//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `git-ns/namespace/list`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Did",
/// "description": "A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.",
/// "type": "string",
/// "maxLength": 2048,
/// "pattern": "^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct Did(::std::string::String);
impl ::std::ops::Deref for Did {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<Did> for ::std::string::String {
fn from(value: Did) -> Self {
value.0
}
}
impl ::std::str::FromStr for Did {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> = ::std::sync::LazyLock::new(
|| {
::regress::Regex::new(
"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$",
)
.unwrap()
},
);
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for Did {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Did {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Did {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for Did {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The lowercased DNS host of a forge: `github.com`, a GitHub Enterprise Server host, `codeberg.org`, or a self-hosted Forgejo instance such as `git.example.org`. No scheme, no port, no path. The host is a segment of every resource, so a right never crosses forges.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ForgeHost",
/// "description": "The lowercased DNS host of a forge: `github.com`, a GitHub Enterprise Server host, `codeberg.org`, or a self-hosted Forgejo instance such as `git.example.org`. No scheme, no port, no path. The host is a segment of every resource, so a right never crosses forges.",
/// "type": "string",
/// "maxLength": 253,
/// "minLength": 3,
/// "pattern": "^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeHost(::std::string::String);
impl ::std::ops::Deref for ForgeHost {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeHost> for ::std::string::String {
fn from(value: ForgeHost) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeHost {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 253usize {
return Err("longer than 253 characters".into());
}
if value.chars().count() < 3usize {
return Err("shorter than 3 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new(
"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+$",
)
.unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeHost {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeHost {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeHost {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeHost {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///An identifier the forge itself assigns — a repository id, a user or organisation id — carried as a string so a forge whose ids are not numbers needs no new version. GitHub and Forgejo ids are decimal integers written as strings (`"812736451"`). Unlike a name, it survives renames and transfers, which is why rights and bindings are keyed by it.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ForgeId",
/// "description": "An identifier the forge itself assigns — a repository id, a user or organisation id — carried as a string so a forge whose ids are not numbers needs no new version. GitHub and Forgejo ids are decimal integers written as strings (`\"812736451\"`). Unlike a name, it survives renames and transfers, which is why rights and bindings are keyed by it.",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeId(::std::string::String);
impl ::std::ops::Deref for ForgeId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeId> for ::std::string::String {
fn from(value: ForgeId) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 64usize {
return Err("longer than 64 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///What the bridge serving the namespace last reported about its standing on the forge owner — its app, its installation and what the owner's plan allows. Display only: it changes no decision the VTC takes. Every member but `missingPermissions` is absent until the bridge reports it.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ForgeStatus",
/// "description": "What the bridge serving the namespace last reported about its standing on the forge owner — its app, its installation and what the owner's plan allows. Display only: it changes no decision the VTC takes. Every member but `missingPermissions` is absent until the bridge reports it.",
/// "type": "object",
/// "required": [
/// "missingPermissions"
/// ],
/// "properties": {
/// "appName": {
/// "description": "The app's display name.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
/// },
/// "appRegistration": {
/// "description": "Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
/// },
/// "appSlug": {
/// "description": "The app's URL slug on the forge.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
/// },
/// "bridgePostedCheck": {
/// "description": "The bridge can post the verify-trust check itself, the fallback where no required workflow is available.",
/// "type": "boolean"
/// },
/// "installationId": {
/// "description": "The forge's identifier for its installation of the community's app (GitHub).",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
/// },
/// "missingPermissions": {
/// "description": "Permissions the app needs and the installation has not granted, in the forge's vocabulary. Empty when none are missing, or none were reported.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "maxLength": 128,
/// "minLength": 1
/// },
/// "maxItems": 256,
/// "uniqueItems": true
/// },
/// "orgRulesets": {
/// "description": "Organisation rulesets are available on the owner's plan.",
/// "type": "boolean"
/// },
/// "permissionUpgradePending": {
/// "description": "A new version of the app asks for permissions the forge owner has not approved yet.",
/// "type": "boolean"
/// },
/// "reportedAt": {
/// "description": "When the VTC received the report.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "requiredWorkflow": {
/// "description": "The organisation ruleset requiring the verify-trust workflow is in force.",
/// "type": "boolean"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct ForgeStatus {
///The app's display name.
#[serde(
rename = "appName",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub app_name: ::std::option::Option<ForgeStatusAppName>,
///Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).
#[serde(
rename = "appRegistration",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub app_registration: ::std::option::Option<ForgeStatusAppRegistration>,
///The app's URL slug on the forge.
#[serde(
rename = "appSlug",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub app_slug: ::std::option::Option<ForgeStatusAppSlug>,
///The bridge can post the verify-trust check itself, the fallback where no required workflow is available.
#[serde(
rename = "bridgePostedCheck",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub bridge_posted_check: ::std::option::Option<bool>,
///The forge's identifier for its installation of the community's app (GitHub).
#[serde(
rename = "installationId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub installation_id: ::std::option::Option<ForgeStatusInstallationId>,
///Permissions the app needs and the installation has not granted, in the forge's vocabulary. Empty when none are missing, or none were reported.
