//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `auth/passkey/enroll/finish`. Version: `0.2`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///The credential the client returns from `navigator.credentials.get`. Binary fields are base64url-encoded.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "AuthenticatorAssertionResponse (login)",
/// "description": "The credential the client returns from `navigator.credentials.get`. Binary fields are base64url-encoded.",
/// "type": "object",
/// "required": [
/// "id",
/// "rawId",
/// "response",
/// "type"
/// ],
/// "properties": {
/// "authenticatorAttachment": {
/// "enum": [
/// "platform",
/// "cross-platform"
/// ]
/// },
/// "clientExtensionResults": {
/// "type": "object"
/// },
/// "id": {
/// "type": "string"
/// },
/// "rawId": {
/// "type": "string"
/// },
/// "response": {
/// "type": "object",
/// "required": [
/// "authenticatorData",
/// "clientDataJSON",
/// "signature"
/// ],
/// "properties": {
/// "authenticatorData": {
/// "type": "string"
/// },
/// "clientDataJSON": {
/// "type": "string"
/// },
/// "signature": {
/// "type": "string"
/// },
/// "userHandle": {
/// "type": [
/// "string",
/// "null"
/// ]
/// }
/// },
/// "additionalProperties": false
/// },
/// "type": {
/// "const": "public-key"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "assertionResponse"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AssertionResponse {
#[serde(
rename = "authenticatorAttachment",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub authenticator_attachment: ::std::option::Option<AssertionResponseAuthenticatorAttachment>,
#[serde(
rename = "clientExtensionResults",
default,
skip_serializing_if = "::serde_json::Map::is_empty"
)]
pub client_extension_results: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
pub id: ::std::string::String,
#[serde(rename = "rawId")]
pub raw_id: ::std::string::String,
pub response: AssertionResponseResponse,
#[serde(rename = "type")]
pub type_: ::serde_json::Value,
}
impl AssertionResponse {
pub fn builder() -> builder::AssertionResponse {
Default::default()
}
}
///`AssertionResponseAuthenticatorAttachment`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "enum": [
/// "platform",
/// "cross-platform"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum AssertionResponseAuthenticatorAttachment {
#[serde(rename = "platform")]
Platform,
#[serde(rename = "cross-platform")]
CrossPlatform,
}
impl ::std::fmt::Display for AssertionResponseAuthenticatorAttachment {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Platform => f.write_str("platform"),
Self::CrossPlatform => f.write_str("cross-platform"),
}
}
}
impl ::std::str::FromStr for AssertionResponseAuthenticatorAttachment {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"platform" => Ok(Self::Platform),
"cross-platform" => Ok(Self::CrossPlatform),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for AssertionResponseAuthenticatorAttachment {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for AssertionResponseAuthenticatorAttachment {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for AssertionResponseAuthenticatorAttachment {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///`AssertionResponseResponse`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "object",
/// "required": [
/// "authenticatorData",
/// "clientDataJSON",
/// "signature"
/// ],
/// "properties": {
/// "authenticatorData": {
/// "type": "string"
/// },
/// "clientDataJSON": {
/// "type": "string"
/// },
/// "signature": {
/// "type": "string"
/// },
/// "userHandle": {
/// "type": [
/// "string",
/// "null"
/// ]
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AssertionResponseResponse {
#[serde(rename = "authenticatorData")]
pub authenticator_data: ::std::string::String,
#[serde(rename = "clientDataJSON")]
pub client_data_json: ::std::string::String,
pub signature: ::std::string::String,
#[serde(
rename = "userHandle",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub user_handle: ::std::option::Option<::std::string::String>,
}
impl AssertionResponseResponse {
pub fn builder() -> builder::AssertionResponseResponse {
Default::default()
}
}
///The credential the client returns from `navigator.credentials.create`. Binary fields are base64url-encoded.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "AuthenticatorAttestationResponse (registration)",
/// "description": "The credential the client returns from `navigator.credentials.create`. Binary fields are base64url-encoded.",
/// "type": "object",
/// "required": [
/// "id",
/// "rawId",
/// "response",
/// "type"
/// ],
/// "properties": {
/// "authenticatorAttachment": {
/// "enum": [
/// "platform",
/// "cross-platform"
/// ]
/// },
/// "clientExtensionResults": {
/// "type": "object"
/// },
/// "id": {
/// "type": "string"
/// },
/// "rawId": {
/// "type": "string"
/// },
/// "response": {
/// "type": "object",
/// "required": [
/// "attestationObject",
/// "clientDataJSON"
/// ],
/// "properties": {
/// "attestationObject": {
/// "type": "string"
