//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `auth/authenticate`. Version: `0.3`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The subject presents a previously-issued challenge along with the framework `proof` that binds the document to a VID. The proof IS the authentication. 0.3 adds an optional proxied form: `principal` names a party the signer authenticates *as*, distinct from `issuer` (the signer, e.g. a VTA acting on the principal's behalf), together with `delegationEvidence` establishing the entitlement. Absent `principal`, or `principal` equal to `issuer`, is the ordinary auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional `sessionKey` member from 0.2.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/auth/authenticate/0.3",
/// "title": "Payload",
/// "description": "The subject presents a previously-issued challenge along with the framework `proof` that binds the document to a VID. The proof IS the authentication. 0.3 adds an optional proxied form: `principal` names a party the signer authenticates *as*, distinct from `issuer` (the signer, e.g. a VTA acting on the principal's behalf), together with `delegationEvidence` establishing the entitlement. Absent `principal`, or `principal` equal to `issuer`, is the ordinary auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional `sessionKey` member from 0.2.",
/// "type": "object",
/// "required": [
/// "challenge",
/// "sessionId"
/// ],
/// "properties": {
/// "challenge": {
/// "description": "The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.",
/// "type": "string",
/// "minLength": 16
/// },
/// "delegationEvidence": {
/// "description": "REQUIRED whenever `principal` is present and differs from `issuer`; MUST be omitted otherwise. Describes the evidence that entitles `issuer` to authenticate as `principal`. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than take `issuer`'s claim of entitlement at face value.",
/// "type": "object",
/// "required": [
/// "kind"
/// ],
/// "properties": {
/// "credential": {
/// "description": "The evidence itself, inline — typically a Verifiable Credential or other signed assertion binding `issuer` to `principal`. Opaque to the framework; shape is consumer- or ecosystem-defined by `kind`.",
/// "type": "object"
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "kind": {
/// "description": "Consumer-defined vocabulary naming the evidence class (e.g. \"vtaContext\", \"mandateCredential\"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
/// },
/// "reference": {
/// "description": "Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "principal": {
/// "description": "The VID being authenticated as, when it differs from the signer of this document. Present and unequal to `issuer` marks a *proxied* authenticate: `issuer` is a delegate (typically the principal's VTA) presenting its own proof, and `payload.delegationEvidence` MUST also be present, describing what entitles `issuer` to act for `principal`. Omitted, or equal to `issuer`, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.",
/// "type": "string",
/// "maxLength": 2048,
/// "pattern": "^did:"
/// },
/// "scope": {
/// "description": "Optional capability tags being requested on the issued tokens. The consumer's authorization layer decides which are granted; the issued TokenBundle's `scope` MAY be a subset.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "sessionId": {
/// "description": "The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.",
/// "type": "string",
/// "minLength": 1
/// },
/// "sessionKey": {
/// "description": "A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework `proof` made by this key, with `proofPurpose: authentication`, as the session's `subject` — for this session only, bounded by the session's `expiresAt` and `acr`, and never where a specification requires an `assertionMethod` attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with `auth/authenticate:sessionKeyUnsupported`.",
/// "type": "string",
/// "maxLength": 512,
/// "pattern": "^did:key:z[1-9A-HJ-NP-Za-km-z]+$"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
///The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.
pub challenge: PayloadChallenge,
#[serde(
rename = "delegationEvidence",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub delegation_evidence: ::std::option::Option<PayloadDelegationEvidence>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The VID being authenticated as, when it differs from the signer of this document. Present and unequal to `issuer` marks a *proxied* authenticate: `issuer` is a delegate (typically the principal's VTA) presenting its own proof, and `payload.delegationEvidence` MUST also be present, describing what entitles `issuer` to act for `principal`. Omitted, or equal to `issuer`, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub principal: ::std::option::Option<PayloadPrincipal>,
///Optional capability tags being requested on the issued tokens. The consumer's authorization layer decides which are granted; the issued TokenBundle's `scope` MAY be a subset.
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub scope: ::std::vec::Vec<PayloadScopeItem>,
///The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.
#[serde(rename = "sessionId")]
pub session_id: PayloadSessionId,
///A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework `proof` made by this key, with `proofPurpose: authentication`, as the session's `subject` — for this session only, bounded by the session's `expiresAt` and `acr`, and never where a specification requires an `assertionMethod` attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with `auth/authenticate:sessionKeyUnsupported`.
#[serde(
rename = "sessionKey",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub session_key: ::std::option::Option<PayloadSessionKey>,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.",
/// "type": "string",
/// "minLength": 16
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadChallenge(::std::string::String);
impl ::std::ops::Deref for PayloadChallenge {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadChallenge> for ::std::string::String {
fn from(value: PayloadChallenge) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadChallenge {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 16usize {
return Err("shorter than 16 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadChallenge {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadChallenge {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadChallenge {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadChallenge {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///REQUIRED whenever `principal` is present and differs from `issuer`; MUST be omitted otherwise. Describes the evidence that entitles `issuer` to authenticate as `principal`. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than take `issuer`'s claim of entitlement at face value.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "REQUIRED whenever `principal` is present and differs from `issuer`; MUST be omitted otherwise. Describes the evidence that entitles `issuer` to authenticate as `principal`. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than take `issuer`'s claim of entitlement at face value.",
/// "type": "object",
/// "required": [
/// "kind"
/// ],
/// "properties": {
/// "credential": {
/// "description": "The evidence itself, inline — typically a Verifiable Credential or other signed assertion binding `issuer` to `principal`. Opaque to the framework; shape is consumer- or ecosystem-defined by `kind`.",
/// "type": "object"
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "kind": {
/// "description": "Consumer-defined vocabulary naming the evidence class (e.g. \"vtaContext\", \"mandateCredential\"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
/// },
/// "reference": {
/// "description": "Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct PayloadDelegationEvidence {
///The evidence itself, inline — typically a Verifiable Credential or other signed assertion binding `issuer` to `principal`. Opaque to the framework; shape is consumer- or ecosystem-defined by `kind`.
#[serde(default, skip_serializing_if = "::serde_json::Map::is_empty")]
pub credential: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Consumer-defined vocabulary naming the evidence class (e.g. "vtaContext", "mandateCredential"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.
