//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `auth/step-up/start`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`Payload`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/auth/step-up/start/0.1",
/// "title": "Payload",
/// "type": "object",
/// "required": [
/// "sessionId"
/// ],
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "sessionId": {
/// "description": "The relying-party session to elevate.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
/// },
/// "targetAcr": {
/// "description": "The assurance level the holder wants the session raised to. Absent means the relying party's own next level above the session's current one.",
/// "type": "string",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///The relying-party session to elevate.
#[serde(rename = "sessionId")]
pub session_id: PayloadSessionId,
///The assurance level the holder wants the session raised to. Absent means the relying party's own next level above the session's current one.
#[serde(
rename = "targetAcr",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub target_acr: ::std::option::Option<PayloadTargetAcr>,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///The relying-party session to elevate.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The relying-party session to elevate.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadSessionId(::std::string::String);
impl ::std::ops::Deref for PayloadSessionId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadSessionId> for ::std::string::String {
fn from(value: PayloadSessionId) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadSessionId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadSessionId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadSessionId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The assurance level the holder wants the session raised to. Absent means the relying party's own next level above the session's current one.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The assurance level the holder wants the session raised to. Absent means the relying party's own next level above the session's current one.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadTargetAcr(::std::string::String);
impl ::std::ops::Deref for PayloadTargetAcr {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadTargetAcr> for ::std::string::String {
fn from(value: PayloadTargetAcr) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadTargetAcr {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadTargetAcr {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadTargetAcr {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadTargetAcr {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadTargetAcr {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`Response`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "type": "object",
/// "required": [
/// "approveRequest"
/// ],
/// "properties": {
/// "approveRequest": {
/// "description": "A complete, signed auth/step-up/approve-request/0.3 document for this session: issuer the relying party, recipient the approver. The approver verifies it on its own terms; the framework-level envelope members are modelled here so none are lost on receipt, but `payload` and `proof` are carried opaque (unpacked and re-validated by that spec, not by this one) so the proof survives.",
/// "type": "object",
/// "required": [
/// "id",
/// "issuer",
/// "payload",
/// "proof",
/// "recipient",
/// "type"
/// ],
/// "properties": {
/// "expiresAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "id": {
/// "type": "string",
/// "minLength": 1
/// },
/// "issuedAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "issuer": {
/// "type": "string",
/// "minLength": 1
/// },
/// "payload": {
/// "description": "The auth/step-up/approve-request/0.3 payload, opaque here — see that spec for its shape."
/// },
/// "proof": {
/// "description": "A W3C Data Integrity proof (SPEC §4.7), opaque here — the approver verifies it on its own terms.",
/// "type": "object"
/// },
/// "recipient": {
/// "type": "string",
/// "minLength": 1
/// },
/// "threadId": {
/// "type": "string",
/// "minLength": 1
/// },
/// "type": {
/// "const": "https://trusttasks.org/spec/auth/step-up/approve-request/0.3"
/// }
/// },
/// "additionalProperties": false
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(rename = "approveRequest")]
pub approve_request: ResponseApproveRequest,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///A complete, signed auth/step-up/approve-request/0.3 document for this session: issuer the relying party, recipient the approver. The approver verifies it on its own terms; the framework-level envelope members are modelled here so none are lost on receipt, but `payload` and `proof` are carried opaque (unpacked and re-validated by that spec, not by this one) so the proof survives.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "A complete, signed auth/step-up/approve-request/0.3 document for this session: issuer the relying party, recipient the approver. The approver verifies it on its own terms; the framework-level envelope members are modelled here so none are lost on receipt, but `payload` and `proof` are carried opaque (unpacked and re-validated by that spec, not by this one) so the proof survives.",
/// "type": "object",
/// "required": [
/// "id",
/// "issuer",
/// "payload",
/// "proof",
/// "recipient",
/// "type"
/// ],
/// "properties": {
/// "expiresAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "id": {
/// "type": "string",
/// "minLength": 1
/// },
/// "issuedAt": {
/// "type": "string",
/// "format": "date-time"
/// },
/// "issuer": {
/// "type": "string",
/// "minLength": 1
/// },
/// "payload": {
/// "description": "The auth/step-up/approve-request/0.3 payload, opaque here — see that spec for its shape."