/// },
/// "clientDataJSON": {
/// "type": "string"
/// },
/// "transports": {
/// "type": "array",
/// "items": {
/// "type": "string"
/// }
/// }
/// },
/// "additionalProperties": false
/// },
/// "type": {
/// "const": "public-key"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "attestationResponse"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AttestationResponse {
#[serde(
rename = "authenticatorAttachment",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub authenticator_attachment: ::std::option::Option<AttestationResponseAuthenticatorAttachment>,
#[serde(
rename = "clientExtensionResults",
default,
skip_serializing_if = "::serde_json::Map::is_empty"
)]
pub client_extension_results: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
pub id: ::std::string::String,
#[serde(rename = "rawId")]
pub raw_id: ::std::string::String,
pub response: AttestationResponseResponse,
#[serde(rename = "type")]
pub type_: ::serde_json::Value,
}
impl AttestationResponse {
pub fn builder() -> builder::AttestationResponse {
Default::default()
}
}
///`AttestationResponseAuthenticatorAttachment`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "enum": [
/// "platform",
/// "cross-platform"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum AttestationResponseAuthenticatorAttachment {
#[serde(rename = "platform")]
Platform,
#[serde(rename = "cross-platform")]
CrossPlatform,
}
impl ::std::fmt::Display for AttestationResponseAuthenticatorAttachment {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Platform => f.write_str("platform"),
Self::CrossPlatform => f.write_str("cross-platform"),
}
}
}
impl ::std::str::FromStr for AttestationResponseAuthenticatorAttachment {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"platform" => Ok(Self::Platform),
"cross-platform" => Ok(Self::CrossPlatform),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for AttestationResponseAuthenticatorAttachment {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String>
for AttestationResponseAuthenticatorAttachment
{
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for AttestationResponseAuthenticatorAttachment {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///`AttestationResponseResponse`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "object",
/// "required": [
/// "attestationObject",
/// "clientDataJSON"
/// ],
/// "properties": {
/// "attestationObject": {
/// "type": "string"
/// },
/// "clientDataJSON": {
/// "type": "string"
/// },
/// "transports": {
/// "type": "array",
/// "items": {
/// "type": "string"
/// }
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AttestationResponseResponse {
#[serde(rename = "attestationObject")]
pub attestation_object: ::std::string::String,
#[serde(rename = "clientDataJSON")]
pub client_data_json: ::std::string::String,
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub transports: ::std::vec::Vec<::std::string::String>,
}
impl AttestationResponseResponse {
pub fn builder() -> builder::AttestationResponseResponse {
Default::default()
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Submit the WebAuthn attestation that completes a passkey-enrollment ceremony. On success the auth service binds the credential to the subject's VID.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2",
/// "title": "Payload",
/// "description": "Submit the WebAuthn attestation that completes a passkey-enrollment ceremony. On success the auth service binds the credential to the subject's VID.",
/// "type": "object",
/// "required": [
/// "credential",
/// "enrollmentId"
/// ],
/// "properties": {
/// "credential": {
/// "description": "AuthenticatorAttestationResponse as returned by `navigator.credentials.create`. Binary fields base64url-encoded.",
/// "$ref": "#/definitions/AttestationResponse"
/// },
/// "deviceLabel": {
/// "description": "Final operator-facing label for the credential. Overrides any label passed at start.",
/// "type": "string",
/// "maxLength": 256
/// },
/// "enrollmentId": {
/// "description": "The enrollmentId issued by the matching `auth/passkey/enroll/start` response. Echoed verbatim.",
/// "type": "string",
/// "minLength": 1
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "uvCredential": {
/// "description": "New in 0.2. AuthenticatorAssertionResponse over the uvOptions returned by start, proving a human with an already-enrolled authenticator authorized adding this one. REQUIRED whenever start returned uvOptions; omitted otherwise. A consumer that issued uvOptions MUST reject a finish that lacks this member — the re-authentication requirement is the consumer's, so treating a missing assertion as consent would let a producer decline it unilaterally.",
/// "$ref": "#/definitions/AssertionResponse"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
///AuthenticatorAttestationResponse as returned by `navigator.credentials.create`. Binary fields base64url-encoded.
pub credential: AttestationResponse,
///Final operator-facing label for the credential. Overrides any label passed at start.