pub kind: PayloadDelegationEvidenceKind,
///Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub reference: ::std::option::Option<PayloadDelegationEvidenceReference>,
}
impl PayloadDelegationEvidence {
pub fn builder() -> builder::PayloadDelegationEvidence {
Default::default()
}
}
///Consumer-defined vocabulary naming the evidence class (e.g. "vtaContext", "mandateCredential"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Consumer-defined vocabulary naming the evidence class (e.g. \"vtaContext\", \"mandateCredential\"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadDelegationEvidenceKind(::std::string::String);
impl ::std::ops::Deref for PayloadDelegationEvidenceKind {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadDelegationEvidenceKind> for ::std::string::String {
fn from(value: PayloadDelegationEvidenceKind) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadDelegationEvidenceKind {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 64usize {
return Err("longer than 64 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadDelegationEvidenceKind {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadDelegationEvidenceKind {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadDelegationEvidenceKind {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadDelegationEvidenceKind {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadDelegationEvidenceReference(::std::string::String);
impl ::std::ops::Deref for PayloadDelegationEvidenceReference {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadDelegationEvidenceReference> for ::std::string::String {
fn from(value: PayloadDelegationEvidenceReference) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadDelegationEvidenceReference {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadDelegationEvidenceReference {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadDelegationEvidenceReference {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadDelegationEvidenceReference {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadDelegationEvidenceReference {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The VID being authenticated as, when it differs from the signer of this document. Present and unequal to `issuer` marks a *proxied* authenticate: `issuer` is a delegate (typically the principal's VTA) presenting its own proof, and `payload.delegationEvidence` MUST also be present, describing what entitles `issuer` to act for `principal`. Omitted, or equal to `issuer`, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The VID being authenticated as, when it differs from the signer of this document. Present and unequal to `issuer` marks a *proxied* authenticate: `issuer` is a delegate (typically the principal's VTA) presenting its own proof, and `payload.delegationEvidence` MUST also be present, describing what entitles `issuer` to act for `principal`. Omitted, or equal to `issuer`, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.",
/// "type": "string",
/// "maxLength": 2048,
/// "pattern": "^did:"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadPrincipal(::std::string::String);
impl ::std::ops::Deref for PayloadPrincipal {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadPrincipal> for ::std::string::String {
fn from(value: PayloadPrincipal) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadPrincipal {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("^did:").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^did:\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadPrincipal {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadPrincipal {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadPrincipal {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadPrincipal {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`PayloadScopeItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadScopeItem(::std::string::String);
impl ::std::ops::Deref for PayloadScopeItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadScopeItem> for ::std::string::String {
fn from(value: PayloadScopeItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadScopeItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadScopeItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadScopeItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadScopeItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadScopeItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadSessionId(::std::string::String);
impl ::std::ops::Deref for PayloadSessionId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadSessionId> for ::std::string::String {
fn from(value: PayloadSessionId) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadSessionId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadSessionId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework `proof` made by this key, with `proofPurpose: authentication`, as the session's `subject` — for this session only, bounded by the session's `expiresAt` and `acr`, and never where a specification requires an `assertionMethod` attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with `auth/authenticate:sessionKeyUnsupported`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework `proof` made by this key, with `proofPurpose: authentication`, as the session's `subject` — for this session only, bounded by the session's `expiresAt` and `acr`, and never where a specification requires an `assertionMethod` attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with `auth/authenticate:sessionKeyUnsupported`.",
/// "type": "string",
/// "maxLength": 512,
/// "pattern": "^did:key:z[1-9A-HJ-NP-Za-km-z]+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadSessionKey(::std::string::String);
impl ::std::ops::Deref for PayloadSessionKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadSessionKey> for ::std::string::String {
fn from(value: PayloadSessionKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadSessionKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 512usize {
return Err("longer than 512 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^did:key:z[1-9A-HJ-NP-Za-km-z]+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^did:key:z[1-9A-HJ-NP-Za-km-z]+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadSessionKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadSessionKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadSessionKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadSessionKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Issued by the auth service after verifying the proof on the authenticate document (and, for a proxied request, the delegation evidence). Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/authenticate/0.3#response.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "Issued by the auth service after verifying the proof on the authenticate document (and, for a proxied request, the delegation evidence). Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/authenticate/0.3#response.",
/// "type": "object",
/// "required": [
/// "session",
/// "tokens"
/// ],
/// "properties": {
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "session": {
/// "description": "The session the consumer has just created for this subject. `session.subject` is `principal` for a proxied request, `issuer` otherwise; `session.actor` is present and equal to `issuer` only for a proxied request. Carries `sessionKey` when the request bound one.",
/// "$ref": "#/definitions/Session"
/// },
/// "tokens": {
/// "description": "Access + optional refresh tokens. Consumers MAY omit a refresh token when their policy doesn't support refresh.",
/// "$ref": "#/definitions/TokenBundle"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The session the consumer has just created for this subject. `session.subject` is `principal` for a proxied request, `issuer` otherwise; `session.actor` is present and equal to `issuer` only for a proxied request. Carries `sessionKey` when the request bound one.
pub session: Session,
///Access + optional refresh tokens. Consumers MAY omit a refresh token when their policy doesn't support refresh.
pub tokens: TokenBundle,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Session",
/// "description": "A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).",
/// "type": "object",
/// "required": [
/// "expiresAt",
/// "id",
/// "issuedAt",
/// "subject"
/// ],
/// "properties": {
/// "absoluteExpiresAt": {
/// "description": "The instant beyond which this session's `expiresAt` MUST NOT be advanced, by auth/refresh/0.2 or by any other means — an absolute session lifetime set once at authentication and never moved forward. Consumers that impose no such ceiling beyond the session's own rolling `expiresAt` omit this member; its absence is not itself a claim that the session is unbounded, only that this response does not state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the enforcement rule.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "acr": {
/// "description": "Authentication Context Class Reference per [OIDC Core §2]. Profiles define their own values; the recommended set is \"aal1\" (single-factor DID auth), \"aal2\" (a second possession-or-biometric factor confirmed), and \"aal3\" (hardware-bound second factor).",
/// "type": "string"
/// },
/// "actor": {
/// "description": "The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1
/// },
/// "amr": {
/// "description": "Authentication Methods References per [RFC 8176]. Typical values: \"did\" (challenge-response), \"passkey\" (WebAuthn), \"vta\" (verifiable-trust agent approval). Multi-factor sessions list every method used.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "minLength": 1
/// },
/// "minItems": 1
/// },
/// "expiresAt": {
/// "description": "ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh before this time; consumers MUST reject after. A consumer honouring `absoluteExpiresAt` MUST NOT advance this value past it, by refresh or any other means.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "id": {
/// "description": "Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.",
/// "type": "string",
/// "minLength": 1
/// },
/// "issuedAt": {
/// "description": "ISO-8601 timestamp when the session was created.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "sessionKey": {
/// "description": "The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.",
/// "type": "string",
/// "maxLength": 512,
/// "pattern": "^did:key:z[1-9A-HJ-NP-Za-km-z]+$"
/// },
/// "subject": {
/// "description": "The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.",
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "session"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Session {
///The instant beyond which this session's `expiresAt` MUST NOT be advanced, by auth/refresh/0.2 or by any other means — an absolute session lifetime set once at authentication and never moved forward. Consumers that impose no such ceiling beyond the session's own rolling `expiresAt` omit this member; its absence is not itself a claim that the session is unbounded, only that this response does not state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the enforcement rule.
#[serde(
rename = "absoluteExpiresAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub absolute_expires_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///Authentication Context Class Reference per [OIDC Core §2]. Profiles define their own values; the recommended set is "aal1" (single-factor DID auth), "aal2" (a second possession-or-biometric factor confirmed), and "aal3" (hardware-bound second factor).
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub acr: ::std::option::Option<::std::string::String>,
///The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub actor: ::std::option::Option<SessionActor>,
///Authentication Methods References per [RFC 8176]. Typical values: "did" (challenge-response), "passkey" (WebAuthn), "vta" (verifiable-trust agent approval). Multi-factor sessions list every method used.
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub amr: ::std::vec::Vec<SessionAmrItem>,
///ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh before this time; consumers MUST reject after. A consumer honouring `absoluteExpiresAt` MUST NOT advance this value past it, by refresh or any other means.