/// },
/// "proof": {
/// "description": "A W3C Data Integrity proof (SPEC §4.7), opaque here — the approver verifies it on its own terms.",
/// "type": "object"
/// },
/// "recipient": {
/// "type": "string",
/// "minLength": 1
/// },
/// "threadId": {
/// "type": "string",
/// "minLength": 1
/// },
/// "type": {
/// "const": "https://trusttasks.org/spec/auth/step-up/approve-request/0.3"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct ResponseApproveRequest {
#[serde(
rename = "expiresAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub expires_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
pub id: ResponseApproveRequestId,
#[serde(
rename = "issuedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub issued_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
pub issuer: ResponseApproveRequestIssuer,
///The auth/step-up/approve-request/0.3 payload, opaque here — see that spec for its shape.
pub payload: ::serde_json::Value,
///A W3C Data Integrity proof (SPEC §4.7), opaque here — the approver verifies it on its own terms.
pub proof: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
pub recipient: ResponseApproveRequestRecipient,
#[serde(
rename = "threadId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub thread_id: ::std::option::Option<ResponseApproveRequestThreadId>,
#[serde(rename = "type")]
pub type_: ::serde_json::Value,
}
impl ResponseApproveRequest {
pub fn builder() -> builder::ResponseApproveRequest {
Default::default()
}
}
///`ResponseApproveRequestId`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseApproveRequestId(::std::string::String);
impl ::std::ops::Deref for ResponseApproveRequestId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseApproveRequestId> for ::std::string::String {
fn from(value: ResponseApproveRequestId) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseApproveRequestId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseApproveRequestId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseApproveRequestId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseApproveRequestId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseApproveRequestId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`ResponseApproveRequestIssuer`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseApproveRequestIssuer(::std::string::String);
impl ::std::ops::Deref for ResponseApproveRequestIssuer {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseApproveRequestIssuer> for ::std::string::String {
fn from(value: ResponseApproveRequestIssuer) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseApproveRequestIssuer {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseApproveRequestIssuer {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseApproveRequestIssuer {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseApproveRequestIssuer {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseApproveRequestIssuer {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`ResponseApproveRequestRecipient`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseApproveRequestRecipient(::std::string::String);
impl ::std::ops::Deref for ResponseApproveRequestRecipient {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseApproveRequestRecipient> for ::std::string::String {
fn from(value: ResponseApproveRequestRecipient) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseApproveRequestRecipient {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseApproveRequestRecipient {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseApproveRequestRecipient {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseApproveRequestRecipient {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseApproveRequestRecipient {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`ResponseApproveRequestThreadId`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseApproveRequestThreadId(::std::string::String);
impl ::std::ops::Deref for ResponseApproveRequestThreadId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseApproveRequestThreadId> for ::std::string::String {
fn from(value: ResponseApproveRequestThreadId) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseApproveRequestThreadId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseApproveRequestThreadId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseApproveRequestThreadId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseApproveRequestThreadId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseApproveRequestThreadId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct Payload {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
session_id: ::std::result::Result<super::PayloadSessionId, ::std::string::String>,
target_acr: ::std::result::Result<
::std::option::Option<super::PayloadTargetAcr>,
::std::string::String,
>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
session_id: Err("no value supplied for session_id".to_string()),
target_acr: Ok(Default::default()),
}
}
}
impl Payload {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn session_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::PayloadSessionId>,
T::Error: ::std::fmt::Display,
{
self.session_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for session_id: {e}"));
self
}
pub fn target_acr<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::PayloadTargetAcr>>,
T::Error: ::std::fmt::Display,
{
self.target_acr = value
.try_into()
.map_err(|e| format!("error converting supplied value for target_acr: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
session_id: value.session_id?,
target_acr: value.target_acr?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
ext: Ok(value.ext),
session_id: Ok(value.session_id),
target_acr: Ok(value.target_acr),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
approve_request:
::std::result::Result<super::ResponseApproveRequest, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
approve_request: Err("no value supplied for approve_request".to_string()),
