//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `rooms/records/put`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///What a party presents to act on a room. Carries the whole authority chain: a host MUST NOT dereference an authority credential's `parent` to fetch a link it was not given. Resolving over the network would make verification depend on availability, turn every identifier into a request the host can be induced to make against an address the holder chooses, and signal credential use to whoever hosts the identifier. A host MUST bind the presenter to the chain's leaf. A chain that verifies is evidence that authority was conferred on somebody; it is not evidence that the party presenting it is that somebody. The leaf's subject MUST equal the party the host authenticated for this request — an identity the transport established or a document `proof` proved, never one named in a payload. A host that omits this check authorizes every captured presentation, and the omission is silent, because the chain still verifies.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "AuthorityPresentation",
/// "description": "What a party presents to act on a room. Carries the whole authority chain: a host MUST NOT dereference an authority credential's `parent` to fetch a link it was not given. Resolving over the network would make verification depend on availability, turn every identifier into a request the host can be induced to make against an address the holder chooses, and signal credential use to whoever hosts the identifier. A host MUST bind the presenter to the chain's leaf. A chain that verifies is evidence that authority was conferred on somebody; it is not evidence that the party presenting it is that somebody. The leaf's subject MUST equal the party the host authenticated for this request — an identity the transport established or a document `proof` proved, never one named in a payload. A host that omits this check authorizes every captured presentation, and the omission is silent, because the chain still verifies.",
/// "type": "object",
/// "required": [
/// "authority",
/// "membership"
/// ],
/// "properties": {
/// "authority": {
/// "description": "The authority chain, LEAF FIRST: the first element is the credential being relied on and the last MUST be one issued by the room itself. Every link the presenter relies on is present, because the host will not fetch one. Capped at 8: verification is linear in chain length and runs on every operation, so an unbounded chain is a denial-of-service surface against the host. The known uses need 2 to 3 — a person attenuating to an agent, and that agent to a sub-agent.",
/// "type": "array",
/// "items": {
/// "type": "string"
/// },
/// "maxItems": 8,
/// "minItems": 1
/// },
/// "membership": {
/// "description": "The presenter's membership credential for this room, or — on a `private` room — a zero-knowledge presentation of it. Serialized per the governing profile.",
/// "type": "string"
/// },
/// "subjectBinding": {
/// "description": "REQUIRED on a `private` room, where the subject identifier is withheld: a proof that the membership credential and the authority chain's leaf describe the SAME subject. Without it two parties pool credentials — one contributes membership, the other authority — and the combination verifies as a single party holding both. A host MUST refuse a private-room presentation that omits this.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AuthorityPresentation {
///The authority chain, LEAF FIRST: the first element is the credential being relied on and the last MUST be one issued by the room itself. Every link the presenter relies on is present, because the host will not fetch one. Capped at 8: verification is linear in chain length and runs on every operation, so an unbounded chain is a denial-of-service surface against the host. The known uses need 2 to 3 — a person attenuating to an agent, and that agent to a sub-agent.
pub authority: ::std::vec::Vec<::std::string::String>,
///The presenter's membership credential for this room, or — on a `private` room — a zero-knowledge presentation of it. Serialized per the governing profile.
pub membership: ::std::string::String,
///REQUIRED on a `private` room, where the subject identifier is withheld: a proof that the membership credential and the authority chain's leaf describe the SAME subject. Without it two parties pool credentials — one contributes membership, the other authority — and the combination verifies as a single party holding both. A host MUST refuse a private-room presentation that omits this.