#[serde(rename = "expiresAt")]
pub expires_at: ::chrono::DateTime<::chrono::offset::Utc>,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.
pub id: SessionId,
///ISO-8601 timestamp when the session was created.
#[serde(rename = "issuedAt")]
pub issued_at: ::chrono::DateTime<::chrono::offset::Utc>,
///The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.
#[serde(
rename = "sessionKey",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub session_key: ::std::option::Option<SessionSessionKey>,
///The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.
pub subject: SessionSubject,
}
impl Session {
pub fn builder() -> builder::Session {
Default::default()
}
}
///The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct SessionActor(::std::string::String);
impl ::std::ops::Deref for SessionActor {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<SessionActor> for ::std::string::String {
fn from(value: SessionActor) -> Self {
value.0
}
}
impl ::std::str::FromStr for SessionActor {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for SessionActor {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for SessionActor {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for SessionActor {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for SessionActor {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`SessionAmrItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct SessionAmrItem(::std::string::String);
impl ::std::ops::Deref for SessionAmrItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<SessionAmrItem> for ::std::string::String {
fn from(value: SessionAmrItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for SessionAmrItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for SessionAmrItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for SessionAmrItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for SessionAmrItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for SessionAmrItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct SessionId(::std::string::String);
impl ::std::ops::Deref for SessionId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<SessionId> for ::std::string::String {
fn from(value: SessionId) -> Self {
value.0
}
}
impl ::std::str::FromStr for SessionId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for SessionId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for SessionId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for SessionId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for SessionId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.",
/// "type": "string",
/// "maxLength": 512,
/// "pattern": "^did:key:z[1-9A-HJ-NP-Za-km-z]+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct SessionSessionKey(::std::string::String);
impl ::std::ops::Deref for SessionSessionKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<SessionSessionKey> for ::std::string::String {
fn from(value: SessionSessionKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for SessionSessionKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 512usize {
return Err("longer than 512 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^did:key:z[1-9A-HJ-NP-Za-km-z]+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^did:key:z[1-9A-HJ-NP-Za-km-z]+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for SessionSessionKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for SessionSessionKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for SessionSessionKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for SessionSessionKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct SessionSubject(::std::string::String);
impl ::std::ops::Deref for SessionSubject {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<SessionSubject> for ::std::string::String {
fn from(value: SessionSubject) -> Self {
value.0
}
}
impl ::std::str::FromStr for SessionSubject {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for SessionSubject {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for SessionSubject {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for SessionSubject {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for SessionSubject {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///An access token (typically short-lived JWT) paired with an optional refresh token (typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1) conventions but are not coupled to any particular OAuth profile.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "TokenBundle",
/// "description": "An access token (typically short-lived JWT) paired with an optional refresh token (typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1) conventions but are not coupled to any particular OAuth profile.",
/// "type": "object",
/// "required": [
/// "accessToken",
/// "expiresIn",
/// "tokenType"
/// ],
/// "properties": {
/// "accessToken": {
/// "description": "Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.",
/// "type": "string",
/// "minLength": 1
/// },
/// "expiresIn": {
/// "description": "Seconds from issuance until the access token expires.",
/// "type": "integer",
/// "minimum": 1.0
/// },
/// "ext": {
/// "description": "Ecosystem-defined extension members per SPEC.md §4.5.1.",
/// "$ref": "#/definitions/Ext"
/// },
/// "refreshExpiresIn": {
/// "description": "Seconds from issuance until the refresh token expires, when one was issued.",
/// "type": "integer",
/// "minimum": 1.0
/// },
/// "refreshToken": {
/// "description": "Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.",
/// "type": "string",
/// "minLength": 1
/// },
/// "scope": {
/// "description": "Capability tags effective on this token. Format is consumer-defined; the framework imposes no syntax.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "tokenType": {
/// "description": "Token presentation scheme. Almost always \"Bearer\"; reserved for future schemes.",
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "tokenBundle"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct TokenBundle {
///Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.
#[serde(rename = "accessToken")]
pub access_token: TokenBundleAccessToken,
///Seconds from issuance until the access token expires.
#[serde(rename = "expiresIn")]
pub expires_in: ::std::num::NonZeroU64,
///Ecosystem-defined extension members per SPEC.md §4.5.1.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Seconds from issuance until the refresh token expires, when one was issued.
#[serde(
rename = "refreshExpiresIn",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub refresh_expires_in: ::std::option::Option<::std::num::NonZeroU64>,
///Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.
#[serde(
rename = "refreshToken",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub refresh_token: ::std::option::Option<TokenBundleRefreshToken>,
///Capability tags effective on this token. Format is consumer-defined; the framework imposes no syntax.
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub scope: ::std::vec::Vec<TokenBundleScopeItem>,
///Token presentation scheme. Almost always "Bearer"; reserved for future schemes.
#[serde(rename = "tokenType")]
pub token_type: TokenBundleTokenType,
}
impl TokenBundle {
pub fn builder() -> builder::TokenBundle {
Default::default()
}
}
///Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct TokenBundleAccessToken(::std::string::String);
impl ::std::ops::Deref for TokenBundleAccessToken {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<TokenBundleAccessToken> for ::std::string::String {
fn from(value: TokenBundleAccessToken) -> Self {
value.0
}
}
impl ::std::str::FromStr for TokenBundleAccessToken {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for TokenBundleAccessToken {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for TokenBundleAccessToken {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for TokenBundleAccessToken {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for TokenBundleAccessToken {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct TokenBundleRefreshToken(::std::string::String);
impl ::std::ops::Deref for TokenBundleRefreshToken {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<TokenBundleRefreshToken> for ::std::string::String {
fn from(value: TokenBundleRefreshToken) -> Self {
value.0
}
}
impl ::std::str::FromStr for TokenBundleRefreshToken {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for TokenBundleRefreshToken {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for TokenBundleRefreshToken {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for TokenBundleRefreshToken {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for TokenBundleRefreshToken {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`TokenBundleScopeItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct TokenBundleScopeItem(::std::string::String);