#[serde(
rename = "deviceLabel",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub device_label: ::std::option::Option<PayloadDeviceLabel>,
///The enrollmentId issued by the matching `auth/passkey/enroll/start` response. Echoed verbatim.
#[serde(rename = "enrollmentId")]
pub enrollment_id: PayloadEnrollmentId,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///New in 0.2. AuthenticatorAssertionResponse over the uvOptions returned by start, proving a human with an already-enrolled authenticator authorized adding this one. REQUIRED whenever start returned uvOptions; omitted otherwise. A consumer that issued uvOptions MUST reject a finish that lacks this member — the re-authentication requirement is the consumer's, so treating a missing assertion as consent would let a producer decline it unilaterally.
#[serde(
rename = "uvCredential",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub uv_credential: ::std::option::Option<AssertionResponse>,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///Final operator-facing label for the credential. Overrides any label passed at start.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Final operator-facing label for the credential. Overrides any label passed at start.",
/// "type": "string",
/// "maxLength": 256
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadDeviceLabel(::std::string::String);
impl ::std::ops::Deref for PayloadDeviceLabel {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadDeviceLabel> for ::std::string::String {
fn from(value: PayloadDeviceLabel) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadDeviceLabel {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadDeviceLabel {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The enrollmentId issued by the matching `auth/passkey/enroll/start` response. Echoed verbatim.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The enrollmentId issued by the matching `auth/passkey/enroll/start` response. Echoed verbatim.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadEnrollmentId(::std::string::String);
impl ::std::ops::Deref for PayloadEnrollmentId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadEnrollmentId> for ::std::string::String {
fn from(value: PayloadEnrollmentId) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadEnrollmentId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadEnrollmentId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadEnrollmentId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadEnrollmentId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadEnrollmentId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Acknowledgement of the registered credential. Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "Acknowledgement of the registered credential. Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response.",
/// "type": "object",
/// "required": [
/// "credentialId",
/// "registeredAt",
/// "subject"
/// ],
/// "properties": {
/// "credentialId": {
/// "description": "base64url-encoded WebAuthn credential id, durable identifier for later management.",
/// "type": "string"
/// },
/// "deviceLabel": {
/// "description": "The label persisted with the credential.",
/// "type": "string",
/// "maxLength": 256
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "registeredAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "subject": {
/// "description": "The VID the credential is now bound to. Echoed for symmetry with finish-time error responses.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
///base64url-encoded WebAuthn credential id, durable identifier for later management.
#[serde(rename = "credentialId")]
pub credential_id: ::std::string::String,
///The label persisted with the credential.
#[serde(
rename = "deviceLabel",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub device_label: ::std::option::Option<ResponseDeviceLabel>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
#[serde(rename = "registeredAt")]
pub registered_at: ::chrono::DateTime<::chrono::offset::Utc>,
///The VID the credential is now bound to. Echoed for symmetry with finish-time error responses.
pub subject: ::std::string::String,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///The label persisted with the credential.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The label persisted with the credential.",
/// "type": "string",
/// "maxLength": 256
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseDeviceLabel(::std::string::String);
impl ::std::ops::Deref for ResponseDeviceLabel {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseDeviceLabel> for ::std::string::String {
fn from(value: ResponseDeviceLabel) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseDeviceLabel {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseDeviceLabel {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseDeviceLabel {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct AssertionResponse {
authenticator_attachment: ::std::result::Result<