#[serde(
rename = "subjectBinding",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub subject_binding: ::std::option::Option<::std::string::String>,
}
impl AuthorityPresentation {
pub fn builder() -> builder::AuthorityPresentation {
Default::default()
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`Payload`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/rooms/records/put/0.1",
/// "title": "Payload",
/// "type": "object",
/// "required": [
/// "key",
/// "presentation",
/// "roomId"
/// ],
/// "properties": {
/// "cleartext": {
/// "description": "REQUIRED on an `open` room, where the host reads records and can therefore search them. Mutually exclusive with `sealed`.",
/// "type": "object",
/// "required": [
/// "body"
/// ],
/// "properties": {
/// "body": {
/// "type": "string",
/// "maxLength": 1048576
/// },
/// "description": {
/// "type": "string",
/// "maxLength": 2048
/// },
/// "tags": {
/// "type": "array",
/// "items": {
/// "type": "string",
/// "maxLength": 64
/// },
/// "maxItems": 32
/// },
/// "title": {
/// "type": "string",
/// "maxLength": 512
/// }
/// },
/// "additionalProperties": false
/// },
/// "expectedVersion": {
/// "description": "Optional precondition. Omit to overwrite unconditionally; `0` means create-only and fails if the key exists. On mismatch the host returns `rooms/records/put:versionConflict` CARRYING THE CURRENT VERSION AND RECORD — a bare rejection would force a re-read, and between rejection and re-read the record can change again, so the pattern has no fixed point under contention.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "key": {
/// "description": "The record's key within the room. MUST be opaque on an `attributed` or `private` room; see RecordMetadata.key.",
/// "type": "string",
/// "maxLength": 512
/// },
/// "presentation": {
/// "description": "Must confer the `write` action at this room's scope.",
/// "$ref": "#/definitions/AuthorityPresentation"
/// },
/// "roomId": {
/// "description": "The room's identifier. A host verifies the presentation against credentials issued by this identifier, never against a member list of its own — which is what lets a room move hosts without reissuing a credential.",
/// "type": "string"
/// },
/// "sealed": {
/// "description": "REQUIRED on an `attributed` or `private` room. Mutually exclusive with `cleartext`.",
/// "$ref": "#/definitions/SealedRecord"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub cleartext: ::std::option::Option<PayloadCleartext>,
///Optional precondition. Omit to overwrite unconditionally; `0` means create-only and fails if the key exists. On mismatch the host returns `rooms/records/put:versionConflict` CARRYING THE CURRENT VERSION AND RECORD — a bare rejection would force a re-read, and between rejection and re-read the record can change again, so the pattern has no fixed point under contention.
#[serde(
rename = "expectedVersion",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub expected_version: ::std::option::Option<u64>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The record's key within the room. MUST be opaque on an `attributed` or `private` room; see RecordMetadata.key.
pub key: PayloadKey,
///Must confer the `write` action at this room's scope.
pub presentation: AuthorityPresentation,
///The room's identifier. A host verifies the presentation against credentials issued by this identifier, never against a member list of its own — which is what lets a room move hosts without reissuing a credential.
#[serde(rename = "roomId")]
pub room_id: ::std::string::String,
///REQUIRED on an `attributed` or `private` room. Mutually exclusive with `cleartext`.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub sealed: ::std::option::Option<SealedRecord>,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///REQUIRED on an `open` room, where the host reads records and can therefore search them. Mutually exclusive with `sealed`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "REQUIRED on an `open` room, where the host reads records and can therefore search them. Mutually exclusive with `sealed`.",
/// "type": "object",
/// "required": [
/// "body"
/// ],
/// "properties": {
/// "body": {
/// "type": "string",
/// "maxLength": 1048576
/// },
/// "description": {
/// "type": "string",
/// "maxLength": 2048
/// },
/// "tags": {
/// "type": "array",
/// "items": {
/// "type": "string",
/// "maxLength": 64
/// },
/// "maxItems": 32
/// },
/// "title": {
/// "type": "string",
/// "maxLength": 512
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct PayloadCleartext {
pub body: PayloadCleartextBody,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub description: ::std::option::Option<PayloadCleartextDescription>,
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub tags: ::std::vec::Vec<PayloadCleartextTagsItem>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub title: ::std::option::Option<PayloadCleartextTitle>,
}
impl PayloadCleartext {
pub fn builder() -> builder::PayloadCleartext {
Default::default()
}
}
///`PayloadCleartextBody`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "maxLength": 1048576
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadCleartextBody(::std::string::String);
impl ::std::ops::Deref for PayloadCleartextBody {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadCleartextBody> for ::std::string::String {
fn from(value: PayloadCleartextBody) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadCleartextBody {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 1048576usize {
return Err("longer than 1048576 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadCleartextBody {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadCleartextBody {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadCleartextBody {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadCleartextBody {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`PayloadCleartextDescription`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "maxLength": 2048
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadCleartextDescription(::std::string::String);