#[serde(rename = "missingPermissions")]
pub missing_permissions: Vec<ForgeStatusMissingPermissionsItem>,
///Organisation rulesets are available on the owner's plan.
#[serde(
rename = "orgRulesets",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub org_rulesets: ::std::option::Option<bool>,
///A new version of the app asks for permissions the forge owner has not approved yet.
#[serde(
rename = "permissionUpgradePending",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub permission_upgrade_pending: ::std::option::Option<bool>,
///When the VTC received the report.
#[serde(
rename = "reportedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub reported_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///The organisation ruleset requiring the verify-trust workflow is in force.
#[serde(
rename = "requiredWorkflow",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub required_workflow: ::std::option::Option<bool>,
}
impl ForgeStatus {
pub fn builder() -> builder::ForgeStatus {
Default::default()
}
}
///The app's display name.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The app's display name.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeStatusAppName(::std::string::String);
impl ::std::ops::Deref for ForgeStatusAppName {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeStatusAppName> for ::std::string::String {
fn from(value: ForgeStatusAppName) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeStatusAppName {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeStatusAppName {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeStatusAppName {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeStatusAppName {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeStatusAppName {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeStatusAppRegistration(::std::string::String);
impl ::std::ops::Deref for ForgeStatusAppRegistration {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeStatusAppRegistration> for ::std::string::String {
fn from(value: ForgeStatusAppRegistration) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeStatusAppRegistration {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeStatusAppRegistration {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeStatusAppRegistration {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeStatusAppRegistration {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeStatusAppRegistration {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The app's URL slug on the forge.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The app's URL slug on the forge.",
/// "type": "string",
/// "maxLength": 256,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeStatusAppSlug(::std::string::String);
impl ::std::ops::Deref for ForgeStatusAppSlug {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeStatusAppSlug> for ::std::string::String {
fn from(value: ForgeStatusAppSlug) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeStatusAppSlug {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 256usize {
return Err("longer than 256 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeStatusAppSlug {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeStatusAppSlug {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeStatusAppSlug {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeStatusAppSlug {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The forge's identifier for its installation of the community's app (GitHub).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The forge's identifier for its installation of the community's app (GitHub).",
/// "type": "string",
/// "maxLength": 64,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeStatusInstallationId(::std::string::String);
impl ::std::ops::Deref for ForgeStatusInstallationId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeStatusInstallationId> for ::std::string::String {
fn from(value: ForgeStatusInstallationId) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeStatusInstallationId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 64usize {
return Err("longer than 64 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeStatusInstallationId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeStatusInstallationId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeStatusInstallationId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeStatusInstallationId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///`ForgeStatusMissingPermissionsItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "maxLength": 128,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ForgeStatusMissingPermissionsItem(::std::string::String);
impl ::std::ops::Deref for ForgeStatusMissingPermissionsItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ForgeStatusMissingPermissionsItem> for ::std::string::String {
fn from(value: ForgeStatusMissingPermissionsItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for ForgeStatusMissingPermissionsItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 128usize {
return Err("longer than 128 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ForgeStatusMissingPermissionsItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ForgeStatusMissingPermissionsItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ForgeStatusMissingPermissionsItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ForgeStatusMissingPermissionsItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///A level of the bridge's forge-neutral role ladder, lowest first: the vocabulary role drift's `observed` and `expected` are reported in. `none` is no direct role on the repository.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "MappedRole",
/// "description": "A level of the bridge's forge-neutral role ladder, lowest first: the vocabulary role drift's `observed` and `expected` are reported in. `none` is no direct role on the repository.",
/// "type": "string",
/// "enum": [
/// "none",
/// "read",
/// "triage",
/// "write",
/// "maintain",
/// "admin"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum MappedRole {
#[serde(rename = "none")]
None,
#[serde(rename = "read")]
Read,
#[serde(rename = "triage")]
Triage,
#[serde(rename = "write")]
Write,
#[serde(rename = "maintain")]
Maintain,
#[serde(rename = "admin")]
Admin,
}
impl ::std::fmt::Display for MappedRole {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::None => f.write_str("none"),
Self::Read => f.write_str("read"),
Self::Triage => f.write_str("triage"),
Self::Write => f.write_str("write"),
Self::Maintain => f.write_str("maintain"),
Self::Admin => f.write_str("admin"),
}
}
}
impl ::std::str::FromStr for MappedRole {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"none" => Ok(Self::None),
"read" => Ok(Self::Read),
"triage" => Ok(Self::Triage),