ext: Ok(Default::default()),
}
}
}
impl Response {
pub fn approve_request<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ResponseApproveRequest>,
T::Error: ::std::fmt::Display,
{
self.approve_request = value
.try_into()
.map_err(|e| format!("error converting supplied value for approve_request: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
approve_request: value.approve_request?,
ext: value.ext?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
approve_request: Ok(value.approve_request),
ext: Ok(value.ext),
}
}
}
#[derive(Clone, Debug)]
pub struct ResponseApproveRequest {
expires_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
id: ::std::result::Result<super::ResponseApproveRequestId, ::std::string::String>,
issued_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
issuer: ::std::result::Result<super::ResponseApproveRequestIssuer, ::std::string::String>,
payload: ::std::result::Result<::serde_json::Value, ::std::string::String>,
proof: ::std::result::Result<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
::std::string::String,
>,
recipient:
::std::result::Result<super::ResponseApproveRequestRecipient, ::std::string::String>,
thread_id: ::std::result::Result<
::std::option::Option<super::ResponseApproveRequestThreadId>,
::std::string::String,
>,
type_: ::std::result::Result<::serde_json::Value, ::std::string::String>,
}
impl ::std::default::Default for ResponseApproveRequest {
fn default() -> Self {
Self {
expires_at: Ok(Default::default()),
ext: Ok(Default::default()),
id: Err("no value supplied for id".to_string()),
issued_at: Ok(Default::default()),
issuer: Err("no value supplied for issuer".to_string()),
payload: Err("no value supplied for payload".to_string()),
proof: Err("no value supplied for proof".to_string()),
recipient: Err("no value supplied for recipient".to_string()),
thread_id: Ok(Default::default()),
type_: Err("no value supplied for type_".to_string()),
}
}
}
impl ResponseApproveRequest {
pub fn expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.expires_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_at: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ResponseApproveRequestId>,
T::Error: ::std::fmt::Display,
{
self.id = value
.try_into()
.map_err(|e| format!("error converting supplied value for id: {e}"));
self
}
pub fn issued_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.issued_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for issued_at: {e}"));
self
}
pub fn issuer<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ResponseApproveRequestIssuer>,
T::Error: ::std::fmt::Display,
{
self.issuer = value
.try_into()
.map_err(|e| format!("error converting supplied value for issuer: {e}"));
self
}
pub fn payload<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::serde_json::Value>,
T::Error: ::std::fmt::Display,
{
self.payload = value
.try_into()
.map_err(|e| format!("error converting supplied value for payload: {e}"));
self
}
pub fn proof<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::serde_json::Map<::std::string::String, ::serde_json::Value>,
>,
T::Error: ::std::fmt::Display,
{
self.proof = value
.try_into()
.map_err(|e| format!("error converting supplied value for proof: {e}"));
self
}
pub fn recipient<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ResponseApproveRequestRecipient>,
T::Error: ::std::fmt::Display,
{
self.recipient = value
.try_into()
.map_err(|e| format!("error converting supplied value for recipient: {e}"));
self
}
pub fn thread_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<super::ResponseApproveRequestThreadId>,
>,
T::Error: ::std::fmt::Display,
{
self.thread_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for thread_id: {e}"));
self
}
pub fn type_<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::serde_json::Value>,
T::Error: ::std::fmt::Display,
{
self.type_ = value
.try_into()
.map_err(|e| format!("error converting supplied value for type_: {e}"));
self
}
}
impl ::std::convert::TryFrom<ResponseApproveRequest> for super::ResponseApproveRequest {
type Error = super::error::ConversionError;
fn try_from(
value: ResponseApproveRequest,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
expires_at: value.expires_at?,
ext: value.ext?,
id: value.id?,
issued_at: value.issued_at?,
issuer: value.issuer?,
payload: value.payload?,
proof: value.proof?,
recipient: value.recipient?,
thread_id: value.thread_id?,
type_: value.type_?,
})
}
}
impl ::std::convert::From<super::ResponseApproveRequest> for ResponseApproveRequest {
fn from(value: super::ResponseApproveRequest) -> Self {
Self {
expires_at: Ok(value.expires_at),
ext: Ok(value.ext),
id: Ok(value.id),
issued_at: Ok(value.issued_at),
issuer: Ok(value.issuer),
payload: Ok(value.payload),
proof: Ok(value.proof),
recipient: Ok(value.recipient),
thread_id: Ok(value.thread_id),
type_: Ok(value.type_),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/auth/step-up/start/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"approveRequest\": {\n \"additionalProperties\": false,\n \"description\": \"A complete, signed auth/step-up/approve-request/0.3 document for this session: issuer the relying party, recipient the approver. The approver verifies it on its own terms; the framework-level envelope members are modelled here so none are lost on receipt, but `payload` and `proof` are carried opaque (unpacked and re-validated by that spec, not by this one) so the proof survives.\",\n \"properties\": {\n \"expiresAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"id\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"issuedAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"issuer\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"payload\": {\n \"description\": \"The auth/step-up/approve-request/0.3 payload, opaque here — see that spec for its shape.\"\n },\n \"proof\": {\n \"description\": \"A W3C Data Integrity proof (SPEC §4.7), opaque here — the approver verifies it on its own terms.