impl ::std::ops::Deref for PayloadCleartextDescription {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadCleartextDescription> for ::std::string::String {
fn from(value: PayloadCleartextDescription) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadCleartextDescription {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadCleartextDescription {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadCleartextDescription {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadCleartextDescription {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadCleartextDescription {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`PayloadCleartextTagsItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "maxLength": 64
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadCleartextTagsItem(::std::string::String);
impl ::std::ops::Deref for PayloadCleartextTagsItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadCleartextTagsItem> for ::std::string::String {
fn from(value: PayloadCleartextTagsItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadCleartextTagsItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 64usize {
return Err("longer than 64 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadCleartextTagsItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadCleartextTagsItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadCleartextTagsItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadCleartextTagsItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`PayloadCleartextTitle`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "maxLength": 512
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadCleartextTitle(::std::string::String);
impl ::std::ops::Deref for PayloadCleartextTitle {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadCleartextTitle> for ::std::string::String {
fn from(value: PayloadCleartextTitle) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadCleartextTitle {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 512usize {
return Err("longer than 512 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadCleartextTitle {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadCleartextTitle {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadCleartextTitle {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadCleartextTitle {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The record's key within the room. MUST be opaque on an `attributed` or `private` room; see RecordMetadata.key.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The record's key within the room. MUST be opaque on an `attributed` or `private` room; see RecordMetadata.key.",
/// "type": "string",
/// "maxLength": 512
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadKey(::std::string::String);
impl ::std::ops::Deref for PayloadKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadKey> for ::std::string::String {
fn from(value: PayloadKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 512usize {
return Err("longer than 512 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Success response to rooms/records/put. Type https://trusttasks.org/spec/rooms/records/put/0.1#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "Success response to rooms/records/put. Type https://trusttasks.org/spec/rooms/records/put/0.1#response.",
/// "type": "object",
/// "required": [
/// "key",
/// "version"
/// ],
/// "properties": {
/// "epoch": {
/// "description": "The epoch the record was stored under.",
/// "type": "integer",
/// "minimum": 1.0
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "key": {
/// "description": "The stored record's key.",
/// "type": "string"
/// },
/// "version": {
/// "description": "The version assigned, monotonic per room.",
/// "type": "integer",
/// "minimum": 1.0
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
///The epoch the record was stored under.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub epoch: ::std::option::Option<::std::num::NonZeroU64>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The stored record's key.
pub key: ::std::string::String,
///The version assigned, monotonic per room.
pub version: ::std::num::NonZeroU64,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///A record as a host stores it on an `attributed` or `private` room. Title, description, body, author and tags are sealed together in one blob rather than separately: splitting them would let a host learn the shape of the material from ciphertext lengths, for no benefit, since a reader decrypts the whole record either way.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "SealedRecord",
/// "description": "A record as a host stores it on an `attributed` or `private` room. Title, description, body, author and tags are sealed together in one blob rather than separately: splitting them would let a host learn the shape of the material from ciphertext lengths, for no benefit, since a reader decrypts the whole record either way.",
/// "type": "object",
/// "required": [
/// "ciphertext",
/// "epoch",
/// "nonce"
/// ],
/// "properties": {
/// "ciphertext": {
/// "description": "The sealed record, base64url. Bound by AEAD associated data to `roomId`, `key`, `version` and `epoch`, so a host that relocates it to another key, version, epoch or room produces a mismatch and the open fails. The record cannot be moved undetected even though the host holds every byte of it.",
/// "type": "string"
/// },
/// "epoch": {
/// "description": "The key epoch this record was sealed under. Cleartext because the host must serve the right ciphertext, and bound into the associated data so that relabelling it fails authentication rather than causing a reader to try the wrong key.",
/// "type": "integer",
/// "minimum": 1.0
/// },
/// "nonce": {
/// "description": "AEAD nonce, base64url.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct SealedRecord {
///The sealed record, base64url. Bound by AEAD associated data to `roomId`, `key`, `version` and `epoch`, so a host that relocates it to another key, version, epoch or room produces a mismatch and the open fails. The record cannot be moved undetected even though the host holds every byte of it.
