//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `vtc/website/upload/begin`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Number of chunks in the bundle, equal to ceil(expectedSizeBytes / chunkSize). Bounded at 4096 so that the manifest itself — one digest per chunk — fits in the single document that carries it under the same message-size reasoning as a chunk.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChunkCount",
/// "description": "Number of chunks in the bundle, equal to ceil(expectedSizeBytes / chunkSize). Bounded at 4096 so that the manifest itself — one digest per chunk — fits in the single document that carries it under the same message-size reasoning as a chunk.",
/// "type": "integer",
/// "maximum": 4096.0,
/// "minimum": 1.0
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ChunkCount(pub ::std::num::NonZeroU64);
impl ::std::ops::Deref for ChunkCount {
type Target = ::std::num::NonZeroU64;
fn deref(&self) -> &::std::num::NonZeroU64 {
&self.0
}
}
impl ::std::convert::From<ChunkCount> for ::std::num::NonZeroU64 {
fn from(value: ChunkCount) -> Self {
value.0
}
}
impl ::std::convert::From<::std::num::NonZeroU64> for ChunkCount {
fn from(value: ::std::num::NonZeroU64) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ChunkCount {
type Err = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ChunkCount {
type Error = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ChunkCount {
type Error = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ChunkCount {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
/**
The terms of a `chunkedTrustTask` transfer, committed before any chunk moves. On export the recipient states them in the descriptor; on import the producer pre-commits them in the request and the recipient echoes them. Either way the manifest arrives in a document whose proof is REQUIRED, so the per-chunk digests are authenticated by the party that computed them and each chunk can be verified — and a single bad chunk re-fetched or refused — on arrival rather than only after reassembly.
Consistency rules JSON Schema cannot state: `chunkCount` MUST equal ceil(expectedSizeBytes / chunkSize) for the bundle the manifest describes, and `chunkDigests` MUST have exactly `chunkCount` items. A party receiving a manifest violating either MUST refuse it.*/
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChunkManifest",
/// "description": "\nThe terms of a `chunkedTrustTask` transfer, committed before any chunk moves. On export the recipient states them in the descriptor; on import the producer pre-commits them in the request and the recipient echoes them. Either way the manifest arrives in a document whose proof is REQUIRED, so the per-chunk digests are authenticated by the party that computed them and each chunk can be verified — and a single bad chunk re-fetched or refused — on arrival rather than only after reassembly.\n\nConsistency rules JSON Schema cannot state: `chunkCount` MUST equal ceil(expectedSizeBytes / chunkSize) for the bundle the manifest describes, and `chunkDigests` MUST have exactly `chunkCount` items. A party receiving a manifest violating either MUST refuse it.",
/// "type": "object",
/// "required": [
/// "chunkCount",
/// "chunkDigests",
/// "chunkSize"
/// ],
/// "properties": {
/// "chunkCount": {
/// "$ref": "#/definitions/ChunkCount"
/// },
/// "chunkDigests": {
/// "description": "Digest of each chunk's raw bytes (not of its base64url encoding), in index order. Compared as decoded multihash bytes, never as encoded strings. sha2-256 is RECOMMENDED and MUST be implemented by every party; a party that does not implement the hash a digest names MUST treat the manifest as unverifiable rather than skip the check.",
/// "type": "array",
/// "items": {
/// "$ref": "#/definitions/DigestMultibase"
/// },
/// "maxItems": 4096,
/// "minItems": 1
/// },
/// "chunkSize": {
/// "$ref": "#/definitions/ChunkSize"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct ChunkManifest {
#[serde(rename = "chunkCount")]
pub chunk_count: ChunkCount,
///Digest of each chunk's raw bytes (not of its base64url encoding), in index order. Compared as decoded multihash bytes, never as encoded strings. sha2-256 is RECOMMENDED and MUST be implemented by every party; a party that does not implement the hash a digest names MUST treat the manifest as unverifiable rather than skip the check.
#[serde(rename = "chunkDigests")]
pub chunk_digests: ::std::vec::Vec<DigestMultibase>,
#[serde(rename = "chunkSize")]
pub chunk_size: ChunkSize,
}
impl ChunkManifest {
pub fn builder() -> builder::ChunkManifest {
Default::default()
}
}
///Size in bytes of every chunk except the last, which carries the remainder and is between 1 and this value inclusive. The ceiling of 262144 (256 KiB) is normative and is derived in `vta/backup/initiate-export/1.1` under Chunked transfer: it is the largest power of two whose `get-chunk` or `put-chunk` document still fits a 1 MiB mediator message after base64url encoding of `data`, DIDComm authcrypt encoding, and two nested forward wrappers. The floor of 16384 keeps a 1 GiB bundle within `ChunkCount`'s ceiling at sizes a constrained transport can still choose.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChunkSize",
/// "description": "Size in bytes of every chunk except the last, which carries the remainder and is between 1 and this value inclusive. The ceiling of 262144 (256 KiB) is normative and is derived in `vta/backup/initiate-export/1.1` under Chunked transfer: it is the largest power of two whose `get-chunk` or `put-chunk` document still fits a 1 MiB mediator message after base64url encoding of `data`, DIDComm authcrypt encoding, and two nested forward wrappers. The floor of 16384 keeps a 1 GiB bundle within `ChunkCount`'s ceiling at sizes a constrained transport can still choose.",
/// "type": "integer",
/// "maximum": 262144.0,
/// "minimum": 16384.0
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ChunkSize(pub i64);
impl ::std::ops::Deref for ChunkSize {
type Target = i64;
fn deref(&self) -> &i64 {
&self.0
}
}
impl ::std::convert::From<ChunkSize> for i64 {
fn from(value: ChunkSize) -> Self {
value.0
}
}
impl ::std::convert::From<i64> for ChunkSize {
fn from(value: i64) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ChunkSize {
type Err = <i64 as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ChunkSize {
type Error = <i64 as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ChunkSize {
type Error = <i64 as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ChunkSize {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
/**
A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.
Multihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.
This definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.
Restricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that "interoperability is not guaranteed between implementations using such values", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.*/
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "DigestMultibase",
/// "description": "\nA cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\n\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\n\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\n\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \"interoperability is not guaranteed between implementations using such values\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.",
/// "examples": [
/// "zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR"
/// ],
/// "type": "string",
/// "minLength": 16,
/// "pattern": "^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct DigestMultibase(::std::string::String);
impl ::std::ops::Deref for DigestMultibase {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<DigestMultibase> for ::std::string::String {
fn from(value: DigestMultibase) -> Self {
value.0
}
}
impl ::std::str::FromStr for DigestMultibase {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 16usize {
return Err("shorter than 16 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\"".into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for DigestMultibase {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Lowercase hex SHA-256 of the whole bundle's bytes. Kept in the hex form the 1.0 descriptor published rather than moved to DigestMultibase, because it is an unchanged member of an existing descriptor and re-encoding it would break every stream producer for no gain in what it checks. For a chunked transfer it is the check over the reassembled bundle, applied after every chunk has verified individually, so that a correct set of chunks assembled in the wrong order is still caught.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ExpectedSha256",
/// "description": "Lowercase hex SHA-256 of the whole bundle's bytes. Kept in the hex form the 1.0 descriptor published rather than moved to DigestMultibase, because it is an unchanged member of an existing descriptor and re-encoding it would break every stream producer for no gain in what it checks. For a chunked transfer it is the check over the reassembled bundle, applied after every chunk has verified individually, so that a correct set of chunks assembled in the wrong order is still caught.",
/// "type": "string",
/// "pattern": "^[0-9a-f]{64}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExpectedSha256(::std::string::String);
impl ::std::ops::Deref for ExpectedSha256 {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExpectedSha256> for ::std::string::String {
fn from(value: ExpectedSha256) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExpectedSha256 {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("^[0-9a-f]{64}$").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[0-9a-f]{64}$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExpectedSha256 {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExpectedSha256 {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExpectedSha256 {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExpectedSha256 {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Total byte count of the bundle. A zero-length bundle is not a degenerate success — nothing was serialized — so the floor is 1.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ExpectedSizeBytes",
/// "description": "Total byte count of the bundle. A zero-length bundle is not a degenerate success — nothing was serialized — so the floor is 1.",
/// "type": "integer",
/// "minimum": 1.0
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ExpectedSizeBytes(pub ::std::num::NonZeroU64);
impl ::std::ops::Deref for ExpectedSizeBytes {
type Target = ::std::num::NonZeroU64;
fn deref(&self) -> &::std::num::NonZeroU64 {
&self.0
}
}
impl ::std::convert::From<ExpectedSizeBytes> for ::std::num::NonZeroU64 {
fn from(value: ExpectedSizeBytes) -> Self {
value.0
}
}
impl ::std::convert::From<::std::num::NonZeroU64> for ExpectedSizeBytes {
fn from(value: ::std::num::NonZeroU64) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ExpectedSizeBytes {
type Err = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ExpectedSizeBytes {
type Error = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ExpectedSizeBytes {
type Error = <::std::num::NonZeroU64 as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ExpectedSizeBytes {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
///After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ExpiresAt",
/// "description": "After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.",
/// "type": "string",
/// "format": "date-time"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ExpiresAt(pub ::chrono::DateTime<::chrono::offset::Utc>);
impl ::std::ops::Deref for ExpiresAt {
type Target = ::chrono::DateTime<::chrono::offset::Utc>;
fn deref(&self) -> &::chrono::DateTime<::chrono::offset::Utc> {
&self.0
}
}
impl ::std::convert::From<ExpiresAt> for ::chrono::DateTime<::chrono::offset::Utc> {
fn from(value: ExpiresAt) -> Self {
value.0
}
}
impl ::std::convert::From<::chrono::DateTime<::chrono::offset::Utc>> for ExpiresAt {
fn from(value: ::chrono::DateTime<::chrono::offset::Utc>) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ExpiresAt {
type Err = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ExpiresAt {
type Error = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ExpiresAt {
type Error = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ExpiresAt {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Open an upload of one website file or a whole-site bundle, committing to its size, SHA-256 and chunk digests. The outer document members are owned by the framework — SPEC §6.3.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/vtc/website/upload/begin/0.1",
/// "title": "Payload",