"write" => Ok(Self::Write),
"maintain" => Ok(Self::Maintain),
"admin" => Ok(Self::Admin),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for MappedRole {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for MappedRole {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for MappedRole {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///The VTC's opaque identifier for a namespace, assigned when it is bound. Stable for the life of the binding; never reused for another binding.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "NamespaceId",
/// "description": "The VTC's opaque identifier for a namespace, assigned when it is bound. Stable for the life of the binding; never reused for another binding.",
/// "type": "string",
/// "maxLength": 128,
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct NamespaceId(::std::string::String);
impl ::std::ops::Deref for NamespaceId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<NamespaceId> for ::std::string::String {
fn from(value: NamespaceId) -> Self {
value.0
}
}
impl ::std::str::FromStr for NamespaceId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 128usize {
return Err("longer than 128 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for NamespaceId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for NamespaceId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///One namespace as its administrators govern it: the binding, who administers it, how many repositories it holds, and what its bridge last reported.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "NamespaceStatus",
/// "description": "One namespace as its administrators govern it: the binding, who administers it, how many repositories it holds, and what its bridge last reported.",
/// "type": "object",
/// "required": [
/// "admins",
/// "boundBy",
/// "cascadeOnDeparture",
/// "forge",
/// "headless",
/// "id",
/// "installationRemoved",
/// "mode",
/// "owner",
/// "repoCount",
/// "requestedAt",
/// "resource",
/// "roleDrift",
/// "roleMapSource",
/// "state"
/// ],
/// "properties": {
/// "admins": {
/// "description": "Everyone holding a live, explicitly recorded `git.ns.admin` on the namespace. Each of them can grant anything in it.",
/// "type": "array",
/// "items": {
/// "$ref": "#/definitions/Did"
/// },
/// "uniqueItems": true
/// },
/// "boundAt": {
/// "description": "When binding completed. Absent while `pending`.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "boundBy": {
/// "description": "Who bound it.",
/// "$ref": "#/definitions/Did"
/// },
/// "bridgeDid": {
/// "description": "The bridge that serves the namespace. Absent in manual mode.",
/// "$ref": "#/definitions/Did"
/// },
/// "cascadeOnDeparture": {
/// "description": "Whether the community's policy revokes the grants a member made when that member leaves. Community-wide, as `roleDrift`.",
/// "type": "boolean"
/// },
/// "forge": {
/// "$ref": "#/definitions/ForgeHost"
/// },
/// "forgeStatus": {
/// "$ref": "#/definitions/ForgeStatus"
/// },
/// "headless": {
/// "description": "Bound, with no live admin: its last admin left or lapsed. Nobody can grant in it until an administrator reseats one (`git-ns/namespace/reseat`).",
/// "type": "boolean"
/// },
/// "id": {
/// "$ref": "#/definitions/NamespaceId"
/// },
/// "installationRemoved": {
/// "description": "The bridge reported losing its access to the forge owner, and has not reported access since.",
/// "type": "boolean"
/// },
/// "kind": {
/// "description": "Whether the owner is an organisation or a personal account, once the forge has said.",
/// "type": "string",
/// "enum": [
/// "organization",
/// "user"
/// ]
/// },
/// "mode": {
/// "description": "As `GitNamespace.mode` in the shared schema.",
/// "type": "string",
/// "enum": [
/// "bridge",
/// "manual"
/// ]
/// },
/// "owner": {
/// "description": "The organisation or user on the forge, lowercased.",
/// "$ref": "#/definitions/Segment"
/// },
/// "ownerId": {
/// "description": "The forge's id for the owner, once the forge has said. Unlike `owner`, it survives a rename.",
/// "$ref": "#/definitions/ForgeId"
/// },
/// "repoCount": {
/// "description": "How many repositories the VTC records in the namespace, in any state.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "requestedAt": {
/// "description": "When binding was requested.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "resource": {
/// "description": "The namespace as a resource: `<forge>/<owner>`.",
/// "$ref": "#/definitions/Resource"
/// },
/// "roleDrift": {
/// "description": "What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.",
/// "type": "string",
/// "enum": [
/// "report",
/// "enforce"
/// ]
/// },
/// "roleMap": {
/// "description": "The forge role each right projects to on a repository without a map of its own, as the serving bridge last reported it. Absent while `roleMapSource` is `unknown`: no map, the default included, is assumed.",
/// "$ref": "#/definitions/RoleMap"
/// },
/// "roleMapReportedAt": {
/// "description": "The `issuedAt` of the role-map report held, on the bridge's clock.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "roleMapSource": {
/// "description": "`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.",
/// "type": "string",
/// "enum": [
/// "reported",
/// "unknown"
/// ]
/// },
/// "state": {
/// "description": "As `GitNamespace.state` in the shared schema.",
/// "type": "string",
/// "enum": [
/// "pending",
/// "bound"
/// ]
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct NamespaceStatus {
///Everyone holding a live, explicitly recorded `git.ns.admin` on the namespace. Each of them can grant anything in it.
pub admins: Vec<Did>,
///When binding completed. Absent while `pending`.
#[serde(
rename = "boundAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub bound_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///Who bound it.
#[serde(rename = "boundBy")]
pub bound_by: Did,
///The bridge that serves the namespace. Absent in manual mode.
#[serde(
rename = "bridgeDid",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub bridge_did: ::std::option::Option<Did>,
///Whether the community's policy revokes the grants a member made when that member leaves. Community-wide, as `roleDrift`.
#[serde(rename = "cascadeOnDeparture")]
pub cascade_on_departure: bool,
pub forge: ForgeHost,
#[serde(
rename = "forgeStatus",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub forge_status: ::std::option::Option<ForgeStatus>,
///Bound, with no live admin: its last admin left or lapsed. Nobody can grant in it until an administrator reseats one (`git-ns/namespace/reseat`).
pub headless: bool,
pub id: NamespaceId,
///The bridge reported losing its access to the forge owner, and has not reported access since.