pub ciphertext: ::std::string::String,
///The key epoch this record was sealed under. Cleartext because the host must serve the right ciphertext, and bound into the associated data so that relabelling it fails authentication rather than causing a reader to try the wrong key.
pub epoch: ::std::num::NonZeroU64,
///AEAD nonce, base64url.
pub nonce: ::std::string::String,
}
impl SealedRecord {
pub fn builder() -> builder::SealedRecord {
Default::default()
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct AuthorityPresentation {
authority:
::std::result::Result<::std::vec::Vec<::std::string::String>, ::std::string::String>,
membership: ::std::result::Result<::std::string::String, ::std::string::String>,
subject_binding: ::std::result::Result<
::std::option::Option<::std::string::String>,
::std::string::String,
>,
}
impl ::std::default::Default for AuthorityPresentation {
fn default() -> Self {
Self {
authority: Err("no value supplied for authority".to_string()),
membership: Err("no value supplied for membership".to_string()),
subject_binding: Ok(Default::default()),
}
}
}
impl AuthorityPresentation {
pub fn authority<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.authority = value
.try_into()
.map_err(|e| format!("error converting supplied value for authority: {e}"));
self
}
pub fn membership<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.membership = value
.try_into()
.map_err(|e| format!("error converting supplied value for membership: {e}"));
self
}
pub fn subject_binding<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.subject_binding = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject_binding: {e}"));
self
}
}
impl ::std::convert::TryFrom<AuthorityPresentation> for super::AuthorityPresentation {
type Error = super::error::ConversionError;
fn try_from(
value: AuthorityPresentation,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
authority: value.authority?,
membership: value.membership?,
subject_binding: value.subject_binding?,
})
}
}
impl ::std::convert::From<super::AuthorityPresentation> for AuthorityPresentation {
fn from(value: super::AuthorityPresentation) -> Self {
Self {
authority: Ok(value.authority),
membership: Ok(value.membership),
subject_binding: Ok(value.subject_binding),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
cleartext: ::std::result::Result<
::std::option::Option<super::PayloadCleartext>,
::std::string::String,
>,
expected_version: ::std::result::Result<::std::option::Option<u64>, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
key: ::std::result::Result<super::PayloadKey, ::std::string::String>,
presentation: ::std::result::Result<super::AuthorityPresentation, ::std::string::String>,
room_id: ::std::result::Result<::std::string::String, ::std::string::String>,
sealed: ::std::result::Result<
::std::option::Option<super::SealedRecord>,
::std::string::String,
>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
cleartext: Ok(Default::default()),
expected_version: Ok(Default::default()),
ext: Ok(Default::default()),
key: Err("no value supplied for key".to_string()),
presentation: Err("no value supplied for presentation".to_string()),
room_id: Err("no value supplied for room_id".to_string()),
sealed: Ok(Default::default()),
}
}
}
impl Payload {
pub fn cleartext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadCleartext>>,
T::Error: ::std::fmt::Display,
{
self.cleartext = value
.try_into()
.map_err(|e| format!("error converting supplied value for cleartext: {e}"));
self
}
pub fn expected_version<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<u64>>,
T::Error: ::std::fmt::Display,
{
self.expected_version = value
.try_into()
.map_err(|e| format!("error converting supplied value for expected_version: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn key<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadKey>,
T::Error: ::std::fmt::Display,
{
self.key = value
.try_into()
.map_err(|e| format!("error converting supplied value for key: {e}"));
self
}
pub fn presentation<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::AuthorityPresentation>,
T::Error: ::std::fmt::Display,
{
self.presentation = value
.try_into()
.map_err(|e| format!("error converting supplied value for presentation: {e}"));
self
}
pub fn room_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.room_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for room_id: {e}"));
self
}
pub fn sealed<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::SealedRecord>>,
T::Error: ::std::fmt::Display,
{
self.sealed = value
.try_into()
.map_err(|e| format!("error converting supplied value for sealed: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
cleartext: value.cleartext?,