impl ::std::ops::Deref for TokenBundleScopeItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<TokenBundleScopeItem> for ::std::string::String {
fn from(value: TokenBundleScopeItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for TokenBundleScopeItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for TokenBundleScopeItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for TokenBundleScopeItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for TokenBundleScopeItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for TokenBundleScopeItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Token presentation scheme. Almost always "Bearer"; reserved for future schemes.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Token presentation scheme. Almost always \"Bearer\"; reserved for future schemes.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct TokenBundleTokenType(::std::string::String);
impl ::std::ops::Deref for TokenBundleTokenType {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<TokenBundleTokenType> for ::std::string::String {
fn from(value: TokenBundleTokenType) -> Self {
value.0
}
}
impl ::std::str::FromStr for TokenBundleTokenType {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for TokenBundleTokenType {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for TokenBundleTokenType {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for TokenBundleTokenType {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for TokenBundleTokenType {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct Payload {
challenge: ::std::result::Result<super::PayloadChallenge, ::std::string::String>,
delegation_evidence: ::std::result::Result<
::std::option::Option<super::PayloadDelegationEvidence>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
principal: ::std::result::Result<
::std::option::Option<super::PayloadPrincipal>,
::std::string::String,
>,
scope:
::std::result::Result<::std::vec::Vec<super::PayloadScopeItem>, ::std::string::String>,
session_id: ::std::result::Result<super::PayloadSessionId, ::std::string::String>,
session_key: ::std::result::Result<
::std::option::Option<super::PayloadSessionKey>,
::std::string::String,
>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
challenge: Err("no value supplied for challenge".to_string()),
delegation_evidence: Ok(Default::default()),
ext: Ok(Default::default()),
principal: Ok(Default::default()),
scope: Ok(Default::default()),
session_id: Err("no value supplied for session_id".to_string()),
session_key: Ok(Default::default()),
}
}
}
impl Payload {
pub fn challenge<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadChallenge>,
T::Error: ::std::fmt::Display,
{
self.challenge = value
.try_into()
.map_err(|e| format!("error converting supplied value for challenge: {e}"));
self
}
pub fn delegation_evidence<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadDelegationEvidence>>,
T::Error: ::std::fmt::Display,
{
self.delegation_evidence = value.try_into().map_err(|e| {
format!("error converting supplied value for delegation_evidence: {e}")
});
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn principal<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadPrincipal>>,
T::Error: ::std::fmt::Display,
{
self.principal = value
.try_into()
.map_err(|e| format!("error converting supplied value for principal: {e}"));
self
}
pub fn scope<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::PayloadScopeItem>>,
T::Error: ::std::fmt::Display,
{
self.scope = value
.try_into()
.map_err(|e| format!("error converting supplied value for scope: {e}"));
self
}
pub fn session_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadSessionId>,
T::Error: ::std::fmt::Display,
{
self.session_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for session_id: {e}"));
self
}
pub fn session_key<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadSessionKey>>,
T::Error: ::std::fmt::Display,
{
self.session_key = value
.try_into()
.map_err(|e| format!("error converting supplied value for session_key: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
challenge: value.challenge?,
delegation_evidence: value.delegation_evidence?,
ext: value.ext?,
principal: value.principal?,
scope: value.scope?,
session_id: value.session_id?,
session_key: value.session_key?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
challenge: Ok(value.challenge),
delegation_evidence: Ok(value.delegation_evidence),
ext: Ok(value.ext),
principal: Ok(value.principal),
scope: Ok(value.scope),
session_id: Ok(value.session_id),
session_key: Ok(value.session_key),
}
}
}
#[derive(Clone, Debug)]
pub struct PayloadDelegationEvidence {
credential: ::std::result::Result<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
kind: ::std::result::Result<super::PayloadDelegationEvidenceKind, ::std::string::String>,
reference: ::std::result::Result<
::std::option::Option<super::PayloadDelegationEvidenceReference>,
::std::string::String,
>,
}
impl ::std::default::Default for PayloadDelegationEvidence {
fn default() -> Self {
Self {
credential: Ok(Default::default()),
ext: Ok(Default::default()),
kind: Err("no value supplied for kind".to_string()),
reference: Ok(Default::default()),
}
}
}
impl PayloadDelegationEvidence {
pub fn credential<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
>,
T::Error: ::std::fmt::Display,
{
self.credential = value
.try_into()
.map_err(|e| format!("error converting supplied value for credential: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn kind<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadDelegationEvidenceKind>,
T::Error: ::std::fmt::Display,
{
self.kind = value
.try_into()
.map_err(|e| format!("error converting supplied value for kind: {e}"));
self
}
pub fn reference<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<super::PayloadDelegationEvidenceReference>,
>,
T::Error: ::std::fmt::Display,
{
self.reference = value
.try_into()
.map_err(|e| format!("error converting supplied value for reference: {e}"));
self
}
}
impl ::std::convert::TryFrom<PayloadDelegationEvidence> for super::PayloadDelegationEvidence {
type Error = super::error::ConversionError;
fn try_from(
value: PayloadDelegationEvidence,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
credential: value.credential?,
ext: value.ext?,
kind: value.kind?,
reference: value.reference?,
})
}
}
impl ::std::convert::From<super::PayloadDelegationEvidence> for PayloadDelegationEvidence {
fn from(value: super::PayloadDelegationEvidence) -> Self {
Self {
credential: Ok(value.credential),
ext: Ok(value.ext),
kind: Ok(value.kind),
reference: Ok(value.reference),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
session: ::std::result::Result<super::Session, ::std::string::String>,
tokens: ::std::result::Result<super::TokenBundle, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
session: Err("no value supplied for session".to_string()),
tokens: Err("no value supplied for tokens".to_string()),
}
}
}
impl Response {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn session<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Session>,
T::Error: ::std::fmt::Display,
{
self.session = value
.try_into()
.map_err(|e| format!("error converting supplied value for session: {e}"));
self
}
pub fn tokens<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::TokenBundle>,
T::Error: ::std::fmt::Display,
{
self.tokens = value
.try_into()
.map_err(|e| format!("error converting supplied value for tokens: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
session: value.session?,
tokens: value.tokens?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
ext: Ok(value.ext),
session: Ok(value.session),
tokens: Ok(value.tokens),
}
}
}
#[derive(Clone, Debug)]
pub struct Session {
absolute_expires_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
acr: ::std::result::Result<
::std::option::Option<::std::string::String>,
::std::string::String,
>,
actor: ::std::result::Result<
::std::option::Option<super::SessionActor>,
::std::string::String,
>,
amr: ::std::result::Result<::std::vec::Vec<super::SessionAmrItem>, ::std::string::String>,
expires_at:
::std::result::Result<::chrono::DateTime<::chrono::offset::Utc>, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
id: ::std::result::Result<super::SessionId, ::std::string::String>,
issued_at:
::std::result::Result<::chrono::DateTime<::chrono::offset::Utc>, ::std::string::String>,
session_key: ::std::result::Result<
::std::option::Option<super::SessionSessionKey>,
::std::string::String,
>,
subject: ::std::result::Result<super::SessionSubject, ::std::string::String>,
}
impl ::std::default::Default for Session {
fn default() -> Self {
Self {
absolute_expires_at: Ok(Default::default()),