#[serde(rename = "installationRemoved")]
pub installation_removed: bool,
///Whether the owner is an organisation or a personal account, once the forge has said.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub kind: ::std::option::Option<NamespaceStatusKind>,
///As `GitNamespace.mode` in the shared schema.
pub mode: NamespaceStatusMode,
///The organisation or user on the forge, lowercased.
pub owner: Segment,
///The forge's id for the owner, once the forge has said. Unlike `owner`, it survives a rename.
#[serde(
rename = "ownerId",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub owner_id: ::std::option::Option<ForgeId>,
///How many repositories the VTC records in the namespace, in any state.
#[serde(rename = "repoCount")]
pub repo_count: u64,
///When binding was requested.
#[serde(rename = "requestedAt")]
pub requested_at: ::chrono::DateTime<::chrono::offset::Utc>,
///The namespace as a resource: `<forge>/<owner>`.
pub resource: Resource,
///What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.
#[serde(rename = "roleDrift")]
pub role_drift: NamespaceStatusRoleDrift,
///The forge role each right projects to on a repository without a map of its own, as the serving bridge last reported it. Absent while `roleMapSource` is `unknown`: no map, the default included, is assumed.
#[serde(
rename = "roleMap",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub role_map: ::std::option::Option<RoleMap>,
///The `issuedAt` of the role-map report held, on the bridge's clock.
#[serde(
rename = "roleMapReportedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub role_map_reported_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.
#[serde(rename = "roleMapSource")]
pub role_map_source: NamespaceStatusRoleMapSource,
///As `GitNamespace.state` in the shared schema.
pub state: NamespaceStatusState,
}
impl NamespaceStatus {
pub fn builder() -> builder::NamespaceStatus {
Default::default()
}
}
///Whether the owner is an organisation or a personal account, once the forge has said.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Whether the owner is an organisation or a personal account, once the forge has said.",
/// "type": "string",
/// "enum": [
/// "organization",
/// "user"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum NamespaceStatusKind {
#[serde(rename = "organization")]
Organization,
#[serde(rename = "user")]
User,
}
impl ::std::fmt::Display for NamespaceStatusKind {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Organization => f.write_str("organization"),
Self::User => f.write_str("user"),
}
}
}
impl ::std::str::FromStr for NamespaceStatusKind {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"organization" => Ok(Self::Organization),
"user" => Ok(Self::User),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for NamespaceStatusKind {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceStatusKind {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceStatusKind {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///As `GitNamespace.mode` in the shared schema.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "As `GitNamespace.mode` in the shared schema.",
/// "type": "string",
/// "enum": [
/// "bridge",
/// "manual"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum NamespaceStatusMode {
#[serde(rename = "bridge")]
Bridge,
#[serde(rename = "manual")]
Manual,
}
impl ::std::fmt::Display for NamespaceStatusMode {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Bridge => f.write_str("bridge"),
Self::Manual => f.write_str("manual"),
}
}
}
impl ::std::str::FromStr for NamespaceStatusMode {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"bridge" => Ok(Self::Bridge),
"manual" => Ok(Self::Manual),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for NamespaceStatusMode {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceStatusMode {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceStatusMode {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.",
/// "type": "string",
/// "enum": [
/// "report",
/// "enforce"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum NamespaceStatusRoleDrift {
#[serde(rename = "report")]
Report,
#[serde(rename = "enforce")]
Enforce,
}
impl ::std::fmt::Display for NamespaceStatusRoleDrift {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Report => f.write_str("report"),
Self::Enforce => f.write_str("enforce"),
}
}
}
impl ::std::str::FromStr for NamespaceStatusRoleDrift {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"report" => Ok(Self::Report),
"enforce" => Ok(Self::Enforce),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for NamespaceStatusRoleDrift {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceStatusRoleDrift {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceStatusRoleDrift {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.",
/// "type": "string",
/// "enum": [
/// "reported",
/// "unknown"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum NamespaceStatusRoleMapSource {
#[serde(rename = "reported")]
Reported,
#[serde(rename = "unknown")]
Unknown,
}
impl ::std::fmt::Display for NamespaceStatusRoleMapSource {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Reported => f.write_str("reported"),
Self::Unknown => f.write_str("unknown"),
}
}
}
impl ::std::str::FromStr for NamespaceStatusRoleMapSource {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"reported" => Ok(Self::Reported),
"unknown" => Ok(Self::Unknown),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for NamespaceStatusRoleMapSource {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceStatusRoleMapSource {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceStatusRoleMapSource {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///As `GitNamespace.state` in the shared schema.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "As `GitNamespace.state` in the shared schema.",
/// "type": "string",
/// "enum": [
/// "pending",
/// "bound"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum NamespaceStatusState {
