: KeyType,
///Optional human-readable label. Operator-facing only; carries no authorization meaning.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub label: ::std::option::Option<::std::string::String>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub origin: ::std::option::Option<KeyOrigin>,
///The public half, multibase-encoded. The private half is never carried by any keys/* response.
#[serde(rename = "publicKey")]
pub public_key: KeyRecordPublicKey,
///Identifier of the seed the key was derived from, when the maintainer holds more than one. Absent for imported keys.
#[serde(
rename = "seedId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub seed_id: ::std::option::Option<u64>,
pub status: KeyStatus,
///RFC 3339 timestamp of the last change to the record (rename, revocation).
#[serde(
rename = "updatedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub updated_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
}
///Maintainer-scoped identifier for the key. Stable for the key's lifetime except through an explicit `keys/rename`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Maintainer-scoped identifier for the key. Stable for the key's lifetime except through an explicit `keys/rename`.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct KeyRecordKeyId(::std::string::String);
impl ::std::ops::Deref for KeyRecordKeyId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<KeyRecordKeyId> for ::std::string::String {
fn from(value: KeyRecordKeyId) -> Self {
value.0
}
}
impl ::std::str::FromStr for KeyRecordKeyId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for KeyRecordKeyId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for KeyRecordKeyId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for KeyRecordKeyId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for KeyRecordKeyId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The public half, multibase-encoded. The private half is never carried by any keys/* response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The public half, multibase-encoded. The private half is never carried by any keys/* response.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct KeyRecordPublicKey(::std::string::String);
impl ::std::ops::Deref for KeyRecordPublicKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<KeyRecordPublicKey> for ::std::string::String {
fn from(value: KeyRecordPublicKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for KeyRecordPublicKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for KeyRecordPublicKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for KeyRecordPublicKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for KeyRecordPublicKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for KeyRecordPublicKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Lifecycle state. Only an `active` key may be named in a signing request; a `revoked` key is retained so historic signatures remain attributable, and MUST NOT be reactivated.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "KeyStatus",
/// "description": "Lifecycle state. Only an `active` key may be named in a signing request; a `revoked` key is retained so historic signatures remain attributable, and MUST NOT be reactivated.",
/// "type": "string",
/// "enum": [
/// "active",
/// "revoked"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
pub enum KeyStatus {
#[serde(rename = "active")]
Active,
#[serde(rename = "revoked")]
Revoked,
}
impl ::std::fmt::Display for KeyStatus {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Active => f.write_str("active"),
Self::Revoked => f.write_str("revoked"),
}
}
}
impl ::std::str::FromStr for KeyStatus {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"active" => Ok(Self::Active),
"revoked" => Ok(Self::Revoked),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for KeyStatus {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for KeyStatus {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for KeyStatus {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///Cryptographic algorithm the key material belongs to. `ed25519` signs (EdDSA), `x25519` performs key agreement and never signs, `p256` signs (ES256).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "KeyType",
/// "description": "Cryptographic algorithm the key material belongs to. `ed25519` signs (EdDSA), `x25519` performs key agreement and never signs, `p256` signs (ES256).",
/// "type": "string",
/// "enum": [
/// "ed25519",
/// "x25519",
/// "p256"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
pub enum KeyType {
#[serde(rename = "ed25519")]
Ed25519,
#[serde(rename = "x25519")]
X25519,
#[serde(rename = "p256")]
P256,
}
impl ::std::fmt::Display for KeyType {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Ed25519 => f.write_str("ed25519"),
Self::X25519 => f.write_str("x25519"),
Self::P256 => f.write_str("p256"),
}
}
}
impl ::std::str::FromStr for KeyType {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"ed25519" => Ok(Self::Ed25519),
"x25519" => Ok(Self::X25519),
"p256" => Ok(Self::P256),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for KeyType {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for KeyType {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for KeyType {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///Hand an externally-created private key to a custodian. Exactly one carrier member MUST be present; the choice of carrier is a confidentiality decision, not a formatting one.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/keys/import/0.1",