acr: Ok(Default::default()),
actor: Ok(Default::default()),
amr: Ok(Default::default()),
expires_at: Err("no value supplied for expires_at".to_string()),
ext: Ok(Default::default()),
id: Err("no value supplied for id".to_string()),
issued_at: Err("no value supplied for issued_at".to_string()),
session_key: Ok(Default::default()),
subject: Err("no value supplied for subject".to_string()),
}
}
}
impl Session {
pub fn absolute_expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.absolute_expires_at = value.try_into().map_err(|e| {
format!("error converting supplied value for absolute_expires_at: {e}")
});
self
}
pub fn acr<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.acr = value
.try_into()
.map_err(|e| format!("error converting supplied value for acr: {e}"));
self
}
pub fn actor<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::SessionActor>>,
T::Error: ::std::fmt::Display,
{
self.actor = value
.try_into()
.map_err(|e| format!("error converting supplied value for actor: {e}"));
self
}
pub fn amr<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::SessionAmrItem>>,
T::Error: ::std::fmt::Display,
{
self.amr = value
.try_into()
.map_err(|e| format!("error converting supplied value for amr: {e}"));
self
}
pub fn expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::chrono::DateTime<::chrono::offset::Utc>>,
T::Error: ::std::fmt::Display,
{
self.expires_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_at: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::SessionId>,
T::Error: ::std::fmt::Display,
{
self.id = value
.try_into()
.map_err(|e| format!("error converting supplied value for id: {e}"));
self
}
pub fn issued_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::chrono::DateTime<::chrono::offset::Utc>>,
T::Error: ::std::fmt::Display,
{
self.issued_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for issued_at: {e}"));
self
}
pub fn session_key<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::SessionSessionKey>>,
T::Error: ::std::fmt::Display,
{
self.session_key = value
.try_into()
.map_err(|e| format!("error converting supplied value for session_key: {e}"));
self
}
pub fn subject<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::SessionSubject>,
T::Error: ::std::fmt::Display,
{
self.subject = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject: {e}"));
self
}
}
impl ::std::convert::TryFrom<Session> for super::Session {
type Error = super::error::ConversionError;
fn try_from(value: Session) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
absolute_expires_at: value.absolute_expires_at?,
acr: value.acr?,
actor: value.actor?,
amr: value.amr?,
expires_at: value.expires_at?,
ext: value.ext?,
id: value.id?,
issued_at: value.issued_at?,
session_key: value.session_key?,
subject: value.subject?,
})
}
}
impl ::std::convert::From<super::Session> for Session {
fn from(value: super::Session) -> Self {
Self {
absolute_expires_at: Ok(value.absolute_expires_at),
acr: Ok(value.acr),
actor: Ok(value.actor),
amr: Ok(value.amr),
expires_at: Ok(value.expires_at),
ext: Ok(value.ext),
id: Ok(value.id),
issued_at: Ok(value.issued_at),
session_key: Ok(value.session_key),
subject: Ok(value.subject),
}
}
}
#[derive(Clone, Debug)]
pub struct TokenBundle {
access_token: ::std::result::Result<super::TokenBundleAccessToken, ::std::string::String>,
expires_in: ::std::result::Result<::std::num::NonZeroU64, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
refresh_expires_in: ::std::result::Result<
::std::option::Option<::std::num::NonZeroU64>,
::std::string::String,
>,
refresh_token: ::std::result::Result<
::std::option::Option<super::TokenBundleRefreshToken>,
::std::string::String,
>,
scope: ::std::result::Result<
::std::vec::Vec<super::TokenBundleScopeItem>,
::std::string::String,
>,
token_type: ::std::result::Result<super::TokenBundleTokenType, ::std::string::String>,
}
impl ::std::default::Default for TokenBundle {
fn default() -> Self {
Self {
access_token: Err("no value supplied for access_token".to_string()),
expires_in: Err("no value supplied for expires_in".to_string()),
ext: Ok(Default::default()),
refresh_expires_in: Ok(Default::default()),
refresh_token: Ok(Default::default()),
scope: Ok(Default::default()),
token_type: Err("no value supplied for token_type".to_string()),
}
}
}
impl TokenBundle {
pub fn access_token<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::TokenBundleAccessToken>,
T::Error: ::std::fmt::Display,
{
self.access_token = value
.try_into()
.map_err(|e| format!("error converting supplied value for access_token: {e}"));
self
}
pub fn expires_in<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::num::NonZeroU64>,
T::Error: ::std::fmt::Display,
{
self.expires_in = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_in: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn refresh_expires_in<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::num::NonZeroU64>>,
T::Error: ::std::fmt::Display,
{
self.refresh_expires_in = value.try_into().map_err(|e| {
format!("error converting supplied value for refresh_expires_in: {e}")
});
self
}
pub fn refresh_token<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::TokenBundleRefreshToken>>,
T::Error: ::std::fmt::Display,
{
self.refresh_token = value
.try_into()
.map_err(|e| format!("error converting supplied value for refresh_token: {e}"));
self
}
pub fn scope<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::TokenBundleScopeItem>>,
T::Error: ::std::fmt::Display,
{
self.scope = value
.try_into()
.map_err(|e| format!("error converting supplied value for scope: {e}"));
self
}
pub fn token_type<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::TokenBundleTokenType>,
T::Error: ::std::fmt::Display,
{
self.token_type = value
.try_into()
.map_err(|e| format!("error converting supplied value for token_type: {e}"));
self
}
}
impl ::std::convert::TryFrom<TokenBundle> for super::TokenBundle {
type Error = super::error::ConversionError;
fn try_from(
value: TokenBundle,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
access_token: value.access_token?,
expires_in: value.expires_in?,
ext: value.ext?,
refresh_expires_in: value.refresh_expires_in?,
refresh_token: value.refresh_token?,
scope: value.scope?,
token_type: value.token_type?,
})
}
}
impl ::std::convert::From<super::TokenBundle> for TokenBundle {
fn from(value: super::TokenBundle) -> Self {
Self {
access_token: Ok(value.access_token),
expires_in: Ok(value.expires_in),
ext: Ok(value.ext),
refresh_expires_in: Ok(value.refresh_expires_in),
refresh_token: Ok(value.refresh_token),
scope: Ok(value.scope),
token_type: Ok(value.token_type),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/auth/authenticate/0.3";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Issued by the auth service after verifying the proof on the authenticate document (and, for a proxied request, the delegation evidence). Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/authenticate/0.3#response.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"session\": {\n \"$ref\": \"#/$defs/Session\",\n \"description\": \"The session the consumer has just created for this subject. `session.subject` is `principal` for a proxied request, `issuer` otherwise; `session.actor` is present and equal to `issuer` only for a proxied request. Carries `sessionKey` when the request bound one.\"\n },\n \"tokens\": {\n \"$ref\": \"#/$defs/TokenBundle\",\n \"description\": \"Access + optional refresh tokens. Consumers MAY omit a refresh token when their policy doesn't support refresh.\"\n }\n },\n \"required\": [\n \"session\",\n \"tokens\"\n ],\n \"title\": \"Auth Authenticate — response payload\",\n \"type\": \"object\"\n },\n \"Session\": {\n \"$anchor\": \"session\",\n \"additionalProperties\": false,\n \"description\": \"A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).\",\n \"properties\": {\n \"absoluteExpiresAt\": {\n \"description\": \"The instant beyond which this session's `expiresAt` MUST NOT be advanced, by auth/refresh/0.2 or by any other means — an absolute session lifetime set once at authentication and never moved forward. Consumers that impose no such ceiling beyond the session's own rolling `expiresAt` omit this member; its absence is not itself a claim that the session is unbounded, only that this response does not state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the enforcement rule.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"acr\": {\n \"description\": \"Authentication Context Class Reference per [OIDC Core §2]. Profiles define their own values; the recommended set is \\\"aal1\\\" (single-factor DID auth), \\\"aal2\\\" (a second possession-or-biometric factor confirmed), and \\\"aal3\\\" (hardware-bound second factor).