#[serde(rename = "pending")]
Pending,
#[serde(rename = "bound")]
Bound,
}
impl ::std::fmt::Display for NamespaceStatusState {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Pending => f.write_str("pending"),
Self::Bound => f.write_str("bound"),
}
}
}
impl ::std::str::FromStr for NamespaceStatusState {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"pending" => Ok(Self::Pending),
"bound" => Ok(Self::Bound),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for NamespaceStatusState {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for NamespaceStatusState {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for NamespaceStatusState {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///An administrator lists the namespaces they administer — every one, for a holder of the community-administrator capability — with each one's admins, repository count, bridge and forge status.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/git-ns/namespace/list/0.1",
/// "title": "Payload",
/// "description": "An administrator lists the namespaces they administer — every one, for a holder of the community-administrator capability — with each one's admins, repository count, bridge and forge status.",
/// "type": "object",
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "namespace": {
/// "description": "Only this namespace. It must be one the caller administers; a namespace they do not administer, or one this VTC does not have, is refused with `notAdministrator` alike.",
/// "$ref": "#/definitions/NamespaceId"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Only this namespace. It must be one the caller administers; a namespace they do not administer, or one this VTC does not have, is refused with `notAdministrator` alike.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub namespace: ::std::option::Option<NamespaceId>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
ext: Default::default(),
namespace: Default::default(),
}
}
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Resource",
/// "description": "A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.",
/// "type": "string",
/// "maxLength": 455,
/// "pattern": "^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct Resource(::std::string::String);
impl ::std::ops::Deref for Resource {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<Resource> for ::std::string::String {
fn from(value: Resource) -> Self {
value.0
}
}
impl ::std::str::FromStr for Resource {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 455usize {
return Err("longer than 455 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> = ::std::sync::LazyLock::new(
|| {
::regress::Regex::new(
"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$",
)
.unwrap()
},
);
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for Resource {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Resource {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Resource {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for Resource {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The namespaces the caller administers, or the one asked for.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "The namespaces the caller administers, or the one asked for.",
/// "type": "object",
/// "required": [
/// "namespaces"
/// ],
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "namespaces": {
/// "description": "Every administered namespace, `pending` ones included, ordered by `resource`. Empty only for a holder of the community-administrator capability on a VTC with no namespace.",
/// "type": "array",
/// "items": {
/// "$ref": "#/definitions/NamespaceStatus"
/// }
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Every administered namespace, `pending` ones included, ordered by `resource`. Empty only for a holder of the community-administrator capability on a VTC with no namespace.
pub namespaces: ::std::vec::Vec<NamespaceStatus>,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///The forge role each repository right is given, as the forge applies it: after the forge's own ladder has rounded it down. `own` is the role `git.repo.own` projects to, `maintain` that of `git.repo.maintain`, `commit` that of `git.commit.sign` (`none` is fork-based contribution). There is no member for `git.ns.admin` or `git.repo.create`, which project to no forge role whatever a bridge is configured with. Ordered: `own` is at least `maintain`, which is at least `commit`, and `commit` is at most `write`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "RoleMap",
/// "description": "The forge role each repository right is given, as the forge applies it: after the forge's own ladder has rounded it down. `own` is the role `git.repo.own` projects to, `maintain` that of `git.repo.maintain`, `commit` that of `git.commit.sign` (`none` is fork-based contribution). There is no member for `git.ns.admin` or `git.repo.create`, which project to no forge role whatever a bridge is configured with. Ordered: `own` is at least `maintain`, which is at least `commit`, and `commit` is at most `write`.",
/// "type": "object",
/// "required": [
/// "commit",
/// "maintain",
/// "own"
/// ],
/// "properties": {
/// "commit": {
/// "$ref": "#/definitions/MappedRole"
/// },
/// "maintain": {
/// "$ref": "#/definitions/MappedRole"
/// },
/// "own": {
/// "$ref": "#/definitions/MappedRole"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct RoleMap {
pub commit: MappedRole,
pub maintain: MappedRole,
pub own: MappedRole,
}
impl RoleMap {
pub fn builder() -> builder::RoleMap {
Default::default()
}
}
///One lowercased owner or repository name. Forges compare these case-insensitively, so the wire form is always lowercase and a producer lowercases before sending. A leading `.` is refused, which rules out `.` and `..`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Segment",