/// "title": "Payload",
/// "description": "Hand an externally-created private key to a custodian. Exactly one carrier member MUST be present; the choice of carrier is a confidentiality decision, not a formatting one.",
/// "type": "object",
/// "oneOf": [
/// {
/// "required": [
/// "privateKeySealed"
/// ]
/// },
/// {
/// "required": [
/// "privateKeyJwe"
/// ]
/// },
/// {
/// "required": [
/// "privateKeyMultibase"
/// ]
/// }
/// ],
/// "required": [
/// "keyType"
/// ],
/// "properties": {
/// "contextId": {
/// "description": "Scope to file the imported key under. Absence is the most restrictive reading, not a wildcard — see KeyRecord.contextId.",
/// "type": "string"
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "keyType": {
/// "description": "Algorithm of the key being imported. The custodian MUST verify the supplied material is of this type rather than trusting the claim.",
/// "$ref": "#/definitions/KeyType"
/// },
/// "label": {
/// "description": "Optional human-readable label for the resulting record.",
/// "type": "string"
/// },
/// "privateKeyJwe": {
/// "description": "The private key as a JWE compact serialization, encrypted to the custodian. Equivalent in intent to `privateKeySealed`; retained for producers that already speak JOSE.",
/// "type": "string"
/// },
/// "privateKeyMultibase": {
/// "description": "The raw private key, multibase-encoded and NOT encrypted to the custodian. Admissible **only** where the transport itself provides end-to-end confidentiality between producer and custodian. A custodian reachable over a transport that terminates anywhere in between (TLS at a load balancer, for instance) MUST refuse this member — see the specification's Security section.",
/// "type": "string"
/// },
/// "privateKeySealed": {
/// "description": "The private key inside an armored sealed-transfer bundle, encrypted to the custodian's own public key. The only carrier that keeps the key confidential from every intermediary, including a transport terminator, so it is the one to prefer.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(untagged, deny_unknown_fields)]
pub enum Payload {
Variant0 {
///Scope to file the imported key under. Absence is the most restrictive reading, not a wildcard — see KeyRecord.contextId.
#[serde(
rename = "contextId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
context_id: ::std::option::Option<::std::string::String>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
ext: ::std::option::Option<Ext>,
///Algorithm of the key being imported. The custodian MUST verify the supplied material is of this type rather than trusting the claim.
#[serde(rename = "keyType")]
key_type: KeyType,
///Optional human-readable label for the resulting record.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
label: ::std::option::Option<::std::string::String>,
///The private key inside an armored sealed-transfer bundle, encrypted to the custodian's own public key. The only carrier that keeps the key confidential from every intermediary, including a transport terminator, so it is the one to prefer.
#[serde(rename = "privateKeySealed")]
private_key_sealed: ::std::string::String,
},
Variant1 {
///Scope to file the imported key under. Absence is the most restrictive reading, not a wildcard — see KeyRecord.contextId.
#[serde(
rename = "contextId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
context_id: ::std::option::Option<::std::string::String>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
ext: ::std::option::Option<Ext>,
///Algorithm of the key being imported. The custodian MUST verify the supplied material is of this type rather than trusting the claim.
#[serde(rename = "keyType")]
key_type: KeyType,
///Optional human-readable label for the resulting record.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
label: ::std::option::Option<::std::string::String>,
///The private key as a JWE compact serialization, encrypted to the custodian. Equivalent in intent to `privateKeySealed`; retained for producers that already speak JOSE.
#[serde(rename = "privateKeyJwe")]
private_key_jwe: ::std::string::String,
},
Variant2 {
///Scope to file the imported key under. Absence is the most restrictive reading, not a wildcard — see KeyRecord.contextId.
#[serde(
rename = "contextId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
context_id: ::std::option::Option<::std::string::String>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
ext: ::std::option::Option<Ext>,
///Algorithm of the key being imported. The custodian MUST verify the supplied material is of this type rather than trusting the claim.
#[serde(rename = "keyType")]
key_type: KeyType,
///Optional human-readable label for the resulting record.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
label: ::std::option::Option<::std::string::String>,
///The raw private key, multibase-encoded and NOT encrypted to the custodian. Admissible **only** where the transport itself provides end-to-end confidentiality between producer and custodian. A custodian reachable over a transport that terminates anywhere in between (TLS at a load balancer, for instance) MUST refuse this member — see the specification's Security section.