/// "description": "Open an upload of one website file or a whole-site bundle, committing to its size, SHA-256 and chunk digests. The outer document members are owned by the framework — SPEC §6.3.",
/// "type": "object",
/// "required": [
/// "chunks",
/// "expectedSha256",
/// "expectedSizeBytes",
/// "target"
/// ],
/// "properties": {
/// "chunks": {
/// "$ref": "#/definitions/ChunkManifest"
/// },
/// "expectedSha256": {
/// "$ref": "#/definitions/ExpectedSha256"
/// },
/// "expectedSizeBytes": {
/// "$ref": "#/definitions/ExpectedSizeBytes"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "target": {
/// "$ref": "#/definitions/UploadTarget"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
pub chunks: ChunkManifest,
#[serde(rename = "expectedSha256")]
pub expected_sha256: ExpectedSha256,
#[serde(rename = "expectedSizeBytes")]
pub expected_size_bytes: ExpectedSizeBytes,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
pub target: UploadTarget,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///`Response`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "type": "object",
/// "required": [
/// "expiresAt",
/// "uploadId"
/// ],
/// "properties": {
/// "expiresAt": {
/// "$ref": "#/definitions/ExpiresAt"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "uploadId": {
/// "$ref": "#/definitions/UploadId"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(rename = "expiresAt")]
pub expires_at: ExpiresAt,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
#[serde(rename = "uploadId")]
pub upload_id: UploadId,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "UploadId",
/// "description": "Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.",
/// "type": "string",
/// "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct UploadId(::std::string::String);
impl ::std::ops::Deref for UploadId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<UploadId> for ::std::string::String {
fn from(value: UploadId) -> Self {
value.0
}
}
impl ::std::str::FromStr for UploadId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new(
"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$",
)
.unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for UploadId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for UploadId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for UploadId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for UploadId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///What the uploaded bytes are for, committed before any byte moves. `file`: one file at `path`, written into the site when the upload commits — the single-file write. `bundle`: a gzip-compressed tar of the whole site, staged when the upload commits and published by vtc/website/deploy. `path` is required for a `file` target and forbidden for a `bundle`, and `ifMatch` is allowed only for a `file` — rules over two members that this schema does not express; a community refuses a violation with `malformedRequest`. `ifMatch` is optimistic concurrency: the write commits only if the file's current content hash is this value.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "UploadTarget",
/// "description": "What the uploaded bytes are for, committed before any byte moves. `file`: one file at `path`, written into the site when the upload commits — the single-file write. `bundle`: a gzip-compressed tar of the whole site, staged when the upload commits and published by vtc/website/deploy. `path` is required for a `file` target and forbidden for a `bundle`, and `ifMatch` is allowed only for a `file` — rules over two members that this schema does not express; a community refuses a violation with `malformedRequest`. `ifMatch` is optimistic concurrency: the write commits only if the file's current content hash is this value.",
/// "type": "object",
/// "required": [
/// "kind"
/// ],
/// "properties": {
/// "ifMatch": {
/// "$ref": "#/definitions/WebsiteEtag"
/// },
/// "kind": {
/// "type": "string",
/// "enum": [
/// "file",
/// "bundle"
/// ]
/// },
/// "path": {
/// "$ref": "#/definitions/WebsitePath"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct UploadTarget {
#[serde(
rename = "ifMatch",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub if_match: ::std::option::Option<WebsiteEtag>,
pub kind: UploadTargetKind,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub path: ::std::option::Option<WebsitePath>,
}
impl UploadTarget {
pub fn builder() -> builder::UploadTarget {
Default::default()
}
}
///`UploadTargetKind`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "enum": [
/// "file",
/// "bundle"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum UploadTargetKind {
#[serde(rename = "file")]
File,
#[serde(rename = "bundle")]
Bundle,
}
impl ::std::fmt::Display for UploadTargetKind {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::File => f.write_str("file"),
Self::Bundle => f.write_str("bundle"),
}
}
}
impl ::std::str::FromStr for UploadTargetKind {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"file" => Ok(Self::File),
"bundle" => Ok(Self::Bundle),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for UploadTargetKind {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for UploadTargetKind {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for UploadTargetKind {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///A file's content hash: the lowercase hex SHA-256 of its bytes — the `etag` vtc/website/files/list reports, and the `ETag` a direct read of the path returns, without the HTTP quotes.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "WebsiteEtag",
/// "description": "A file's content hash: the lowercase hex SHA-256 of its bytes — the `etag` vtc/website/files/list reports, and the `ETag` a direct read of the path returns, without the HTTP quotes.",
/// "type": "string",
/// "pattern": "^[0-9a-f]{64}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct WebsiteEtag(::std::string::String);
impl ::std::ops::Deref for WebsiteEtag {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<WebsiteEtag> for ::std::string::String {
fn from(value: WebsiteEtag) -> Self {
value.0
}
}