/// "description": "One lowercased owner or repository name. Forges compare these case-insensitively, so the wire form is always lowercase and a producer lowercases before sending. A leading `.` is refused, which rules out `.` and `..`.",
/// "type": "string",
/// "maxLength": 100,
/// "minLength": 1,
/// "pattern": "^[a-z0-9_-][a-z0-9._-]*$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct Segment(::std::string::String);
impl ::std::ops::Deref for Segment {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<Segment> for ::std::string::String {
fn from(value: Segment) -> Self {
value.0
}
}
impl ::std::str::FromStr for Segment {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 100usize {
return Err("longer than 100 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z0-9_-][a-z0-9._-]*$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z0-9_-][a-z0-9._-]*$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for Segment {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Segment {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Segment {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for Segment {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct ForgeStatus {
app_name: ::std::result::Result<
::std::option::Option<super::ForgeStatusAppName>,
::std::string::String,
>,
app_registration: ::std::result::Result<
::std::option::Option<super::ForgeStatusAppRegistration>,
::std::string::String,
>,
app_slug: ::std::result::Result<
::std::option::Option<super::ForgeStatusAppSlug>,
::std::string::String,
>,
bridge_posted_check:
::std::result::Result<::std::option::Option<bool>, ::std::string::String>,
installation_id: ::std::result::Result<
::std::option::Option<super::ForgeStatusInstallationId>,
::std::string::String,
>,
missing_permissions: ::std::result::Result<
Vec<super::ForgeStatusMissingPermissionsItem>,
::std::string::String,
>,
org_rulesets: ::std::result::Result<::std::option::Option<bool>, ::std::string::String>,
permission_upgrade_pending:
::std::result::Result<::std::option::Option<bool>, ::std::string::String>,
reported_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
required_workflow:
::std::result::Result<::std::option::Option<bool>, ::std::string::String>,
}
impl ::std::default::Default for ForgeStatus {
fn default() -> Self {
Self {
app_name: Ok(Default::default()),
app_registration: Ok(Default::default()),
app_slug: Ok(Default::default()),
bridge_posted_check: Ok(Default::default()),
installation_id: Ok(Default::default()),
missing_permissions: Err("no value supplied for missing_permissions".to_string()),
org_rulesets: Ok(Default::default()),
permission_upgrade_pending: Ok(Default::default()),
reported_at: Ok(Default::default()),
required_workflow: Ok(Default::default()),
}
}
}
impl ForgeStatus {
pub fn app_name<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeStatusAppName>>,
T::Error: ::std::fmt::Display,
{
self.app_name = value
.try_into()
.map_err(|e| format!("error converting supplied value for app_name: {e}"));
self
}
pub fn app_registration<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeStatusAppRegistration>>,
T::Error: ::std::fmt::Display,
{
self.app_registration = value
.try_into()
.map_err(|e| format!("error converting supplied value for app_registration: {e}"));
self
}
pub fn app_slug<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeStatusAppSlug>>,
T::Error: ::std::fmt::Display,
{
self.app_slug = value
.try_into()
.map_err(|e| format!("error converting supplied value for app_slug: {e}"));
self
}
pub fn bridge_posted_check<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<bool>>,
T::Error: ::std::fmt::Display,
{
self.bridge_posted_check = value.try_into().map_err(|e| {
format!("error converting supplied value for bridge_posted_check: {e}")
});
self
}
pub fn installation_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeStatusInstallationId>>,
T::Error: ::std::fmt::Display,
{
self.installation_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for installation_id: {e}"));
self
}
pub fn missing_permissions<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<Vec<super::ForgeStatusMissingPermissionsItem>>,
T::Error: ::std::fmt::Display,
{
self.missing_permissions = value.try_into().map_err(|e| {
format!("error converting supplied value for missing_permissions: {e}")
});
self
}
pub fn org_rulesets<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<bool>>,
T::Error: ::std::fmt::Display,
{
self.org_rulesets = value
.try_into()
.map_err(|e| format!("error converting supplied value for org_rulesets: {e}"));
self
}
pub fn permission_upgrade_pending<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<bool>>,
T::Error: ::std::fmt::Display,
{
self.permission_upgrade_pending = value.try_into().map_err(|e| {
format!("error converting supplied value for permission_upgrade_pending: {e}")
});
self
}
pub fn reported_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.reported_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for reported_at: {e}"));
self
}
pub fn required_workflow<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<bool>>,
T::Error: ::std::fmt::Display,
{
self.required_workflow = value
.try_into()
.map_err(|e| format!("error converting supplied value for required_workflow: {e}"));
self
}
}
impl ::std::convert::TryFrom<ForgeStatus> for super::ForgeStatus {
type Error = super::error::ConversionError;
fn try_from(
value: ForgeStatus,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
app_name: value.app_name?,
app_registration: value.app_registration?,
app_slug: value.app_slug?,
bridge_posted_check: value.bridge_posted_check?,
installation_id: value.installation_id?,
missing_permissions: value.missing_permissions?,
org_rulesets: value.org_rulesets?,
permission_upgrade_pending: value.permission_upgrade_pending?,
reported_at: value.reported_at?,
required_workflow: value.required_workflow?,
})
}
}
impl ::std::convert::From<super::ForgeStatus> for ForgeStatus {
fn from(value: super::ForgeStatus) -> Self {
Self {
app_name: Ok(value.app_name),
app_registration: Ok(value.app_registration),
app_slug: Ok(value.app_slug),