\",\n \"type\": \"string\"\n },\n \"actor\": {\n \"description\": \"The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).\",\n \"maxLength\": 2048,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"amr\": {\n \"description\": \"Authentication Methods References per [RFC 8176]. Typical values: \\\"did\\\" (challenge-response), \\\"passkey\\\" (WebAuthn), \\\"vta\\\" (verifiable-trust agent approval). Multi-factor sessions list every method used.\",\n \"items\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"expiresAt\": {\n \"description\": \"ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh before this time; consumers MUST reject after. A consumer honouring `absoluteExpiresAt` MUST NOT advance this value past it, by refresh or any other means.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"id\": {\n \"description\": \"Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"issuedAt\": {\n \"description\": \"ISO-8601 timestamp when the session was created.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"sessionKey\": {\n \"description\": \"The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.\",\n \"maxLength\": 512,\n \"pattern\": \"^did:key:z[1-9A-HJ-NP-Za-km-z]+$\",\n \"type\": \"string\"\n },\n \"subject\": {\n \"description\": \"The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"id\",\n \"subject\",\n \"issuedAt\",\n \"expiresAt\"\n ],\n \"title\": \"Session\",\n \"type\": \"object\"\n },\n \"TokenBundle\": {\n \"$anchor\": \"tokenBundle\",\n \"additionalProperties\": false,\n \"description\": \"An access token (typically short-lived JWT) paired with an optional refresh token (typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1) conventions but are not coupled to any particular OAuth profile.\",\n \"properties\": {\n \"accessToken\": {\n \"description\": \"Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"expiresIn\": {\n \"description\": \"Seconds from issuance until the access token expires.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"refreshExpiresIn\": {\n \"description\": \"Seconds from issuance until the refresh token expires, when one was issued.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"refreshToken\": {\n \"description\": \"Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"scope\": {\n \"description\": \"Capability tags effective on this token. Format is consumer-defined; the framework imposes no syntax.\",\n \"items\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"type\": \"array\"\n },\n \"tokenType\": {\n \"description\": \"Token presentation scheme. Almost always \\\"Bearer\\\"; reserved for future schemes.\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"accessToken\",\n \"tokenType\",\n \"expiresIn\"\n ],\n \"title\": \"TokenBundle\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/auth/authenticate/0.3\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"The subject presents a previously-issued challenge along with the framework `proof` that binds the document to a VID. The proof IS the authentication. 0.3 adds an optional proxied form: `principal` names a party the signer authenticates *as*, distinct from `issuer` (the signer, e.g. a VTA acting on the principal's behalf), together with `delegationEvidence` establishing the entitlement. Absent `principal`, or `principal` equal to `issuer`, is the ordinary auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional `sessionKey` member from 0.2.\",\n \"properties\": {\n \"challenge\": {\n \"description\": \"The exact challenge value returned by a prior auth/challenge call. Consumers MUST reject mismatch, expired, or re-used challenges.\",\n \"minLength\": 16,\n \"type\": \"string\"\n },\n \"delegationEvidence\": {\n \"additionalProperties\": false,\n \"description\": \"REQUIRED whenever `principal` is present and differs from `issuer`; MUST be omitted otherwise. Describes the evidence that entitles `issuer` to authenticate as `principal`. The framework does not prescribe its shape — see Authorization — but the consumer's policy MUST verify it independently rather than take `issuer`'s claim of entitlement at face value.\",\n \"properties\": {\n \"credential\": {\n \"description\": \"The evidence itself, inline — typically a Verifiable Credential or other signed assertion binding `issuer` to `principal`. Opaque to the framework; shape is consumer- or ecosystem-defined by `kind`.\",\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"kind\": {\n \"description\": \"Consumer-defined vocabulary naming the evidence class (e.g. \\\"vtaContext\\\", \\\"mandateCredential\\\"). The framework imposes no syntax; an unrecognized `kind` is refused with `auth/authenticate:delegationNotRecognized`.\",\n \"maxLength\": 64,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"reference\": {\n \"description\": \"Alternative to inlining `credential`: an opaque reference (an id, a URL) to evidence the consumer already holds — for example a previously-registered VTA context binding. Consumer-defined; mutually informative with `credential`, not mutually exclusive — a producer MAY supply both.\",\n \"maxLength\": 2048,\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"kind\"\n ],\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"principal\": {\n \"description\": \"The VID being authenticated as, when it differs from the signer of this document. Present and unequal to `issuer` marks a *proxied* authenticate: `issuer` is a delegate (typically the principal's VTA) presenting its own proof, and `payload.delegationEvidence` MUST also be present, describing what entitles `issuer` to act for `principal`. Omitted, or equal to `issuer`, is the ordinary case: the signer authenticates as itself, exactly as auth/authenticate/0.2. See Authorization and Security & Privacy.\",\n \"maxLength\": 2048,\n \"pattern\": \"^did:\",\n \"type\": \"string\"\n },\n \"scope\": {\n \"description\": \"Optional capability tags being requested on the issued tokens. The consumer's authorization layer decides which are granted; the issued TokenBundle's `scope` MAY be a subset.\",\n \"items\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"type\": \"array\"\n },\n \"sessionId\": {\n \"description\": \"The sessionId returned alongside the challenge. Consumers use it to look up the server-side challenge binding.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"sessionKey\": {\n \"description\": \"A did:key VID the producer asks the consumer to bind to the session this authenticate document creates. The producer MUST hold the corresponding private key and SHOULD keep it non-extractable (for example, a WebCrypto non-extractable key). Once bound, the consumer MUST accept a framework `proof` made by this key, with `proofPurpose: authentication`, as the session's `subject` — for this session only, bounded by the session's `expiresAt` and `acr`, and never where a specification requires an `assertionMethod` attestation (SPEC.md §7.2 item 10; see Security & Privacy). Behaves identically whether or not this document is a proxied authenticate. The consumer MAY refuse a key type it does not support with `auth/authenticate:sessionKeyUnsupported`.\",\n \"maxLength\": 512,\n \"pattern\": \"^did:key:z[1-9A-HJ-NP-Za-km-z]+$\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"challenge\",\n \"sessionId\"\n ],\n \"title\": \"Auth — Authenticate\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/auth/authenticate/0.3#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"Issued by the auth service after verifying the proof on the authenticate document (and, for a proxied request, the delegation evidence). Carried in a Trust Task document whose type is https://trusttasks.org/spec/auth/authenticate/0.3#response.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"session\": {\n \"$ref\": \"#/$defs/Session\",\n \"description\": \"The session the consumer has just created for this subject. `session.subject` is `principal` for a proxied request, `issuer` otherwise; `session.actor` is present and equal to `issuer` only for a proxied request. Carries `sessionKey` when the request bound one.\"\n },\n \"tokens\": {\n \"$ref\": \"#/$defs/TokenBundle\",\n \"description\": \"Access + optional refresh tokens. Consumers MAY omit a refresh token when their policy doesn't support refresh.\"\n }\n },\n \"required\": [\n \"session\",\n \"tokens\"\n ],\n \"title\": \"Auth Authenticate — response payload\",\n \"type\": \"object\"\n },\n \"Session\": {\n \"$anchor\": \"session\",\n \"additionalProperties\": false,\n \"description\": \"A logical authentication context bound to a subject. Producers and consumers exchange Session-shaped data in challenge issuance, authentication responses, and introspection (whoami).