impl ::std::str::FromStr for WebsiteEtag {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("^[0-9a-f]{64}$").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[0-9a-f]{64}$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for WebsiteEtag {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for WebsiteEtag {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for WebsiteEtag {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for WebsiteEtag {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///A file's path relative to the site root, `/`-separated, with or without a leading `/`. The community resolves it inside the site root and refuses one that escapes the root (`..`), names a hidden file or directory (a segment beginning `.`), carries a blocklisted extension, or contains a control character — the same rules the public read handler applies, so nothing can be written that the site would refuse to serve, and nothing can be read that it would not.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "WebsitePath",
/// "description": "A file's path relative to the site root, `/`-separated, with or without a leading `/`. The community resolves it inside the site root and refuses one that escapes the root (`..`), names a hidden file or directory (a segment beginning `.`), carries a blocklisted extension, or contains a control character — the same rules the public read handler applies, so nothing can be written that the site would refuse to serve, and nothing can be read that it would not.",
/// "type": "string",
/// "maxLength": 1024,
/// "minLength": 1,
/// "pattern": "^[^\\\\]+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct WebsitePath(::std::string::String);
impl ::std::ops::Deref for WebsitePath {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<WebsitePath> for ::std::string::String {
fn from(value: WebsitePath) -> Self {
value.0
}
}
impl ::std::str::FromStr for WebsitePath {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 1024usize {
return Err("longer than 1024 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("^[^\\\\]+$").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[^\\\\]+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for WebsitePath {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for WebsitePath {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for WebsitePath {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for WebsitePath {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct ChunkManifest {
chunk_count: ::std::result::Result<super::ChunkCount, ::std::string::String>,
chunk_digests:
::std::result::Result<::std::vec::Vec<super::DigestMultibase>, ::std::string::String>,
chunk_size: ::std::result::Result<super::ChunkSize, ::std::string::String>,
}
impl ::std::default::Default for ChunkManifest {
fn default() -> Self {
Self {
chunk_count: Err("no value supplied for chunk_count".to_string()),
chunk_digests: Err("no value supplied for chunk_digests".to_string()),
chunk_size: Err("no value supplied for chunk_size".to_string()),
}
}
}
impl ChunkManifest {
pub fn chunk_count<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkCount>,
T::Error: ::std::fmt::Display,
{
self.chunk_count = value
.try_into()
.map_err(|e| format!("error converting supplied value for chunk_count: {e}"));
self
}
pub fn chunk_digests<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::DigestMultibase>>,
T::Error: ::std::fmt::Display,
{
self.chunk_digests = value
.try_into()
.map_err(|e| format!("error converting supplied value for chunk_digests: {e}"));
self
}
pub fn chunk_size<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkSize>,
T::Error: ::std::fmt::Display,
{
self.chunk_size = value
.try_into()
.map_err(|e| format!("error converting supplied value for chunk_size: {e}"));
self
}
}
impl ::std::convert::TryFrom<ChunkManifest> for super::ChunkManifest {
type Error = super::error::ConversionError;
fn try_from(
value: ChunkManifest,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
chunk_count: value.chunk_count?,
chunk_digests: value.chunk_digests?,
chunk_size: value.chunk_size?,
})
}
}
impl ::std::convert::From<super::ChunkManifest> for ChunkManifest {
fn from(value: super::ChunkManifest) -> Self {
Self {
chunk_count: Ok(value.chunk_count),
chunk_digests: Ok(value.chunk_digests),
chunk_size: Ok(value.chunk_size),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
chunks: ::std::result::Result<super::ChunkManifest, ::std::string::String>,
expected_sha256: ::std::result::Result<super::ExpectedSha256, ::std::string::String>,
expected_size_bytes: ::std::result::Result<super::ExpectedSizeBytes, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
target: ::std::result::Result<super::UploadTarget, ::std::string::String>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
chunks: Err("no value supplied for chunks".to_string()),
expected_sha256: Err("no value supplied for expected_sha256".to_string()),
expected_size_bytes: Err("no value supplied for expected_size_bytes".to_string()),
ext: Ok(Default::default()),
target: Err("no value supplied for target".to_string()),
}
}
}
impl Payload {
pub fn chunks<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkManifest>,
T::Error: ::std::fmt::Display,
{
self.chunks = value
.try_into()
.map_err(|e| format!("error converting supplied value for chunks: {e}"));
self
}
pub fn expected_sha256<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ExpectedSha256>,
T::Error: ::std::fmt::Display,
{
self.expected_sha256 = value
.try_into()
.map_err(|e| format!("error converting supplied value for expected_sha256: {e}"));
self
}
pub fn expected_size_bytes<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ExpectedSizeBytes>,
T::Error: ::std::fmt::Display,
{
self.expected_size_bytes = value.try_into().map_err(|e| {
format!("error converting supplied value for expected_size_bytes: {e}")
});
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn target<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::UploadTarget>,
T::Error: ::std::fmt::Display,
{
self.target = value
.try_into()
.map_err(|e| format!("error converting supplied value for target: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
chunks: value.chunks?,
expected_sha256: value.expected_sha256?,
expected_size_bytes: value.expected_size_bytes?,
ext: value.ext?,