\",\n \"type\": \"object\"\n },\n \"recipient\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"threadId\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"type\": {\n \"const\": \"https://trusttasks.org/spec/auth/step-up/approve-request/0.3\"\n }\n },\n \"required\": [\n \"id\",\n \"type\",\n \"issuer\",\n \"recipient\",\n \"payload\",\n \"proof\"\n ],\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n }\n },\n \"required\": [\n \"approveRequest\"\n ],\n \"title\": \"Auth Step-up Start — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/auth/step-up/start/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"sessionId\": {\n \"description\": \"The relying-party session to elevate.\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"targetAcr\": {\n \"description\": \"The assurance level the holder wants the session raised to. Absent means the relying party's own next level above the session's current one.\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"sessionId\"\n ],\n \"title\": \"Auth Step-up Start — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/auth/step-up/start/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"approveRequest\": {\n \"additionalProperties\": false,\n \"description\": \"A complete, signed auth/step-up/approve-request/0.3 document for this session: issuer the relying party, recipient the approver. The approver verifies it on its own terms; the framework-level envelope members are modelled here so none are lost on receipt, but `payload` and `proof` are carried opaque (unpacked and re-validated by that spec, not by this one) so the proof survives.\",\n \"properties\": {\n \"expiresAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"id\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"issuedAt\": {\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"issuer\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"payload\": {\n \"description\": \"The auth/step-up/approve-request/0.3 payload, opaque here — see that spec for its shape.\"\n },\n \"proof\": {\n \"description\": \"A W3C Data Integrity proof (SPEC §4.7), opaque here — the approver verifies it on its own terms.\",\n \"type\": \"object\"\n },\n \"recipient\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"threadId\": {\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"type\": {\n \"const\": \"https://trusttasks.org/spec/auth/step-up/approve-request/0.3\"\n }\n },\n \"required\": [\n \"id\",\n \"type\",\n \"issuer\",\n \"recipient\",\n \"payload\",\n \"proof\"\n ],\n \"type\": \"object\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n }\n },\n \"required\": [\n \"approveRequest\"\n ],\n \"title\": \"Auth Step-up Start — response payload\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::SESSION_UNKNOWN,
error_codes::NOT_NEEDED,
error_codes::RATE_LIMITED,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `auth/step-up/start:sessionUnknown`
///
/// No live session with this `sessionId` belongs to the proven issuer. Returned alike for a session that does not exist, one that has expired, and one that belongs to someone else, so the code cannot be used to probe sessions.
///
/// Declared `retryable: false`.
pub const SESSION_UNKNOWN: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/step-up/start:sessionUnknown",
retryable: false,
};
/// `auth/step-up/start:notNeeded`
///
/// The session is already at or above the requested assurance level.
///
/// Declared `retryable: false`.
pub const NOT_NEEDED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/step-up/start:notNeeded",
retryable: false,
};
/// `auth/step-up/start:rateLimited`
///
/// The holder has started too many step-ups for this session recently.
///
/// Declared `retryable: true`.
pub const RATE_LIMITED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "auth/step-up/start:rateLimited",
retryable: true,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:6b1734a8-2846-479a-8d9e-7a8b9c0d1e01\",\n \"type\": \"https://trusttasks.org/spec/auth/step-up/start/0.1\",\n \"issuer\": \"did:webvh:QmAliceScid7:did.example.com:alice\",\n \"recipient\": \"did:webvh:QmControlScid2:control.example.com\",\n \"issuedAt\": \"2026-09-27T09:00:00Z\",\n \"payload\": { \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\", \"targetAcr\": \"aal2\" }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:6b1734a8-2846-479a-8d9e-7a8b9c0d1e02\",\n \"type\": \"https://trusttasks.org/spec/auth/step-up/start/0.1#response\",\n \"threadId\": \"urn:uuid:6b1734a8-2846-479a-8d9e-7a8b9c0d1e01\",\n \"issuer\": \"did:webvh:QmControlScid2:control.example.com\",\n \"recipient\": \"did:webvh:QmAliceScid7:did.example.com:alice\",\n \"issuedAt\": \"2026-09-27T09:00:01Z\",\n \"payload\": {\n \"approveRequest\": {\n \"id\": \"urn:uuid:6b1734a8-2846-479a-8d9e-7a8b9c0d1e03\",\n \"type\": \"https://trusttasks.org/spec/auth/step-up/approve-request/0.3\",\n \"issuer\": \"did:webvh:QmControlScid2:control.example.com\",\n \"recipient\": \"did:webvh:QmAliceScid7:did.example.com:alice\",\n \"issuedAt\": \"2026-09-27T09:00:01Z\",\n \"expiresAt\": \"2026-09-27T09:05:01Z\",\n \"payload\": {\n \"subject\": \"did:webvh:QmAliceScid7:did.example.com:alice\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\",\n \"challenge\": \"u0Zp3cQ8mV2kX9sN4bT7yR1wE6aL5fH0\",\n \"reason\": \"Raise your console session to manage domains.\",\n \"targetAcr\": \"aal2\"\n },\n \"proof\": {\n \"type\": \"DataIntegrityProof\",\n \"cryptosuite\": \"eddsa-jcs-2022\",\n \"verificationMethod\": \"did:webvh:QmControlScid2:control.example.com#key-2\",\n \"created\": \"2026-09-27T09:00:01Z\",\n \"proofPurpose\": \"authentication\",\n \"proofValue\": \"z3sXm...\"\n }\n }\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
("Missing sessionId.", "{}"),
("Empty sessionId.", "{\n \"sessionId\": \"\"\n}"),
(
"The holder does not choose the reason; the relying party writes it into the signed request.",
"{\n \"reason\": \"please\",\n \"sessionId\": \"ec5d3c89-3f49-49b2-9d7d-2a8c0a8a7b9b\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}