\",\n \"properties\": {\n \"absoluteExpiresAt\": {\n \"description\": \"The instant beyond which this session's `expiresAt` MUST NOT be advanced, by auth/refresh/0.2 or by any other means — an absolute session lifetime set once at authentication and never moved forward. Consumers that impose no such ceiling beyond the session's own rolling `expiresAt` omit this member; its absence is not itself a claim that the session is unbounded, only that this response does not state a bound. See auth/refresh/0.2 Conformance and Security & Privacy for the enforcement rule.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"acr\": {\n \"description\": \"Authentication Context Class Reference per [OIDC Core §2]. Profiles define their own values; the recommended set is \\\"aal1\\\" (single-factor DID auth), \\\"aal2\\\" (a second possession-or-biometric factor confirmed), and \\\"aal3\\\" (hardware-bound second factor).\",\n \"type\": \"string\"\n },\n \"actor\": {\n \"description\": \"The delegate's VID — the party whose `proof` actually authenticated this session — when this session was established by a *proxied* login (auth/authenticate/0.3, `payload.principal` present and distinct from `issuer`). Absent whenever `subject` authenticated with its own key, including every auth/authenticate/0.1 and /0.2 session and an auth/authenticate/0.3 request where `principal` is absent or equals `issuer`. Carrying `actor` separately from `subject` is what lets an audit trail, a revocation, or a response to a compromised delegate name the true acting party without conflating it with the principal it acted for — see auth/authenticate/0.3 Security & Privacy (Correlation).\",\n \"maxLength\": 2048,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"amr\": {\n \"description\": \"Authentication Methods References per [RFC 8176]. Typical values: \\\"did\\\" (challenge-response), \\\"passkey\\\" (WebAuthn), \\\"vta\\\" (verifiable-trust agent approval). Multi-factor sessions list every method used.\",\n \"items\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"expiresAt\": {\n \"description\": \"ISO-8601 timestamp when the session ceases to be valid. Producers SHOULD refresh before this time; consumers MUST reject after. A consumer honouring `absoluteExpiresAt` MUST NOT advance this value past it, by refresh or any other means.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"id\": {\n \"description\": \"Opaque, server-chosen session identifier. Stable for the lifetime of the session. Consumers MUST treat the value as opaque; no structure is implied.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"issuedAt\": {\n \"description\": \"ISO-8601 timestamp when the session was created.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"sessionKey\": {\n \"description\": \"The did:key VID bound to this session by auth/authenticate/0.2 or 0.3, when the producer registered one. Present here so introspection (auth/whoami, auth/sessions/list) can show the binding a client already holds; it is descriptive, not an additional grant — the binding, its scope and its lifetime are governed entirely by the auth/authenticate specification version that established it. Absent when the session was established without a session key, or by a specification version that does not carry one.\",\n \"maxLength\": 512,\n \"pattern\": \"^did:key:z[1-9A-HJ-NP-Za-km-z]+$\",\n \"type\": \"string\"\n },\n \"subject\": {\n \"description\": \"The authenticated party's VID (typically a DID URL). For a session established by a proxied login (auth/authenticate/0.3), this is the *principal* being authenticated as — never the delegate that signed the authenticate document; see `actor`.\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"id\",\n \"subject\",\n \"issuedAt\",\n \"expiresAt\"\n ],\n \"title\": \"Session\",\n \"type\": \"object\"\n },\n \"TokenBundle\": {\n \"$anchor\": \"tokenBundle\",\n \"additionalProperties\": false,\n \"description\": \"An access token (typically short-lived JWT) paired with an optional refresh token (typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1) conventions but are not coupled to any particular OAuth profile.\",\n \"properties\": {\n \"accessToken\": {\n \"description\": \"Bearer-style access token. Consumers presenting this token to downstream services prove the holder of the original session. Format is consumer-defined — JWT is common, but opaque strings are also valid.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"expiresIn\": {\n \"description\": \"Seconds from issuance until the access token expires.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\",\n \"description\": \"Ecosystem-defined extension members per SPEC.md §4.5.1.\"\n },\n \"refreshExpiresIn\": {\n \"description\": \"Seconds from issuance until the refresh token expires, when one was issued.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"refreshToken\": {\n \"description\": \"Long-lived token redeemable via auth/refresh for a new access token. MAY be absent when the issuer does not support refresh.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"scope\": {\n \"description\": \"Capability tags effective on this token. Format is consumer-defined; the framework imposes no syntax.\",\n \"items\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"type\": \"array\"\n },\n \"tokenType\": {\n \"description\": \"Token presentation scheme. Almost always \\\"Bearer\\\"; reserved for future schemes.\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"accessToken\",\n \"tokenType\",\n \"expiresIn\"\n ],\n \"title\": \"TokenBundle\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::CHALLENGE_NOT_FOUND,
error_codes::CHALLENGE_EXPIRED,
error_codes::CHALLENGE_MISMATCH,
error_codes::SUBJECT_MISMATCH,
error_codes::SCOPE_DENIED,
error_codes::SESSION_KEY_UNSUPPORTED,
error_codes::DELEGATION_EVIDENCE_REQUIRED,
error_codes::DELEGATION_NOT_RECOGNIZED,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `auth/authenticate:challengeNotFound`
///
/// The `sessionId` does not refer to any challenge the auth service issued, or the challenge was already consumed.
///
/// Declared `retryable: false`.
pub const CHALLENGE_NOT_FOUND: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:challengeNotFound",
retryable: false,
};
/// `auth/authenticate:challengeExpired`
///
/// The challenge's expiresAt is in the past.
///
/// Declared `retryable: true`.
pub const CHALLENGE_EXPIRED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:challengeExpired",
retryable: true,
};
/// `auth/authenticate:challengeMismatch`
///
/// The presented `challenge` value does not equal the one the auth service bound to `sessionId`.
///
/// Declared `retryable: false`.
pub const CHALLENGE_MISMATCH: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:challengeMismatch",
retryable: false,
};
/// `auth/authenticate:subjectMismatch`
///
/// The verified acting party — `payload.principal` for a proxied request, otherwise the document's `issuer` — does not equal the `subject` the challenge was bound to.
///
/// Declared `retryable: false`.
pub const SUBJECT_MISMATCH: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:subjectMismatch",
retryable: false,
};
/// `auth/authenticate:scopeDenied`
///
/// One or more requested scopes were refused by the consumer's authorization policy. `details.refused` MAY enumerate the denied scopes.
///
/// Declared `retryable: false`.
pub const SCOPE_DENIED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:scopeDenied",
retryable: false,
};
/// `auth/authenticate:sessionKeyUnsupported`
///
/// The consumer does not support the key type or DID method of the requested `sessionKey` (for example, a `did:key` encoding a curve the consumer's verifier does not implement) and refuses the request rather than silently authenticating without the binding. `details.requested` MAY echo the offending `sessionKey`.
///
/// Declared `retryable: false`.
pub const SESSION_KEY_UNSUPPORTED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:sessionKeyUnsupported",
retryable: false,
};
/// `auth/authenticate:delegationEvidenceRequired`
///
/// `payload.principal` is present and differs from the document's `issuer`, but `payload.delegationEvidence` is absent. A proxied authenticate MUST carry both.
///
/// Declared `retryable: false`.
pub const DELEGATION_EVIDENCE_REQUIRED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:delegationEvidenceRequired",
retryable: false,
};
/// `auth/authenticate:delegationNotRecognized`
///
/// `payload.delegationEvidence` was present but did not establish, under the consumer's own authorization policy, that `issuer` is entitled to authenticate as `principal` — an unrecognized `kind`, a reference the consumer cannot resolve, a credential that fails verification, or one that verifies but names a different principal or has expired or been revoked.