target: value.target?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
chunks: Ok(value.chunks),
expected_sha256: Ok(value.expected_sha256),
expected_size_bytes: Ok(value.expected_size_bytes),
ext: Ok(value.ext),
target: Ok(value.target),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
expires_at: ::std::result::Result<super::ExpiresAt, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
upload_id: ::std::result::Result<super::UploadId, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
expires_at: Err("no value supplied for expires_at".to_string()),
ext: Ok(Default::default()),
upload_id: Err("no value supplied for upload_id".to_string()),
}
}
}
impl Response {
pub fn expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ExpiresAt>,
T::Error: ::std::fmt::Display,
{
self.expires_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_at: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn upload_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::UploadId>,
T::Error: ::std::fmt::Display,
{
self.upload_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for upload_id: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
expires_at: value.expires_at?,
ext: value.ext?,
upload_id: value.upload_id?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
expires_at: Ok(value.expires_at),
ext: Ok(value.ext),
upload_id: Ok(value.upload_id),
}
}
}
#[derive(Clone, Debug)]
pub struct UploadTarget {
if_match:
::std::result::Result<::std::option::Option<super::WebsiteEtag>, ::std::string::String>,
kind: ::std::result::Result<super::UploadTargetKind, ::std::string::String>,
path:
::std::result::Result<::std::option::Option<super::WebsitePath>, ::std::string::String>,
}
impl ::std::default::Default for UploadTarget {
fn default() -> Self {
Self {
if_match: Ok(Default::default()),
kind: Err("no value supplied for kind".to_string()),
path: Ok(Default::default()),
}
}
}
impl UploadTarget {
pub fn if_match<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::WebsiteEtag>>,
T::Error: ::std::fmt::Display,
{
self.if_match = value
.try_into()
.map_err(|e| format!("error converting supplied value for if_match: {e}"));
self
}
pub fn kind<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::UploadTargetKind>,
T::Error: ::std::fmt::Display,
{
self.kind = value
.try_into()
.map_err(|e| format!("error converting supplied value for kind: {e}"));
self
}
pub fn path<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::WebsitePath>>,
T::Error: ::std::fmt::Display,
{
self.path = value
.try_into()
.map_err(|e| format!("error converting supplied value for path: {e}"));
self
}
}
impl ::std::convert::TryFrom<UploadTarget> for super::UploadTarget {
type Error = super::error::ConversionError;
fn try_from(
value: UploadTarget,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
if_match: value.if_match?,
kind: value.kind?,
path: value.path?,
})
}
}
impl ::std::convert::From<super::UploadTarget> for UploadTarget {
fn from(value: super::UploadTarget) -> Self {
Self {
if_match: Ok(value.if_match),
kind: Ok(value.kind),
path: Ok(value.path),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/vtc/website/upload/begin/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const MAX_DOCUMENT_BYTES: Option<usize> = Some(262144usize);
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"ChunkCount\": {\n \"description\": \"Number of chunks in the bundle, equal to ceil(expectedSizeBytes / chunkSize). Bounded at 4096 so that the manifest itself — one digest per chunk — fits in the single document that carries it under the same message-size reasoning as a chunk.\",\n \"maximum\": 4096,\n \"minimum\": 1,\n \"title\": \"ChunkCount\",\n \"type\": \"integer\"\n },\n \"ChunkManifest\": {\n \"additionalProperties\": false,\n \"description\": \"The terms of a `chunkedTrustTask` transfer, committed before any chunk moves. On export the recipient states them in the descriptor; on import the producer pre-commits them in the request and the recipient echoes them. Either way the manifest arrives in a document whose proof is REQUIRED, so the per-chunk digests are authenticated by the party that computed them and each chunk can be verified — and a single bad chunk re-fetched or refused — on arrival rather than only after reassembly.\\n\\nConsistency rules JSON Schema cannot state: `chunkCount` MUST equal ceil(expectedSizeBytes / chunkSize) for the bundle the manifest describes, and `chunkDigests` MUST have exactly `chunkCount` items. A party receiving a manifest violating either MUST refuse it.\",\n \"properties\": {\n \"chunkCount\": {\n \"$ref\": \"#/$defs/ChunkCount\"\n },\n \"chunkDigests\": {\n \"description\": \"Digest of each chunk's raw bytes (not of its base64url encoding), in index order. Compared as decoded multihash bytes, never as encoded strings. sha2-256 is RECOMMENDED and MUST be implemented by every party; a party that does not implement the hash a digest names MUST treat the manifest as unverifiable rather than skip the check.\",\n \"items\": {\n \"$ref\": \"#/$defs/DigestMultibase\"\n },\n \"maxItems\": 4096,\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"chunkSize\": {\n \"$ref\": \"#/$defs/ChunkSize\"\n }\n },\n \"required\": [\n \"chunkSize\",\n \"chunkCount\",\n \"chunkDigests\"\n ],\n \"title\": \"ChunkManifest\",\n \"type\": \"object\"\n },\n \"ChunkSize\": {\n \"description\": \"Size in bytes of every chunk except the last, which carries the remainder and is between 1 and this value inclusive. The ceiling of 262144 (256 KiB) is normative and is derived in `vta/backup/initiate-export/1.1` under Chunked transfer: it is the largest power of two whose `get-chunk` or `put-chunk` document still fits a 1 MiB mediator message after base64url encoding of `data`, DIDComm authcrypt encoding, and two nested forward wrappers. The floor of 16384 keeps a 1 GiB bundle within `ChunkCount`'s ceiling at sizes a constrained transport can still choose.\",\n \"maximum\": 262144,\n \"minimum\": 16384,\n \"title\": \"ChunkSize\",\n \"type\": \"integer\"\n },\n \"DigestMultibase\": {\n \"description\": \"A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\\n\\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\\n\\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\\n\\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \\\"interoperability is not guaranteed between implementations using such values\\\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.