::std::option::Option<super::AssertionResponseAuthenticatorAttachment>,
::std::string::String,
>,
client_extension_results: ::std::result::Result<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
::std::string::String,
>,
id: ::std::result::Result<::std::string::String, ::std::string::String>,
raw_id: ::std::result::Result<::std::string::String, ::std::string::String>,
response: ::std::result::Result<super::AssertionResponseResponse, ::std::string::String>,
type_: ::std::result::Result<::serde_json::Value, ::std::string::String>,
}
impl ::std::default::Default for AssertionResponse {
fn default() -> Self {
Self {
authenticator_attachment: Ok(Default::default()),
client_extension_results: Ok(Default::default()),
id: Err("no value supplied for id".to_string()),
raw_id: Err("no value supplied for raw_id".to_string()),
response: Err("no value supplied for response".to_string()),
type_: Err("no value supplied for type_".to_string()),
}
}
}
impl AssertionResponse {
pub fn authenticator_attachment<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<super::AssertionResponseAuthenticatorAttachment>,
>,
T::Error: ::std::fmt::Display,
{
self.authenticator_attachment = value.try_into().map_err(|e| {
format!("error converting supplied value for authenticator_attachment: {e}")
});
self
}
pub fn client_extension_results<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
>,
T::Error: ::std::fmt::Display,
{
self.client_extension_results = value.try_into().map_err(|e| {
format!("error converting supplied value for client_extension_results: {e}")
});
self
}
pub fn id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.id = value
.try_into()
.map_err(|e| format!("error converting supplied value for id: {e}"));
self
}
pub fn raw_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.raw_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for raw_id: {e}"));
self
}
pub fn response<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::AssertionResponseResponse>,
T::Error: ::std::fmt::Display,
{
self.response = value
.try_into()
.map_err(|e| format!("error converting supplied value for response: {e}"));
self
}
pub fn type_<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::serde_json::Value>,
T::Error: ::std::fmt::Display,
{
self.type_ = value
.try_into()
.map_err(|e| format!("error converting supplied value for type_: {e}"));
self
}
}
impl ::std::convert::TryFrom<AssertionResponse> for super::AssertionResponse {
type Error = super::error::ConversionError;
fn try_from(
value: AssertionResponse,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
authenticator_attachment: value.authenticator_attachment?,
client_extension_results: value.client_extension_results?,
id: value.id?,
raw_id: value.raw_id?,
response: value.response?,
type_: value.type_?,
})
}
}
impl ::std::convert::From<super::AssertionResponse> for AssertionResponse {
fn from(value: super::AssertionResponse) -> Self {
Self {
authenticator_attachment: Ok(value.authenticator_attachment),
client_extension_results: Ok(value.client_extension_results),
id: Ok(value.id),
raw_id: Ok(value.raw_id),
response: Ok(value.response),
type_: Ok(value.type_),
}
}
}
#[derive(Clone, Debug)]
pub struct AssertionResponseResponse {
authenticator_data: ::std::result::Result<::std::string::String, ::std::string::String>,
client_data_json: ::std::result::Result<::std::string::String, ::std::string::String>,
signature: ::std::result::Result<::std::string::String, ::std::string::String>,
user_handle: ::std::result::Result<
::std::option::Option<::std::string::String>,
::std::string::String,
>,
}
impl ::std::default::Default for AssertionResponseResponse {
fn default() -> Self {
Self {
authenticator_data: Err("no value supplied for authenticator_data".to_string()),
client_data_json: Err("no value supplied for client_data_json".to_string()),
signature: Err("no value supplied for signature".to_string()),
user_handle: Ok(Default::default()),
}
}
}
impl AssertionResponseResponse {
pub fn authenticator_data<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.authenticator_data = value.try_into().map_err(|e| {
format!("error converting supplied value for authenticator_data: {e}")
});
self
}
pub fn client_data_json<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.client_data_json = value
.try_into()
.map_err(|e| format!("error converting supplied value for client_data_json: {e}"));
self
}
pub fn signature<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.signature = value
.try_into()
.map_err(|e| format!("error converting supplied value for signature: {e}"));
self
}
pub fn user_handle<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.user_handle = value
.try_into()
.map_err(|e| format!("error converting supplied value for user_handle: {e}"));
self
}
}
impl ::std::convert::TryFrom<AssertionResponseResponse> for super::AssertionResponseResponse {
type Error = super::error::ConversionError;
fn try_from(
value: AssertionResponseResponse,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
authenticator_data: value.authenticator_data?,
client_data_json: value.client_data_json?,