#[serde(rename = "privateKeyMultibase")]
private_key_multibase: ::std::string::String,
},
}
///The success response to a keys/import request: the record the custodian now holds. Carried in a Trust Task document whose type is https://trusttasks.org/spec/keys/import/0.1#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "The success response to a keys/import request: the record the custodian now holds. Carried in a Trust Task document whose type is https://trusttasks.org/spec/keys/import/0.1#response.",
/// "type": "object",
/// "required": [
/// "key"
/// ],
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "key": {
/// "description": "The realized record. `origin` is `imported` and `derivationPath` is absent — an imported key is not reproducible from any seed the custodian holds.",
/// "$ref": "#/definitions/KeyRecord"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Response {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The realized record. `origin` is `imported` and `derivationPath` is absent — an imported key is not reproducible from any seed the custodian holds.
pub key: KeyRecord,
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/keys/import/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/keys/import/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
}
#[cfg(feature = "validate")]
impl crate::validate::ValidatedPayload for Payload {
const SCHEMA_JSON: &'static str = "{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"KeyOrigin\": {\n \"default\": \"derived\",\n \"description\": \"Where the private key came from. `derived` means the maintainer generated it from a seed it holds and can reproduce it from `derivationPath`; `imported` means it arrived from outside and exists only as stored material. The distinction is operationally load-bearing: a `derived` key survives a seed restore, an `imported` one is lost unless it was backed up separately.\",\n \"enum\": [\n \"derived\",\n \"imported\"\n ],\n \"title\": \"KeyOrigin\",\n \"type\": \"string\"\n },\n \"KeyRecord\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"contextId\": {\n \"description\": \"Scope the key belongs to. **Absence is not 'every scope'** — a key with no context is reachable only by a caller with unrestricted authority over the maintainer, which is the more restrictive reading, and a consumer that treats absence as a wildcard inverts the guarantee.\",\n \"type\": \"string\"\n },\n \"createdAt\": {\n \"description\": \"RFC 3339 timestamp at which the key was created or imported.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"derivationPath\": {\n \"description\": \"Hierarchical-deterministic path the key was derived at, when `origin` is `derived`. Absent for imported keys, which have no path.\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"keyId\": {\n \"description\": \"Maintainer-scoped identifier for the key. Stable for the key's lifetime except through an explicit `keys/rename`.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"keyType\": {\n \"$ref\": \"#/$defs/KeyType\"\n },\n \"label\": {\n \"description\": \"Optional human-readable label. Operator-facing only; carries no authorization meaning.\",\n \"type\": \"string\"\n },\n \"origin\": {\n \"$ref\": \"#/$defs/KeyOrigin\"\n },\n \"publicKey\": {\n \"description\": \"The public half, multibase-encoded. The private half is never carried by any keys/* response.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"seedId\": {\n \"description\": \"Identifier of the seed the key was derived from, when the maintainer holds more than one. Absent for imported keys.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"status\": {\n \"$ref\": \"#/$defs/KeyStatus\"\n },\n \"updatedAt\": {\n \"description\": \"RFC 3339 timestamp of the last change to the record (rename, revocation).\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"keyId\",\n \"keyType\",\n \"status\",\n \"publicKey\",\n \"createdAt\"\n ],\n \"title\": \"KeyRecord\",\n \"type\": \"object\"\n },\n \"KeyStatus\": {\n \"description\": \"Lifecycle state. Only an `active` key may be named in a signing request; a `revoked` key is retained so historic signatures remain attributable, and MUST NOT be reactivated.\",\n \"enum\": [\n \"active\",\n \"revoked\"\n ],\n \"title\": \"KeyStatus\",\n \"type\": \"string\"\n },\n \"KeyType\": {\n \"description\": \"Cryptographic algorithm the key material belongs to. `ed25519` signs (EdDSA), `x25519` performs key agreement and never signs, `p256` signs (ES256).