\",\n \"examples\": [\n \"zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR\"\n ],\n \"minLength\": 16,\n \"pattern\": \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\",\n \"title\": \"DigestMultibase\",\n \"type\": \"string\"\n },\n \"ExpectedSha256\": {\n \"description\": \"Lowercase hex SHA-256 of the whole bundle's bytes. Kept in the hex form the 1.0 descriptor published rather than moved to DigestMultibase, because it is an unchanged member of an existing descriptor and re-encoding it would break every stream producer for no gain in what it checks. For a chunked transfer it is the check over the reassembled bundle, applied after every chunk has verified individually, so that a correct set of chunks assembled in the wrong order is still caught.\",\n \"pattern\": \"^[0-9a-f]{64}$\",\n \"title\": \"ExpectedSha256\",\n \"type\": \"string\"\n },\n \"ExpectedSizeBytes\": {\n \"description\": \"Total byte count of the bundle. A zero-length bundle is not a degenerate success — nothing was serialized — so the floor is 1.\",\n \"minimum\": 1,\n \"title\": \"ExpectedSizeBytes\",\n \"type\": \"integer\"\n },\n \"ExpiresAt\": {\n \"description\": \"After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.\",\n \"format\": \"date-time\",\n \"title\": \"ExpiresAt\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"expiresAt\": {\n \"$ref\": \"#/$defs/ExpiresAt\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"uploadId\": {\n \"$ref\": \"#/$defs/UploadId\"\n }\n },\n \"required\": [\n \"uploadId\",\n \"expiresAt\"\n ],\n \"title\": \"VTC Website — Upload — Begin — response payload\",\n \"type\": \"object\"\n },\n \"UploadId\": {\n \"description\": \"Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.\",\n \"pattern\": \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\",\n \"title\": \"UploadId\",\n \"type\": \"string\"\n },\n \"UploadTarget\": {\n \"additionalProperties\": false,\n \"description\": \"What the uploaded bytes are for, committed before any byte moves. `file`: one file at `path`, written into the site when the upload commits — the single-file write. `bundle`: a gzip-compressed tar of the whole site, staged when the upload commits and published by vtc/website/deploy. `path` is required for a `file` target and forbidden for a `bundle`, and `ifMatch` is allowed only for a `file` — rules over two members that this schema does not express; a community refuses a violation with `malformedRequest`. `ifMatch` is optimistic concurrency: the write commits only if the file's current content hash is this value.\",\n \"properties\": {\n \"ifMatch\": {\n \"$ref\": \"#/$defs/WebsiteEtag\"\n },\n \"kind\": {\n \"enum\": [\n \"file\",\n \"bundle\"\n ],\n \"type\": \"string\"\n },\n \"path\": {\n \"$ref\": \"#/$defs/WebsitePath\"\n }\n },\n \"required\": [\n \"kind\"\n ],\n \"title\": \"UploadTarget\",\n \"type\": \"object\"\n },\n \"WebsiteEtag\": {\n \"description\": \"A file's content hash: the lowercase hex SHA-256 of its bytes — the `etag` vtc/website/files/list reports, and the `ETag` a direct read of the path returns, without the HTTP quotes.\",\n \"pattern\": \"^[0-9a-f]{64}$\",\n \"title\": \"WebsiteEtag\",\n \"type\": \"string\"\n },\n \"WebsitePath\": {\n \"description\": \"A file's path relative to the site root, `/`-separated, with or without a leading `/`. The community resolves it inside the site root and refuses one that escapes the root (`..`), names a hidden file or directory (a segment beginning `.`), carries a blocklisted extension, or contains a control character — the same rules the public read handler applies, so nothing can be written that the site would refuse to serve, and nothing can be read that it would not.\",\n \"maxLength\": 1024,\n \"minLength\": 1,\n \"pattern\": \"^[^\\\\\\\\]+$\",\n \"title\": \"WebsitePath\",\n \"type\": \"string\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/vtc/website/upload/begin/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Open an upload of one website file or a whole-site bundle, committing to its size, SHA-256 and chunk digests. The outer document members are owned by the framework — SPEC §6.3.\",\n \"properties\": {\n \"chunks\": {\n \"$ref\": \"#/$defs/ChunkManifest\"\n },\n \"expectedSha256\": {\n \"$ref\": \"#/$defs/ExpectedSha256\"\n },\n \"expectedSizeBytes\": {\n \"$ref\": \"#/$defs/ExpectedSizeBytes\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"target\": {\n \"$ref\": \"#/$defs/UploadTarget\"\n }\n },\n \"required\": [\n \"target\",\n \"expectedSha256\",\n \"expectedSizeBytes\",\n \"chunks\"\n ],\n \"title\": \"VTC Website — Upload — Begin — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str =
"https://trusttasks.org/spec/vtc/website/upload/begin/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"ChunkCount\": {\n \"description\": \"Number of chunks in the bundle, equal to ceil(expectedSizeBytes / chunkSize). Bounded at 4096 so that the manifest itself — one digest per chunk — fits in the single document that carries it under the same message-size reasoning as a chunk.\",\n \"maximum\": 4096,\n \"minimum\": 1,\n \"title\": \"ChunkCount\",\n \"type\": \"integer\"\n },\n \"ChunkManifest\": {\n \"additionalProperties\": false,\n \"description\": \"The terms of a `chunkedTrustTask` transfer, committed before any chunk moves. On export the recipient states them in the descriptor; on import the producer pre-commits them in the request and the recipient echoes them. Either way the manifest arrives in a document whose proof is REQUIRED, so the per-chunk digests are authenticated by the party that computed them and each chunk can be verified — and a single bad chunk re-fetched or refused — on arrival rather than only after reassembly.\\n\\nConsistency rules JSON Schema cannot state: `chunkCount` MUST equal ceil(expectedSizeBytes / chunkSize) for the bundle the manifest describes, and `chunkDigests` MUST have exactly `chunkCount` items. A party receiving a manifest violating either MUST refuse it.