signature: value.signature?,
user_handle: value.user_handle?,
})
}
}
impl ::std::convert::From<super::AssertionResponseResponse> for AssertionResponseResponse {
fn from(value: super::AssertionResponseResponse) -> Self {
Self {
authenticator_data: Ok(value.authenticator_data),
client_data_json: Ok(value.client_data_json),
signature: Ok(value.signature),
user_handle: Ok(value.user_handle),
}
}
}
#[derive(Clone, Debug)]
pub struct AttestationResponse {
authenticator_attachment: ::std::result::Result<
::std::option::Option<super::AttestationResponseAuthenticatorAttachment>,
::std::string::String,
>,
client_extension_results: ::std::result::Result<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
::std::string::String,
>,
id: ::std::result::Result<::std::string::String, ::std::string::String>,
raw_id: ::std::result::Result<::std::string::String, ::std::string::String>,
response: ::std::result::Result<super::AttestationResponseResponse, ::std::string::String>,
type_: ::std::result::Result<::serde_json::Value, ::std::string::String>,
}
impl ::std::default::Default for AttestationResponse {
fn default() -> Self {
Self {
authenticator_attachment: Ok(Default::default()),
client_extension_results: Ok(Default::default()),
id: Err("no value supplied for id".to_string()),
raw_id: Err("no value supplied for raw_id".to_string()),
response: Err("no value supplied for response".to_string()),
type_: Err("no value supplied for type_".to_string()),
}
}
}
impl AttestationResponse {
pub fn authenticator_attachment<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<super::AttestationResponseAuthenticatorAttachment>,
>,
T::Error: ::std::fmt::Display,
{
self.authenticator_attachment = value.try_into().map_err(|e| {
format!("error converting supplied value for authenticator_attachment: {e}")
});
self
}
pub fn client_extension_results<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
>,
T::Error: ::std::fmt::Display,
{
self.client_extension_results = value.try_into().map_err(|e| {
format!("error converting supplied value for client_extension_results: {e}")
});
self
}
pub fn id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.id = value
.try_into()
.map_err(|e| format!("error converting supplied value for id: {e}"));
self
}
pub fn raw_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.raw_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for raw_id: {e}"));
self
}
pub fn response<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::AttestationResponseResponse>,
T::Error: ::std::fmt::Display,
{
self.response = value
.try_into()
.map_err(|e| format!("error converting supplied value for response: {e}"));
self
}
pub fn type_<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::serde_json::Value>,
T::Error: ::std::fmt::Display,
{
self.type_ = value
.try_into()
.map_err(|e| format!("error converting supplied value for type_: {e}"));
self
}
}
impl ::std::convert::TryFrom<AttestationResponse> for super::AttestationResponse {
type Error = super::error::ConversionError;
fn try_from(
value: AttestationResponse,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
authenticator_attachment: value.authenticator_attachment?,
client_extension_results: value.client_extension_results?,
id: value.id?,
raw_id: value.raw_id?,
response: value.response?,
type_: value.type_?,
})
}
}
impl ::std::convert::From<super::AttestationResponse> for AttestationResponse {
fn from(value: super::AttestationResponse) -> Self {
Self {
authenticator_attachment: Ok(value.authenticator_attachment),
client_extension_results: Ok(value.client_extension_results),
id: Ok(value.id),
raw_id: Ok(value.raw_id),
response: Ok(value.response),
type_: Ok(value.type_),
}
}
}
#[derive(Clone, Debug)]
pub struct AttestationResponseResponse {
attestation_object: ::std::result::Result<::std::string::String, ::std::string::String>,
client_data_json: ::std::result::Result<::std::string::String, ::std::string::String>,
transports:
::std::result::Result<::std::vec::Vec<::std::string::String>, ::std::string::String>,
}
impl ::std::default::Default for AttestationResponseResponse {
fn default() -> Self {
Self {
attestation_object: Err("no value supplied for attestation_object".to_string()),
client_data_json: Err("no value supplied for client_data_json".to_string()),
transports: Ok(Default::default()),
}
}
}
impl AttestationResponseResponse {
pub fn attestation_object<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.attestation_object = value.try_into().map_err(|e| {
format!("error converting supplied value for attestation_object: {e}")
});
self
}
pub fn client_data_json<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.client_data_json = value
.try_into()
.map_err(|e| format!("error converting supplied value for client_data_json: {e}"));
self
}
pub fn transports<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.transports = value
.try_into()
.map_err(|e| format!("error converting supplied value for transports: {e}"));
self
}
}
impl ::std::convert::TryFrom<AttestationResponseResponse> for super::AttestationResponseResponse {