///
/// Declared `retryable: false`.
pub const DELEGATION_NOT_RECOGNIZED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/authenticate:delegationNotRecognized",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"1a2b3c4d-5e6f-7890-1234-567890abcdef\",\n \"type\": \"https://trusttasks.org/spec/auth/authenticate/0.3\",\n \"issuer\": \"did:web:alice.example\",\n \"recipient\": \"did:web:auth.example\",\n \"issuedAt\": \"2026-05-23T10:00:30Z\",\n \"payload\": {\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n },\n \"proof\": {\n \"type\": \"DataIntegrityProof\",\n \"cryptosuite\": \"eddsa-jcs-2022\",\n \"verificationMethod\": \"did:web:alice.example#key-1\",\n \"created\": \"2026-05-23T10:00:30Z\",\n \"proofPurpose\": \"authentication\",\n \"proofValue\": \"z3kg…\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_2() {
const JSON: &str = "{\n \"id\": \"9a1b2c3d-4e5f-6071-8293-a4b5c6d7e8f9\",\n \"type\": \"https://trusttasks.org/spec/auth/authenticate/0.3\",\n \"issuer\": \"did:web:vta.alice.example\",\n \"recipient\": \"did:web:auth.example\",\n \"issuedAt\": \"2026-05-23T10:00:30Z\",\n \"payload\": {\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"principal\": \"did:web:alice.example\",\n \"delegationEvidence\": {\n \"kind\": \"vtaContext\",\n \"reference\": \"vta-context:personal/console\"\n }\n },\n \"proof\": {\n \"type\": \"DataIntegrityProof\",\n \"cryptosuite\": \"eddsa-jcs-2022\",\n \"verificationMethod\": \"did:web:vta.alice.example#key-1\",\n \"created\": \"2026-05-23T10:00:30Z\",\n \"proofPurpose\": \"authentication\",\n \"proofValue\": \"z9pq…\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_3() {
const JSON: &str = "{\n \"id\": \"bad-proxy-no-evidence-0001\",\n \"type\": \"https://trusttasks.org/spec/auth/authenticate/0.3\",\n \"issuer\": \"did:web:vta.alice.example\",\n \"recipient\": \"did:web:auth.example\",\n \"issuedAt\": \"2026-05-23T10:00:30Z\",\n \"payload\": {\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"principal\": \"did:web:alice.example\"\n },\n \"proof\": {\n \"type\": \"DataIntegrityProof\",\n \"cryptosuite\": \"eddsa-jcs-2022\",\n \"verificationMethod\": \"did:web:vta.alice.example#key-1\",\n \"created\": \"2026-05-23T10:00:30Z\",\n \"proofPurpose\": \"authentication\",\n \"proofValue\": \"z9pq…\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"3c4d5e6f-7890-1234-5678-90abcdef1234\",\n \"type\": \"https://trusttasks.org/spec/auth/authenticate/0.3#response\",\n \"threadId\": \"9a1b2c3d-4e5f-6071-8293-a4b5c6d7e8f9\",\n \"issuer\": \"did:web:auth.example\",\n \"recipient\": \"did:web:vta.alice.example\",\n \"issuedAt\": \"2026-05-23T10:00:31Z\",\n \"payload\": {\n \"session\": {\n \"id\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"subject\": \"did:web:alice.example\",\n \"actor\": \"did:web:vta.alice.example\",\n \"issuedAt\": \"2026-05-23T10:00:31Z\",\n \"expiresAt\": \"2026-05-23T10:15:31Z\",\n \"absoluteExpiresAt\": \"2026-05-24T10:00:31Z\",\n \"amr\": [\"did\"],\n \"acr\": \"aal1\"\n },\n \"tokens\": {\n \"accessToken\": \"eyJhbGciOiJFZERTQSIsInR5cCI6IkpXVCJ9…\",\n \"refreshToken\": \"rt_8f2c1d4e9a7b3056\",\n \"tokenType\": \"Bearer\",\n \"expiresIn\": 900,\n \"refreshExpiresIn\": 86400\n }\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
#[test]
fn response_example_2() {
const JSON: &str = "{\n \"id\": \"5d6e7f80-9123-4567-8901-abcdef123456\",\n \"type\": \"https://trusttasks.org/spec/auth/authenticate/0.3#response\",\n \"threadId\": \"1a2b3c4d-5e6f-7890-1234-567890abcdef\",\n \"issuer\": \"did:web:auth.example\",\n \"recipient\": \"did:web:alice.example\",\n \"issuedAt\": \"2026-05-23T10:00:31Z\",\n \"payload\": {\n \"session\": {\n \"id\": \"fa6e4d90-4a5a-4ac3-8e8e-3b9d1b8b8c0c\",\n \"subject\": \"did:web:alice.example\",\n \"issuedAt\": \"2026-05-23T10:00:31Z\",\n \"expiresAt\": \"2026-05-23T10:15:31Z\",\n \"absoluteExpiresAt\": \"2026-05-24T10:00:31Z\",\n \"amr\": [\"did\"],\n \"acr\": \"aal1\",\n \"sessionKey\": \"did:key:z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH\"\n },\n \"tokens\": {\n \"accessToken\": \"eyJhbGciOiJFZERTQSIsInR5cCI6IkpXVCJ9…\",\n \"refreshToken\": \"rt_1a2b3c4d5e6f7080\",\n \"tokenType\": \"Bearer\",\n \"expiresIn\": 900,\n \"refreshExpiresIn\": 86400\n }\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Missing required `challenge` field.",
"{\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
(
"Missing required `sessionId` field.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\"\n}",
),
(
"Challenge too short — schema enforces ≥16 chars (the wire form of a 128-bit nonce in base64url is ≥22 chars; the floor here is liberal to allow padded encodings).",
"{\n \"challenge\": \"short\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
(
"Unknown top-level payload member.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"frobnicate\": true,\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
(
"sessionKey is not a did:key VID — the schema requires the did:key method specifically (bare multikey or another DID method is rejected), for consistency with the passkey path's did:key session-key store.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"sessionKey\": \"did:web:alice.example#session-1\"\n}",
),
(
"sessionKey carrying a bare multikey instead of a did:key VID — the schema requires the did:key: prefix, not the raw multibase-encoded key alone.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"sessionKey\": \"z6MkpTHR8VNsBxYAAWHut2Geadd9jSwuBV8xRoAnwWsdvktH\"\n}",
),
(
"principal is not a DID (`did:` prefix required) — a bare handle is not a VID the delegation machinery can reason about.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"principal\": \"alice.example\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
(
"delegationEvidence missing required `kind` — the consumer's policy has no vocabulary to evaluate an evidence object that doesn't say what class it is, so `kind` is REQUIRED whenever the member is present at all.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"delegationEvidence\": {\n \"reference\": \"vta-context:personal/console\"\n },\n \"principal\": \"did:web:alice.example\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
(
"delegationEvidence carrying an unknown member — additionalProperties: false catches a producer inventing its own field instead of using `kind`/`credential`/`reference`/`ext`.",
"{\n \"challenge\": \"ZGN3RvOXh0c3JydWxsbmJzcmVxdHJjQVZjbA\",\n \"delegationEvidence\": {\n \"kind\": \"vtaContext\",\n \"trustMe\": true\n },\n \"principal\": \"did:web:alice.example\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}