bridge_posted_check: Ok(value.bridge_posted_check),
installation_id: Ok(value.installation_id),
missing_permissions: Ok(value.missing_permissions),
org_rulesets: Ok(value.org_rulesets),
permission_upgrade_pending: Ok(value.permission_upgrade_pending),
reported_at: Ok(value.reported_at),
required_workflow: Ok(value.required_workflow),
}
}
}
#[derive(Clone, Debug)]
pub struct NamespaceStatus {
admins: ::std::result::Result<Vec<super::Did>, ::std::string::String>,
bound_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
bound_by: ::std::result::Result<super::Did, ::std::string::String>,
bridge_did: ::std::result::Result<::std::option::Option<super::Did>, ::std::string::String>,
cascade_on_departure: ::std::result::Result<bool, ::std::string::String>,
forge: ::std::result::Result<super::ForgeHost, ::std::string::String>,
forge_status:
::std::result::Result<::std::option::Option<super::ForgeStatus>, ::std::string::String>,
headless: ::std::result::Result<bool, ::std::string::String>,
id: ::std::result::Result<super::NamespaceId, ::std::string::String>,
installation_removed: ::std::result::Result<bool, ::std::string::String>,
kind: ::std::result::Result<
::std::option::Option<super::NamespaceStatusKind>,
::std::string::String,
>,
mode: ::std::result::Result<super::NamespaceStatusMode, ::std::string::String>,
owner: ::std::result::Result<super::Segment, ::std::string::String>,
owner_id:
::std::result::Result<::std::option::Option<super::ForgeId>, ::std::string::String>,
repo_count: ::std::result::Result<u64, ::std::string::String>,
requested_at:
::std::result::Result<::chrono::DateTime<::chrono::offset::Utc>, ::std::string::String>,
resource: ::std::result::Result<super::Resource, ::std::string::String>,
role_drift: ::std::result::Result<super::NamespaceStatusRoleDrift, ::std::string::String>,
role_map:
::std::result::Result<::std::option::Option<super::RoleMap>, ::std::string::String>,
role_map_reported_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
role_map_source:
::std::result::Result<super::NamespaceStatusRoleMapSource, ::std::string::String>,
state: ::std::result::Result<super::NamespaceStatusState, ::std::string::String>,
}
impl ::std::default::Default for NamespaceStatus {
fn default() -> Self {
Self {
admins: Err("no value supplied for admins".to_string()),
bound_at: Ok(Default::default()),
bound_by: Err("no value supplied for bound_by".to_string()),
bridge_did: Ok(Default::default()),
cascade_on_departure: Err("no value supplied for cascade_on_departure".to_string()),
forge: Err("no value supplied for forge".to_string()),
forge_status: Ok(Default::default()),
headless: Err("no value supplied for headless".to_string()),
id: Err("no value supplied for id".to_string()),
installation_removed: Err("no value supplied for installation_removed".to_string()),
kind: Ok(Default::default()),
mode: Err("no value supplied for mode".to_string()),
owner: Err("no value supplied for owner".to_string()),
owner_id: Ok(Default::default()),
repo_count: Err("no value supplied for repo_count".to_string()),
requested_at: Err("no value supplied for requested_at".to_string()),
resource: Err("no value supplied for resource".to_string()),
role_drift: Err("no value supplied for role_drift".to_string()),
role_map: Ok(Default::default()),
role_map_reported_at: Ok(Default::default()),
role_map_source: Err("no value supplied for role_map_source".to_string()),
state: Err("no value supplied for state".to_string()),
}
}
}
impl NamespaceStatus {
pub fn admins<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<Vec<super::Did>>,
T::Error: ::std::fmt::Display,
{
self.admins = value
.try_into()
.map_err(|e| format!("error converting supplied value for admins: {e}"));
self
}
pub fn bound_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.bound_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for bound_at: {e}"));
self
}
pub fn bound_by<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Did>,
T::Error: ::std::fmt::Display,
{
self.bound_by = value
.try_into()
.map_err(|e| format!("error converting supplied value for bound_by: {e}"));
self
}
pub fn bridge_did<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Did>>,
T::Error: ::std::fmt::Display,
{
self.bridge_did = value
.try_into()
.map_err(|e| format!("error converting supplied value for bridge_did: {e}"));
self
}
pub fn cascade_on_departure<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.cascade_on_departure = value.try_into().map_err(|e| {
format!("error converting supplied value for cascade_on_departure: {e}")
});
self
}
pub fn forge<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ForgeHost>,
T::Error: ::std::fmt::Display,
{
self.forge = value
.try_into()
.map_err(|e| format!("error converting supplied value for forge: {e}"));
self
}
pub fn forge_status<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeStatus>>,
T::Error: ::std::fmt::Display,
{
self.forge_status = value
.try_into()
.map_err(|e| format!("error converting supplied value for forge_status: {e}"));
self
}
pub fn headless<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.headless = value
.try_into()
.map_err(|e| format!("error converting supplied value for headless: {e}"));
self
}
pub fn id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::NamespaceId>,
T::Error: ::std::fmt::Display,
{
self.id = value
.try_into()
.map_err(|e| format!("error converting supplied value for id: {e}"));
self
}
pub fn installation_removed<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.installation_removed = value.try_into().map_err(|e| {
format!("error converting supplied value for installation_removed: {e}")
});
self
}
pub fn kind<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::NamespaceStatusKind>>,
T::Error: ::std::fmt::Display,
{
self.kind = value
.try_into()
.map_err(|e| format!("error converting supplied value for kind: {e}"));
self
}
pub fn mode<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::NamespaceStatusMode>,
T::Error: ::std::fmt::Display,
{
self.mode = value
.try_into()