type Error = super::error::ConversionError;
fn try_from(
value: AttestationResponseResponse,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
attestation_object: value.attestation_object?,
client_data_json: value.client_data_json?,
transports: value.transports?,
})
}
}
impl ::std::convert::From<super::AttestationResponseResponse> for AttestationResponseResponse {
fn from(value: super::AttestationResponseResponse) -> Self {
Self {
attestation_object: Ok(value.attestation_object),
client_data_json: Ok(value.client_data_json),
transports: Ok(value.transports),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
credential: ::std::result::Result<super::AttestationResponse, ::std::string::String>,
device_label: ::std::result::Result<
::std::option::Option<super::PayloadDeviceLabel>,
::std::string::String,
>,
enrollment_id: ::std::result::Result<super::PayloadEnrollmentId, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
uv_credential: ::std::result::Result<
::std::option::Option<super::AssertionResponse>,
::std::string::String,
>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
credential: Err("no value supplied for credential".to_string()),
device_label: Ok(Default::default()),
enrollment_id: Err("no value supplied for enrollment_id".to_string()),
ext: Ok(Default::default()),
uv_credential: Ok(Default::default()),
}
}
}
impl Payload {
pub fn credential<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::AttestationResponse>,
T::Error: ::std::fmt::Display,
{
self.credential = value
.try_into()
.map_err(|e| format!("error converting supplied value for credential: {e}"));
self
}
pub fn device_label<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadDeviceLabel>>,
T::Error: ::std::fmt::Display,
{
self.device_label = value
.try_into()
.map_err(|e| format!("error converting supplied value for device_label: {e}"));
self
}
pub fn enrollment_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadEnrollmentId>,
T::Error: ::std::fmt::Display,
{
self.enrollment_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for enrollment_id: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn uv_credential<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::AssertionResponse>>,
T::Error: ::std::fmt::Display,
{
self.uv_credential = value
.try_into()
.map_err(|e| format!("error converting supplied value for uv_credential: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
credential: value.credential?,
device_label: value.device_label?,
enrollment_id: value.enrollment_id?,
ext: value.ext?,
uv_credential: value.uv_credential?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
credential: Ok(value.credential),
device_label: Ok(value.device_label),
enrollment_id: Ok(value.enrollment_id),
ext: Ok(value.ext),
uv_credential: Ok(value.uv_credential),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
credential_id: ::std::result::Result<::std::string::String, ::std::string::String>,
device_label: ::std::result::Result<
::std::option::Option<super::ResponseDeviceLabel>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
registered_at:
::std::result::Result<::chrono::DateTime<::chrono::offset::Utc>, ::std::string::String>,
subject: ::std::result::Result<::std::string::String, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
credential_id: Err("no value supplied for credential_id".to_string()),
device_label: Ok(Default::default()),
ext: Ok(Default::default()),
registered_at: Err("no value supplied for registered_at".to_string()),
subject: Err("no value supplied for subject".to_string()),
}
}
}
impl Response {
pub fn credential_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.credential_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for credential_id: {e}"));
self
}
pub fn device_label<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ResponseDeviceLabel>>,
T::Error: ::std::fmt::Display,
{
self.device_label = value
.try_into()
.map_err(|e| format!("error converting supplied value for device_label: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn registered_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::chrono::DateTime<::chrono::offset::Utc>>,
T::Error: ::std::fmt::Display,
{
self.registered_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for registered_at: {e}"));
self
}
pub fn subject<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.subject = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
credential_id: value.credential_id?,
device_label: value.device_label?,
ext: value.ext?,
registered_at: value.registered_at?,
subject: value.subject?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
credential_id: Ok(value.credential_id),
device_label: Ok(value.device_label),
ext: Ok(value.ext),
registered_at: Ok(value.registered_at),