expected_version: value.expected_version?,
ext: value.ext?,
key: value.key?,
presentation: value.presentation?,
room_id: value.room_id?,
sealed: value.sealed?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
cleartext: Ok(value.cleartext),
expected_version: Ok(value.expected_version),
ext: Ok(value.ext),
key: Ok(value.key),
presentation: Ok(value.presentation),
room_id: Ok(value.room_id),
sealed: Ok(value.sealed),
}
}
}
#[derive(Clone, Debug)]
pub struct PayloadCleartext {
body: ::std::result::Result<super::PayloadCleartextBody, ::std::string::String>,
description: ::std::result::Result<
::std::option::Option<super::PayloadCleartextDescription>,
::std::string::String,
>,
tags: ::std::result::Result<
::std::vec::Vec<super::PayloadCleartextTagsItem>,
::std::string::String,
>,
title: ::std::result::Result<
::std::option::Option<super::PayloadCleartextTitle>,
::std::string::String,
>,
}
impl ::std::default::Default for PayloadCleartext {
fn default() -> Self {
Self {
body: Err("no value supplied for body".to_string()),
description: Ok(Default::default()),
tags: Ok(Default::default()),
title: Ok(Default::default()),
}
}
}
impl PayloadCleartext {
pub fn body<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadCleartextBody>,
T::Error: ::std::fmt::Display,
{
self.body = value
.try_into()
.map_err(|e| format!("error converting supplied value for body: {e}"));
self
}
pub fn description<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadCleartextDescription>>,
T::Error: ::std::fmt::Display,
{
self.description = value
.try_into()
.map_err(|e| format!("error converting supplied value for description: {e}"));
self
}
pub fn tags<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::PayloadCleartextTagsItem>>,
T::Error: ::std::fmt::Display,
{
self.tags = value
.try_into()
.map_err(|e| format!("error converting supplied value for tags: {e}"));
self
}
pub fn title<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadCleartextTitle>>,
T::Error: ::std::fmt::Display,
{
self.title = value
.try_into()
.map_err(|e| format!("error converting supplied value for title: {e}"));
self
}
}
impl ::std::convert::TryFrom<PayloadCleartext> for super::PayloadCleartext {
type Error = super::error::ConversionError;
fn try_from(
value: PayloadCleartext,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
body: value.body?,
description: value.description?,
tags: value.tags?,
title: value.title?,
})
}
}
impl ::std::convert::From<super::PayloadCleartext> for PayloadCleartext {
fn from(value: super::PayloadCleartext) -> Self {
Self {
body: Ok(value.body),
description: Ok(value.description),
tags: Ok(value.tags),
title: Ok(value.title),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
epoch: ::std::result::Result<
::std::option::Option<::std::num::NonZeroU64>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
key: ::std::result::Result<::std::string::String, ::std::string::String>,
version: ::std::result::Result<::std::num::NonZeroU64, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
epoch: Ok(Default::default()),
ext: Ok(Default::default()),
key: Err("no value supplied for key".to_string()),
version: Err("no value supplied for version".to_string()),
}
}
}
impl Response {
pub fn epoch<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::num::NonZeroU64>>,
T::Error: ::std::fmt::Display,
{
self.epoch = value
.try_into()
.map_err(|e| format!("error converting supplied value for epoch: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn key<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.key = value
.try_into()
.map_err(|e| format!("error converting supplied value for key: {e}"));
self
}
pub fn version<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::num::NonZeroU64>,
T::Error: ::std::fmt::Display,
{
self.version = value
.try_into()
.map_err(|e| format!("error converting supplied value for version: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
epoch: value.epoch?,
ext: value.ext?,
key: value.key?,
version: value.version?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
epoch: Ok(value.epoch),
ext: Ok(value.ext),
key: Ok(value.key),
version: Ok(value.version),
}
}
}
#[derive(Clone, Debug)]
pub struct SealedRecord {
ciphertext: ::std::result::Result<::std::string::String, ::std::string::String>,
epoch: ::std::result::Result<::std::num::NonZeroU64, ::std::string::String>,
nonce: ::std::result::Result<::std::string::String, ::std::string::String>,
}
impl ::std::default::Default for SealedRecord {
fn default() -> Self {
Self {
ciphertext: Err("no value supplied for ciphertext".to_string()),
epoch: Err("no value supplied for epoch".to_string()),
nonce: Err("no value supplied for nonce".to_string()),
}
}
}
impl SealedRecord {