\",\n \"enum\": [\n \"ed25519\",\n \"x25519\",\n \"p256\"\n ],\n \"title\": \"KeyType\",\n \"type\": \"string\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The success response to a keys/import request: the record the custodian now holds. Carried in a Trust Task document whose type is https://trusttasks.org/spec/keys/import/0.1#response.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"key\": {\n \"$ref\": \"#/$defs/KeyRecord\",\n \"description\": \"The realized record. `origin` is `imported` and `derivationPath` is absent — an imported key is not reproducible from any seed the custodian holds.\"\n }\n },\n \"required\": [\n \"key\"\n ],\n \"title\": \"Keys Import — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/keys/import/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Hand an externally-created private key to a custodian. Exactly one carrier member MUST be present; the choice of carrier is a confidentiality decision, not a formatting one.\",\n \"oneOf\": [\n {\n \"required\": [\n \"privateKeySealed\"\n ]\n },\n {\n \"required\": [\n \"privateKeyJwe\"\n ]\n },\n {\n \"required\": [\n \"privateKeyMultibase\"\n ]\n }\n ],\n \"properties\": {\n \"contextId\": {\n \"description\": \"Scope to file the imported key under. Absence is the most restrictive reading, not a wildcard — see KeyRecord.contextId.\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"keyType\": {\n \"$ref\": \"#/$defs/KeyType\",\n \"description\": \"Algorithm of the key being imported. The custodian MUST verify the supplied material is of this type rather than trusting the claim.\"\n },\n \"label\": {\n \"description\": \"Optional human-readable label for the resulting record.\",\n \"type\": \"string\"\n },\n \"privateKeyJwe\": {\n \"description\": \"The private key as a JWE compact serialization, encrypted to the custodian. Equivalent in intent to `privateKeySealed`; retained for producers that already speak JOSE.\",\n \"type\": \"string\"\n },\n \"privateKeyMultibase\": {\n \"description\": \"The raw private key, multibase-encoded and NOT encrypted to the custodian. Admissible **only** where the transport itself provides end-to-end confidentiality between producer and custodian. A custodian reachable over a transport that terminates anywhere in between (TLS at a load balancer, for instance) MUST refuse this member — see the specification's Security section.\",\n \"type\": \"string\"\n },\n \"privateKeySealed\": {\n \"description\": \"The private key inside an armored sealed-transfer bundle, encrypted to the custodian's own public key. The only carrier that keeps the key confidential from every intermediary, including a transport terminator, so it is the one to prefer.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"keyType\"\n ],\n \"title\": \"Keys Import — payload\",\n \"type\": \"object\"\n}\n";
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"c3f0e1d2-1a2b-4c3d-8e4f-5a6b7c8d9e0f\",\n \"type\": \"https://trusttasks.org/spec/keys/import/0.1\",\n \"issuer\": \"did:web:operator.example\",\n \"recipient\": \"did:web:custodian.example\",\n \"issuedAt\": \"2026-07-31T09:10:00Z\",\n \"payload\": {\n \"keyType\": \"ed25519\",\n \"privateKeySealed\": \"-----BEGIN SEALED TRANSFER-----\\nBundle-Id: 7a1c...\\n...\\n-----END SEALED TRANSFER-----\",\n \"label\": \"legacy release-signing key\",\n \"contextId\": \"release\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_2() {
const JSON: &str = "{\n \"id\": \"d4e1f2a3-2b3c-4d5e-9f60-6b7c8d9e0f11\",\n \"type\": \"https://trusttasks.org/spec/keys/import/0.1\",\n \"issuer\": \"did:web:operator.example\",\n \"recipient\": \"did:web:custodian.example\",\n \"issuedAt\": \"2026-07-31T09:12:00Z\",\n \"payload\": {\n \"keyType\": \"ed25519\",\n \"privateKeyMultibase\": \"z3u2Wv...\",\n \"label\": \"migrated signer\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"e5f2a3b4-3c4d-5e6f-a071-7c8d9e0f1122\",\n \"type\": \"https://trusttasks.org/spec/keys/import/0.1#response\",\n \"threadId\": \"c3f0e1d2-1a2b-4c3d-8e4f-5a6b7c8d9e0f\",\n \"issuer\": \"did:web:custodian.example\",\n \"recipient\": \"did:web:operator.example\",\n \"issuedAt\": \"2026-07-31T09:10:02Z\",\n \"payload\": {\n \"key\": {\n \"keyId\": \"legacy-release-signer\",\n \"keyType\": \"ed25519\",\n \"status\": \"active\",\n \"publicKey\": \"z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH\",\n \"origin\": \"imported\",\n \"label\": \"legacy release-signing key\",\n \"contextId\": \"release\",\n \"createdAt\": \"2026-07-31T09:10:02Z\",\n \"updatedAt\": \"2026-07-31T09:10:02Z\"\n }\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
}