subject: Ok(value.subject),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AssertionResponse\": {\n \"$anchor\": \"assertionResponse\",\n \"additionalProperties\": false,\n \"description\": \"The credential the client returns from `navigator.credentials.get`. Binary fields are base64url-encoded.\",\n \"properties\": {\n \"authenticatorAttachment\": {\n \"enum\": [\n \"platform\",\n \"cross-platform\"\n ]\n },\n \"clientExtensionResults\": {\n \"type\": \"object\"\n },\n \"id\": {\n \"type\": \"string\"\n },\n \"rawId\": {\n \"type\": \"string\"\n },\n \"response\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"authenticatorData\": {\n \"type\": \"string\"\n },\n \"clientDataJSON\": {\n \"type\": \"string\"\n },\n \"signature\": {\n \"type\": \"string\"\n },\n \"userHandle\": {\n \"type\": [\n \"string\",\n \"null\"\n ]\n }\n },\n \"required\": [\n \"clientDataJSON\",\n \"authenticatorData\",\n \"signature\"\n ],\n \"type\": \"object\"\n },\n \"type\": {\n \"const\": \"public-key\"\n }\n },\n \"required\": [\n \"id\",\n \"rawId\",\n \"type\",\n \"response\"\n ],\n \"title\": \"AuthenticatorAssertionResponse (login)\",\n \"type\": \"object\"\n },\n \"AttestationResponse\": {\n \"$anchor\": \"attestationResponse\",\n \"additionalProperties\": false,\n \"description\": \"The credential the client returns from `navigator.credentials.create`. Binary fields are base64url-encoded.\",\n \"properties\": {\n \"authenticatorAttachment\": {\n \"enum\": [\n \"platform\",\n \"cross-platform\"\n ]\n },\n \"clientExtensionResults\": {\n \"type\": \"object\"\n },\n \"id\": {\n \"type\": \"string\"\n },\n \"rawId\": {\n \"type\": \"string\"\n },\n \"response\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"attestationObject\": {\n \"type\": \"string\"\n },\n \"clientDataJSON\": {\n \"type\": \"string\"\n },\n \"transports\": {\n \"items\": {\n \"type\": \"string\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"clientDataJSON\",\n \"attestationObject\"\n ],\n \"type\": \"object\"\n },\n \"type\": {\n \"const\": \"public-key\"\n }\n },\n \"required\": [\n \"id\",\n \"rawId\",\n \"type\",\n \"response\"\n ],\n \"title\": \"AuthenticatorAttestationResponse (registration)\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Acknowledgement of the registered credential. Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response.\",\n \"properties\": {\n \"credentialId\": {\n \"description\": \"base64url-encoded WebAuthn credential id, durable identifier for later management.\",\n \"type\": \"string\"\n },\n \"deviceLabel\": {\n \"description\": \"The label persisted with the credential.\",\n \"maxLength\": 256,\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"registeredAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"subject\": {\n \"description\": \"The VID the credential is now bound to. Echoed for symmetry with finish-time error responses.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"credentialId\",\n \"subject\",\n \"registeredAt\"\n ],\n \"title\": \"Auth Passkey Enroll Finish — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Submit the WebAuthn attestation that completes a passkey-enrollment ceremony. On success the auth service binds the credential to the subject's VID.\",\n \"properties\": {\n \"credential\": {\n \"$ref\": \"#/$defs/AttestationResponse\",\n \"description\": \"AuthenticatorAttestationResponse as returned by `navigator.credentials.create`. Binary fields base64url-encoded.\"\n },\n \"deviceLabel\": {\n \"description\": \"Final operator-facing label for the credential. Overrides any label passed at start.\",\n \"maxLength\": 256,\n \"type\": \"string\"\n },\n \"enrollmentId\": {\n \"description\": \"The enrollmentId issued by the matching `auth/passkey/enroll/start` response. Echoed verbatim.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"uvCredential\": {\n \"$ref\": \"#/$defs/AssertionResponse\",\n \"description\": \"New in 0.2. AuthenticatorAssertionResponse over the uvOptions returned by start, proving a human with an already-enrolled authenticator authorized adding this one. REQUIRED whenever start returned uvOptions; omitted otherwise. A consumer that issued uvOptions MUST reject a finish that lacks this member — the re-authentication requirement is the consumer's, so treating a missing assertion as consent would let a producer decline it unilaterally.\"\n }\n },\n \"required\": [\n \"enrollmentId\",\n \"credential\"\n ],\n \"title\": \"Auth — Passkey Enroll (finish)\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str =