pub fn ciphertext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.ciphertext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ciphertext: {e}"));
self
}
pub fn epoch<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::num::NonZeroU64>,
T::Error: ::std::fmt::Display,
{
self.epoch = value
.try_into()
.map_err(|e| format!("error converting supplied value for epoch: {e}"));
self
}
pub fn nonce<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::string::String>,
T::Error: ::std::fmt::Display,
{
self.nonce = value
.try_into()
.map_err(|e| format!("error converting supplied value for nonce: {e}"));
self
}
}
impl ::std::convert::TryFrom<SealedRecord> for super::SealedRecord {
type Error = super::error::ConversionError;
fn try_from(
value: SealedRecord,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ciphertext: value.ciphertext?,
epoch: value.epoch?,
nonce: value.nonce?,
})
}
}
impl ::std::convert::From<super::SealedRecord> for SealedRecord {
fn from(value: super::SealedRecord) -> Self {
Self {
ciphertext: Ok(value.ciphertext),
epoch: Ok(value.epoch),
nonce: Ok(value.nonce),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/rooms/records/put/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AuthorityPresentation\": {\n \"additionalProperties\": false,\n \"description\": \"What a party presents to act on a room. Carries the whole authority chain: a host MUST NOT dereference an authority credential's `parent` to fetch a link it was not given. Resolving over the network would make verification depend on availability, turn every identifier into a request the host can be induced to make against an address the holder chooses, and signal credential use to whoever hosts the identifier. A host MUST bind the presenter to the chain's leaf. A chain that verifies is evidence that authority was conferred on somebody; it is not evidence that the party presenting it is that somebody. The leaf's subject MUST equal the party the host authenticated for this request — an identity the transport established or a document `proof` proved, never one named in a payload. A host that omits this check authorizes every captured presentation, and the omission is silent, because the chain still verifies.\",\n \"properties\": {\n \"authority\": {\n \"description\": \"The authority chain, LEAF FIRST: the first element is the credential being relied on and the last MUST be one issued by the room itself. Every link the presenter relies on is present, because the host will not fetch one. Capped at 8: verification is linear in chain length and runs on every operation, so an unbounded chain is a denial-of-service surface against the host. The known uses need 2 to 3 — a person attenuating to an agent, and that agent to a sub-agent.\",\n \"items\": {\n \"type\": \"string\"\n },\n \"maxItems\": 8,\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"membership\": {\n \"description\": \"The presenter's membership credential for this room, or — on a `private` room — a zero-knowledge presentation of it. Serialized per the governing profile.\",\n \"type\": \"string\"\n },\n \"subjectBinding\": {\n \"description\": \"REQUIRED on a `private` room, where the subject identifier is withheld: a proof that the membership credential and the authority chain's leaf describe the SAME subject. Without it two parties pool credentials — one contributes membership, the other authority — and the combination verifies as a single party holding both. A host MUST refuse a private-room presentation that omits this.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"membership\",\n \"authority\"\n ],\n \"title\": \"AuthorityPresentation\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to rooms/records/put. Type https://trusttasks.org/spec/rooms/records/put/0.1#response.\",\n \"properties\": {\n \"epoch\": {\n \"description\": \"The epoch the record was stored under.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"key\": {\n \"description\": \"The stored record's key.\",\n \"type\": \"string\"\n },\n \"version\": {\n \"description\": \"The version assigned, monotonic per room.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"key\",\n \"version\"\n ],\n \"title\": \"Rooms Records Put — response payload\",\n \"type\": \"object\"\n },\n \"SealedRecord\": {\n \"additionalProperties\": false,\n \"description\": \"A record as a host stores it on an `attributed` or `private` room. Title, description, body, author and tags are sealed together in one blob rather than separately: splitting them would let a host learn the shape of the material from ciphertext lengths, for no benefit, since a reader decrypts the whole record either way.