\",\n \"properties\": {\n \"chunkCount\": {\n \"$ref\": \"#/$defs/ChunkCount\"\n },\n \"chunkDigests\": {\n \"description\": \"Digest of each chunk's raw bytes (not of its base64url encoding), in index order. Compared as decoded multihash bytes, never as encoded strings. sha2-256 is RECOMMENDED and MUST be implemented by every party; a party that does not implement the hash a digest names MUST treat the manifest as unverifiable rather than skip the check.\",\n \"items\": {\n \"$ref\": \"#/$defs/DigestMultibase\"\n },\n \"maxItems\": 4096,\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"chunkSize\": {\n \"$ref\": \"#/$defs/ChunkSize\"\n }\n },\n \"required\": [\n \"chunkSize\",\n \"chunkCount\",\n \"chunkDigests\"\n ],\n \"title\": \"ChunkManifest\",\n \"type\": \"object\"\n },\n \"ChunkSize\": {\n \"description\": \"Size in bytes of every chunk except the last, which carries the remainder and is between 1 and this value inclusive. The ceiling of 262144 (256 KiB) is normative and is derived in `vta/backup/initiate-export/1.1` under Chunked transfer: it is the largest power of two whose `get-chunk` or `put-chunk` document still fits a 1 MiB mediator message after base64url encoding of `data`, DIDComm authcrypt encoding, and two nested forward wrappers. The floor of 16384 keeps a 1 GiB bundle within `ChunkCount`'s ceiling at sizes a constrained transport can still choose.\",\n \"maximum\": 262144,\n \"minimum\": 16384,\n \"title\": \"ChunkSize\",\n \"type\": \"integer\"\n },\n \"DigestMultibase\": {\n \"description\": \"A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\\n\\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\\n\\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\\n\\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \\\"interoperability is not guaranteed between implementations using such values\\\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.\",\n \"examples\": [\n \"zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR\"\n ],\n \"minLength\": 16,\n \"pattern\": \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\",\n \"title\": \"DigestMultibase\",\n \"type\": \"string\"\n },\n \"ExpectedSha256\": {\n \"description\": \"Lowercase hex SHA-256 of the whole bundle's bytes. Kept in the hex form the 1.0 descriptor published rather than moved to DigestMultibase, because it is an unchanged member of an existing descriptor and re-encoding it would break every stream producer for no gain in what it checks. For a chunked transfer it is the check over the reassembled bundle, applied after every chunk has verified individually, so that a correct set of chunks assembled in the wrong order is still caught.\",\n \"pattern\": \"^[0-9a-f]{64}$\",\n \"title\": \"ExpectedSha256\",\n \"type\": \"string\"\n },\n \"ExpectedSizeBytes\": {\n \"description\": \"Total byte count of the bundle. A zero-length bundle is not a degenerate success — nothing was serialized — so the floor is 1.\",\n \"minimum\": 1,\n \"title\": \"ExpectedSizeBytes\",\n \"type\": \"integer\"\n },\n \"ExpiresAt\": {\n \"description\": \"After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.\",\n \"format\": \"date-time\",\n \"title\": \"ExpiresAt\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"expiresAt\": {\n \"$ref\": \"#/$defs/ExpiresAt\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"uploadId\": {\n \"$ref\": \"#/$defs/UploadId\"\n }\n },\n \"required\": [\n \"uploadId\",\n \"expiresAt\"\n ],\n \"title\": \"VTC Website — Upload — Begin — response payload\",\n \"type\": \"object\"\n },\n \"UploadId\": {\n \"description\": \"Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.\",\n \"pattern\": \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\",\n \"title\": \"UploadId\",\n \"type\": \"string\"\n },\n \"UploadTarget\": {\n \"additionalProperties\": false,\n \"description\": \"What the uploaded bytes are for, committed before any byte moves. `file`: one file at `path`, written into the site when the upload commits — the single-file write. `bundle`: a gzip-compressed tar of the whole site, staged when the upload commits and published by vtc/website/deploy. `path` is required for a `file` target and forbidden for a `bundle`, and `ifMatch` is allowed only for a `file` — rules over two members that this schema does not express; a community refuses a violation with `malformedRequest`. `ifMatch` is optimistic concurrency: the write commits only if the file's current content hash is this value.\",\n \"properties\": {\n \"ifMatch\": {\n \"$ref\": \"#/$defs/WebsiteEtag\"\n },\n \"kind\": {\n \"enum\": [\n \"file\",\n \"bundle\"\n ],\n \"type\": \"string\"\n },\n \"path\": {\n \"$ref\": \"#/$defs/WebsitePath\"\n }\n },\n \"required\": [\n \"kind\"\n ],\n \"title\": \"UploadTarget\",\n \"type\": \"object\"\n },\n \"WebsiteEtag\": {\n \"description\": \"A file's content hash: the lowercase hex SHA-256 of its bytes — the `etag` vtc/website/files/list reports, and the `ETag` a direct read of the path returns, without the HTTP quotes.\",\n \"pattern\": \"^[0-9a-f]{64}$\",\n \"title\": \"WebsiteEtag\",\n \"type\": \"string\"\n },\n \"WebsitePath\": {\n \"description\": \"A file's path relative to the site root, `/`-separated, with or without a leading `/`. The community resolves it inside the site root and refuses one that escapes the root (`..`), names a hidden file or directory (a segment beginning `.`), carries a blocklisted extension, or contains a control character — the same rules the public read handler applies, so nothing can be written that the site would refuse to serve, and nothing can be read that it would not.\",\n \"maxLength\": 1024,\n \"minLength\": 1,\n \"pattern\": \"^[^\\\\\\\\]+$\",\n \"title\": \"WebsitePath\",\n \"type\": \"string\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::NOT_CONFIGURED,
error_codes::TOO_LARGE,
error_codes::PATH_REFUSED,
error_codes::SINGLE_FILE_WRITES_DISABLED,
error_codes::INVALID_MANIFEST,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `vtc/website/upload/begin:notConfigured`
///
/// The community serves no website — it has no site root configured — so there is nothing to upload into.