"https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AssertionResponse\": {\n \"$anchor\": \"assertionResponse\",\n \"additionalProperties\": false,\n \"description\": \"The credential the client returns from `navigator.credentials.get`. Binary fields are base64url-encoded.\",\n \"properties\": {\n \"authenticatorAttachment\": {\n \"enum\": [\n \"platform\",\n \"cross-platform\"\n ]\n },\n \"clientExtensionResults\": {\n \"type\": \"object\"\n },\n \"id\": {\n \"type\": \"string\"\n },\n \"rawId\": {\n \"type\": \"string\"\n },\n \"response\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"authenticatorData\": {\n \"type\": \"string\"\n },\n \"clientDataJSON\": {\n \"type\": \"string\"\n },\n \"signature\": {\n \"type\": \"string\"\n },\n \"userHandle\": {\n \"type\": [\n \"string\",\n \"null\"\n ]\n }\n },\n \"required\": [\n \"clientDataJSON\",\n \"authenticatorData\",\n \"signature\"\n ],\n \"type\": \"object\"\n },\n \"type\": {\n \"const\": \"public-key\"\n }\n },\n \"required\": [\n \"id\",\n \"rawId\",\n \"type\",\n \"response\"\n ],\n \"title\": \"AuthenticatorAssertionResponse (login)\",\n \"type\": \"object\"\n },\n \"AttestationResponse\": {\n \"$anchor\": \"attestationResponse\",\n \"additionalProperties\": false,\n \"description\": \"The credential the client returns from `navigator.credentials.create`. Binary fields are base64url-encoded.\",\n \"properties\": {\n \"authenticatorAttachment\": {\n \"enum\": [\n \"platform\",\n \"cross-platform\"\n ]\n },\n \"clientExtensionResults\": {\n \"type\": \"object\"\n },\n \"id\": {\n \"type\": \"string\"\n },\n \"rawId\": {\n \"type\": \"string\"\n },\n \"response\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"attestationObject\": {\n \"type\": \"string\"\n },\n \"clientDataJSON\": {\n \"type\": \"string\"\n },\n \"transports\": {\n \"items\": {\n \"type\": \"string\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"clientDataJSON\",\n \"attestationObject\"\n ],\n \"type\": \"object\"\n },\n \"type\": {\n \"const\": \"public-key\"\n }\n },\n \"required\": [\n \"id\",\n \"rawId\",\n \"type\",\n \"response\"\n ],\n \"title\": \"AuthenticatorAttestationResponse (registration)\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Acknowledgement of the registered credential. Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response.\",\n \"properties\": {\n \"credentialId\": {\n \"description\": \"base64url-encoded WebAuthn credential id, durable identifier for later management.\",\n \"type\": \"string\"\n },\n \"deviceLabel\": {\n \"description\": \"The label persisted with the credential.\",\n \"maxLength\": 256,\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"registeredAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"subject\": {\n \"description\": \"The VID the credential is now bound to. Echoed for symmetry with finish-time error responses.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"credentialId\",\n \"subject\",\n \"registeredAt\"\n ],\n \"title\": \"Auth Passkey Enroll Finish — response payload\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::ENROLLMENT_NOT_FOUND,
error_codes::ENROLLMENT_EXPIRED,
error_codes::SUBJECT_MISMATCH,
error_codes::ATTESTATION_INVALID,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `auth/passkey/enroll/finish:enrollmentNotFound`
///
/// The `enrollmentId` does not refer to any active enrollment ceremony.
///
/// Declared `retryable: false`.
pub const ENROLLMENT_NOT_FOUND: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/passkey/enroll/finish:enrollmentNotFound",
retryable: false,
};
/// `auth/passkey/enroll/finish:enrollmentExpired`
///
/// The enrollment's start-time expiry has elapsed.
///
/// Declared `retryable: true`.
pub const ENROLLMENT_EXPIRED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/passkey/enroll/finish:enrollmentExpired",
retryable: true,
};
/// `auth/passkey/enroll/finish:subjectMismatch`
///
/// The producer's VID differs from the VID the start ceremony was issued to.
///
/// Declared `retryable: false`.
pub const SUBJECT_MISMATCH: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/passkey/enroll/finish:subjectMismatch",
retryable: false,
};
/// `auth/passkey/enroll/finish:attestationInvalid`
///
/// The WebAuthn attestation failed verification (challenge mismatch, signature failure, unsupported algorithm, etc.). `details.reason` carries a machine-readable hint.
///
/// Declared `retryable: false`.
pub const ATTESTATION_INVALID: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/passkey/enroll/finish:attestationInvalid",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"77777777-aaaa-bbbb-cccc-888888888888\",\n \"type\": \"https://trusttasks.org/spec/auth/passkey/enroll/finish/0.2#response\",\n \"threadId\": \"55555555-eeee-ffff-aaaa-666666666666\",\n \"issuer\": \"did:web:auth.example\",\n \"recipient\": \"did:web:alice.example\",\n \"issuedAt\": \"2026-05-23T12:01:01Z\",\n \"payload\": {\n \"credentialId\": \"Y3JlZF8xYTJiM2M\",\n \"subject\": \"did:web:alice.example\",\n \"deviceLabel\": \"Alice's MacBook Pro\",\n \"registeredAt\": \"2026-05-23T12:01:01Z\"\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Missing required enrollmentId.",
"{\n \"credential\": {\n \"id\": \"x\",\n \"rawId\": \"x\",\n \"response\": {\n \"attestationObject\": \"x\",\n \"clientDataJSON\": \"x\"\n },\n \"type\": \"public-key\"\n }\n}",
),
(
"Missing required credential.",
"{\n \"enrollmentId\": \"enr_1a2b3c4d5e6f7890\"\n}",
),
(
"credential.type is not the WebAuthn-required const.",
"{\n \"credential\": {\n \"id\": \"x\",\n \"rawId\": \"x\",\n \"response\": {\n \"attestationObject\": \"x\",\n \"clientDataJSON\": \"x\"\n },\n \"type\": \"totp\"\n },\n \"enrollmentId\": \"enr_1a2b3c4d5e6f7890\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}