\",\n \"properties\": {\n \"ciphertext\": {\n \"description\": \"The sealed record, base64url. Bound by AEAD associated data to `roomId`, `key`, `version` and `epoch`, so a host that relocates it to another key, version, epoch or room produces a mismatch and the open fails. The record cannot be moved undetected even though the host holds every byte of it.\",\n \"type\": \"string\"\n },\n \"epoch\": {\n \"description\": \"The key epoch this record was sealed under. Cleartext because the host must serve the right ciphertext, and bound into the associated data so that relabelling it fails authentication rather than causing a reader to try the wrong key.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"nonce\": {\n \"description\": \"AEAD nonce, base64url.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"ciphertext\",\n \"nonce\",\n \"epoch\"\n ],\n \"title\": \"SealedRecord\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/rooms/records/put/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"properties\": {\n \"cleartext\": {\n \"additionalProperties\": false,\n \"description\": \"REQUIRED on an `open` room, where the host reads records and can therefore search them. Mutually exclusive with `sealed`.\",\n \"properties\": {\n \"body\": {\n \"maxLength\": 1048576,\n \"type\": \"string\"\n },\n \"description\": {\n \"maxLength\": 2048,\n \"type\": \"string\"\n },\n \"tags\": {\n \"items\": {\n \"maxLength\": 64,\n \"type\": \"string\"\n },\n \"maxItems\": 32,\n \"type\": \"array\"\n },\n \"title\": {\n \"maxLength\": 512,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"body\"\n ],\n \"type\": \"object\"\n },\n \"expectedVersion\": {\n \"description\": \"Optional precondition. Omit to overwrite unconditionally; `0` means create-only and fails if the key exists. On mismatch the host returns `rooms/records/put:versionConflict` CARRYING THE CURRENT VERSION AND RECORD — a bare rejection would force a re-read, and between rejection and re-read the record can change again, so the pattern has no fixed point under contention.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"key\": {\n \"description\": \"The record's key within the room. MUST be opaque on an `attributed` or `private` room; see RecordMetadata.key.\",\n \"maxLength\": 512,\n \"type\": \"string\"\n },\n \"presentation\": {\n \"$ref\": \"#/$defs/AuthorityPresentation\",\n \"description\": \"Must confer the `write` action at this room's scope.\"\n },\n \"roomId\": {\n \"description\": \"The room's identifier. A host verifies the presentation against credentials issued by this identifier, never against a member list of its own — which is what lets a room move hosts without reissuing a credential.\",\n \"type\": \"string\"\n },\n \"sealed\": {\n \"$ref\": \"#/$defs/SealedRecord\",\n \"description\": \"REQUIRED on an `attributed` or `private` room. Mutually exclusive with `cleartext`.\"\n }\n },\n \"required\": [\n \"roomId\",\n \"key\",\n \"presentation\"\n ],\n \"title\": \"Rooms Records Put — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/rooms/records/put/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AuthorityPresentation\": {\n \"additionalProperties\": false,\n \"description\": \"What a party presents to act on a room. Carries the whole authority chain: a host MUST NOT dereference an authority credential's `parent` to fetch a link it was not given. Resolving over the network would make verification depend on availability, turn every identifier into a request the host can be induced to make against an address the holder chooses, and signal credential use to whoever hosts the identifier. A host MUST bind the presenter to the chain's leaf. A chain that verifies is evidence that authority was conferred on somebody; it is not evidence that the party presenting it is that somebody. The leaf's subject MUST equal the party the host authenticated for this request — an identity the transport established or a document `proof` proved, never one named in a payload. A host that omits this check authorizes every captured presentation, and the omission is silent, because the chain still verifies.\",\n \"properties\": {\n \"authority\": {\n \"description\": \"The authority chain, LEAF FIRST: the first element is the credential being relied on and the last MUST be one issued by the room itself. Every link the presenter relies on is present, because the host will not fetch one. Capped at 8: verification is linear in chain length and runs on every operation, so an unbounded chain is a denial-of-service surface against the host. The known uses need 2 to 3 — a person attenuating to an agent, and that agent to a sub-agent.