///
/// Declared `retryable: false`.
pub const NOT_CONFIGURED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/begin:notConfigured",
retryable: false,
};
/// `vtc/website/upload/begin:tooLarge`
///
/// `expectedSizeBytes` exceeds the community's limit for the target: its maximum file size for a `file`, its maximum bundle size for a `bundle`. `details.maxSizeBytes` states the limit.
///
/// Declared `retryable: false`.
pub const TOO_LARGE: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/begin:tooLarge",
retryable: false,
};
/// `vtc/website/upload/begin:pathRefused`
///
/// The target `path` escapes the site root, names a hidden file or directory, carries a blocklisted extension, or contains a character the site refuses. Checked here, before any byte moves, and again at commit.
///
/// Declared `retryable: false`.
pub const PATH_REFUSED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/begin:pathRefused",
retryable: false,
};
/// `vtc/website/upload/begin:singleFileWritesDisabled`
///
/// The community's website is in managed deploy mode, where every change lands as a new generation; a `file` target cannot be written. Upload a `bundle` and deploy it.
///
/// Declared `retryable: false`.
pub const SINGLE_FILE_WRITES_DISABLED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/begin:singleFileWritesDisabled",
retryable: false,
};
/// `vtc/website/upload/begin:invalidManifest`
///
/// `chunks.chunkCount` is not ceil(expectedSizeBytes / chunkSize), or `chunks.chunkDigests` does not have exactly `chunkCount` items.
///
/// Declared `retryable: false`.
pub const INVALID_MANIFEST: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/begin:invalidManifest",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000001\",\n \"type\": \"https://trusttasks.org/spec/vtc/website/upload/begin/0.1#request\",\n \"issuer\": \"did:example:administrator\",\n \"recipient\": \"did:example:community\",\n \"issuedAt\": \"2026-09-28T10:00:00Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000001ff\",\n \"payload\": {\n \"target\": {\n \"kind\": \"file\",\n \"path\": \"/events/index.html\",\n \"ifMatch\": \"9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08\"\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"chunks\": {\n \"chunkSize\": 262144,\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ]\n }\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_2() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000002\",\n \"type\": \"https://trusttasks.org/spec/vtc/website/upload/begin/0.1#request\",\n \"issuer\": \"did:example:administrator\",\n \"recipient\": \"did:example:community\",\n \"issuedAt\": \"2026-09-28T10:00:00Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000001fe\",\n \"payload\": {\n \"target\": {\n \"kind\": \"bundle\"\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"chunks\": {\n \"chunkSize\": 262144,\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ]\n }\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000003\",\n \"type\": \"https://trusttasks.org/spec/vtc/website/upload/begin/0.1#response\",\n \"issuer\": \"did:example:community\",\n \"recipient\": \"did:example:administrator\",\n \"issuedAt\": \"2026-09-28T10:00:01Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000001ff\",\n \"payload\": {\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\",\n \"expiresAt\": \"2026-09-28T11:00:00Z\"\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"No manifest — every chunk is checked on arrival against digests committed here.",
"{\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"target\": {\n \"kind\": \"bundle\"\n }\n}",
),
(
"A zero-byte transfer.",
"{\n \"chunks\": {\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ],\n \"chunkSize\": 262144\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 0,\n \"target\": {\n \"kind\": \"bundle\"\n }\n}",
),
(
"An upper-case SHA-256 — the committed hash is lowercase hex.",
"{\n \"chunks\": {\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ],\n \"chunkSize\": 262144\n },\n \"expectedSha256\": \"3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B8A55\",\n \"expectedSizeBytes\": 300000,\n \"target\": {\n \"kind\": \"bundle\"\n }\n}",
),
(
"A chunk size above the 256 KiB ceiling.",
"{\n \"chunks\": {\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ],\n \"chunkSize\": 524288\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"target\": {\n \"kind\": \"bundle\"\n }\n}",
),
(
"An unknown target kind.",
"{\n \"chunks\": {\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ],\n \"chunkSize\": 262144\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"target\": {\n \"kind\": \"directory\",\n \"path\": \"/events\"\n }\n}",
),
(
"A path with a backslash — paths are `/`-separated.",
"{\n \"chunks\": {\n \"chunkCount\": 2,\n \"chunkDigests\": [\n \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\"\n ],\n \"chunkSize\": 262144\n },\n \"expectedSha256\": \"3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b8a55\",\n \"expectedSizeBytes\": 300000,\n \"target\": {\n \"kind\": \"file\",\n \"path\": \"events\\\\index.html\"\n }\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
/// Each `"variant": "response"` fixture in
/// `payload.invalid-examples.json` MUST be rejected as a
/// response payload by at least one of: serde deserialization
/// into `Response`, or JSON-Schema validation against the
/// `$anchor: "response"` sub-schema (validate feature).
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_response_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"An upload id that is not a UUID.",
"{\n \"expiresAt\": \"2026-09-28T11:00:00Z\",\n \"uploadId\": \"upload-1\"\n}",
),
(
"Response without an expiry.",
"{\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Response>(value.clone()).is_ok();
let schema_ok = super::Response::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid response example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}