\",\n \"items\": {\n \"type\": \"string\"\n },\n \"maxItems\": 8,\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"membership\": {\n \"description\": \"The presenter's membership credential for this room, or — on a `private` room — a zero-knowledge presentation of it. Serialized per the governing profile.\",\n \"type\": \"string\"\n },\n \"subjectBinding\": {\n \"description\": \"REQUIRED on a `private` room, where the subject identifier is withheld: a proof that the membership credential and the authority chain's leaf describe the SAME subject. Without it two parties pool credentials — one contributes membership, the other authority — and the combination verifies as a single party holding both. A host MUST refuse a private-room presentation that omits this.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"membership\",\n \"authority\"\n ],\n \"title\": \"AuthorityPresentation\",\n \"type\": \"object\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Success response to rooms/records/put. Type https://trusttasks.org/spec/rooms/records/put/0.1#response.\",\n \"properties\": {\n \"epoch\": {\n \"description\": \"The epoch the record was stored under.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"key\": {\n \"description\": \"The stored record's key.\",\n \"type\": \"string\"\n },\n \"version\": {\n \"description\": \"The version assigned, monotonic per room.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"key\",\n \"version\"\n ],\n \"title\": \"Rooms Records Put — response payload\",\n \"type\": \"object\"\n },\n \"SealedRecord\": {\n \"additionalProperties\": false,\n \"description\": \"A record as a host stores it on an `attributed` or `private` room. Title, description, body, author and tags are sealed together in one blob rather than separately: splitting them would let a host learn the shape of the material from ciphertext lengths, for no benefit, since a reader decrypts the whole record either way.\",\n \"properties\": {\n \"ciphertext\": {\n \"description\": \"The sealed record, base64url. Bound by AEAD associated data to `roomId`, `key`, `version` and `epoch`, so a host that relocates it to another key, version, epoch or room produces a mismatch and the open fails. The record cannot be moved undetected even though the host holds every byte of it.\",\n \"type\": \"string\"\n },\n \"epoch\": {\n \"description\": \"The key epoch this record was sealed under. Cleartext because the host must serve the right ciphertext, and bound into the associated data so that relabelling it fails authentication rather than causing a reader to try the wrong key.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"nonce\": {\n \"description\": \"AEAD nonce, base64url.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"ciphertext\",\n \"nonce\",\n \"epoch\"\n ],\n \"title\": \"SealedRecord\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::NOT_AUTHORIZED,
error_codes::VERSION_CONFLICT,
error_codes::CHAIN_TOO_DEEP,
error_codes::SUBJECT_BINDING_MISSING,
error_codes::EPOCH_MISMATCH,
error_codes::RECORD_TOO_LARGE,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `rooms/records/put:notAuthorized`
///
/// The presentation does not confer `write` at this room's scope, or its chain does not reach the room.
///
/// Declared `retryable: false`.
pub const NOT_AUTHORIZED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:notAuthorized",
retryable: false,
};
/// `rooms/records/put:versionConflict`
///
/// `expectedVersion` did not match. The response carries the current version and record.
///
/// Declared `retryable: false`.
pub const VERSION_CONFLICT: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:versionConflict",
retryable: false,
};
/// `rooms/records/put:chainTooDeep`
///
/// The authority chain exceeds the maximum of 8 links.
///
/// Declared `retryable: false`.
pub const CHAIN_TOO_DEEP: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:chainTooDeep",
retryable: false,
};
/// `rooms/records/put:subjectBindingMissing`
///
/// A `private` room presentation omitted the required same-subject proof.
///
/// Declared `retryable: false`.
pub const SUBJECT_BINDING_MISSING: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:subjectBindingMissing",
retryable: false,
};
/// `rooms/records/put:epochMismatch`
///
/// The record was sealed under an epoch that is not the room's current one.
///
/// Declared `retryable: false`.
pub const EPOCH_MISMATCH: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:epochMismatch",
retryable: false,
};
/// `rooms/records/put:recordTooLarge`
///
/// The record exceeds the host's per-record limit.
///
/// Declared `retryable: false`.
pub const RECORD_TOO_LARGE: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "rooms/records/put:recordTooLarge",
retryable: false,
};
}