.map_err(|e| format!("error converting supplied value for mode: {e}"));
self
}
pub fn owner<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Segment>,
T::Error: ::std::fmt::Display,
{
self.owner = value
.try_into()
.map_err(|e| format!("error converting supplied value for owner: {e}"));
self
}
pub fn owner_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ForgeId>>,
T::Error: ::std::fmt::Display,
{
self.owner_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for owner_id: {e}"));
self
}
pub fn repo_count<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<u64>,
T::Error: ::std::fmt::Display,
{
self.repo_count = value
.try_into()
.map_err(|e| format!("error converting supplied value for repo_count: {e}"));
self
}
pub fn requested_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::chrono::DateTime<::chrono::offset::Utc>>,
T::Error: ::std::fmt::Display,
{
self.requested_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for requested_at: {e}"));
self
}
pub fn resource<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Resource>,
T::Error: ::std::fmt::Display,
{
self.resource = value
.try_into()
.map_err(|e| format!("error converting supplied value for resource: {e}"));
self
}
pub fn role_drift<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::NamespaceStatusRoleDrift>,
T::Error: ::std::fmt::Display,
{
self.role_drift = value
.try_into()
.map_err(|e| format!("error converting supplied value for role_drift: {e}"));
self
}
pub fn role_map<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::RoleMap>>,
T::Error: ::std::fmt::Display,
{
self.role_map = value
.try_into()
.map_err(|e| format!("error converting supplied value for role_map: {e}"));
self
}
pub fn role_map_reported_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.role_map_reported_at = value.try_into().map_err(|e| {
format!("error converting supplied value for role_map_reported_at: {e}")
});
self
}
pub fn role_map_source<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::NamespaceStatusRoleMapSource>,
T::Error: ::std::fmt::Display,
{
self.role_map_source = value
.try_into()
.map_err(|e| format!("error converting supplied value for role_map_source: {e}"));
self
}
pub fn state<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::NamespaceStatusState>,
T::Error: ::std::fmt::Display,
{
self.state = value
.try_into()
.map_err(|e| format!("error converting supplied value for state: {e}"));
self
}
}
impl ::std::convert::TryFrom<NamespaceStatus> for super::NamespaceStatus {
type Error = super::error::ConversionError;
fn try_from(
value: NamespaceStatus,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
admins: value.admins?,
bound_at: value.bound_at?,
bound_by: value.bound_by?,
bridge_did: value.bridge_did?,
cascade_on_departure: value.cascade_on_departure?,
forge: value.forge?,
forge_status: value.forge_status?,
headless: value.headless?,
id: value.id?,
installation_removed: value.installation_removed?,
kind: value.kind?,
mode: value.mode?,
owner: value.owner?,
owner_id: value.owner_id?,
repo_count: value.repo_count?,
requested_at: value.requested_at?,
resource: value.resource?,
role_drift: value.role_drift?,
role_map: value.role_map?,
role_map_reported_at: value.role_map_reported_at?,
role_map_source: value.role_map_source?,
state: value.state?,
})
}
}
impl ::std::convert::From<super::NamespaceStatus> for NamespaceStatus {
fn from(value: super::NamespaceStatus) -> Self {
Self {
admins: Ok(value.admins),
bound_at: Ok(value.bound_at),
bound_by: Ok(value.bound_by),
bridge_did: Ok(value.bridge_did),
cascade_on_departure: Ok(value.cascade_on_departure),
forge: Ok(value.forge),
forge_status: Ok(value.forge_status),
headless: Ok(value.headless),
id: Ok(value.id),
installation_removed: Ok(value.installation_removed),
kind: Ok(value.kind),
mode: Ok(value.mode),
owner: Ok(value.owner),
owner_id: Ok(value.owner_id),
repo_count: Ok(value.repo_count),
requested_at: Ok(value.requested_at),
resource: Ok(value.resource),
role_drift: Ok(value.role_drift),
role_map: Ok(value.role_map),
role_map_reported_at: Ok(value.role_map_reported_at),
role_map_source: Ok(value.role_map_source),
state: Ok(value.state),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
namespace:
::std::result::Result<::std::option::Option<super::NamespaceId>, ::std::string::String>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
namespace: Ok(Default::default()),
}
}
}
impl Payload {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn namespace<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::NamespaceId>>,
T::Error: ::std::fmt::Display,
{
self.namespace = value
.try_into()
.map_err(|e| format!("error converting supplied value for namespace: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
namespace: value.namespace?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
ext: Ok(value.ext),
namespace: Ok(value.namespace),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
namespaces:
::std::result::Result<::std::vec::Vec<super::NamespaceStatus>, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
namespaces: Err("no value supplied for namespaces".to_string()),
}
}
}
impl Response {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn namespaces<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::NamespaceStatus>>,
T::Error: ::std::fmt::Display,
{
self.namespaces = value
.try_into()
.map_err(|e| format!("error converting supplied value for namespaces: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
namespaces: value.namespaces?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
ext: Ok(value.ext),
namespaces: Ok(value.namespaces),
}
}
}
#[derive(Clone, Debug)]
pub struct RoleMap {
commit: ::std::result::Result<super::MappedRole, ::std::string::String>,
maintain: ::std::result::Result<super::MappedRole, ::std::string::String>,
own: ::std::result::Result<super::MappedRole, ::std::string::String>,
}
impl ::std::default::Default for RoleMap {
fn default() -> Self {
Self {
commit: Err("no value supplied for commit".to_string()),
maintain: Err("no value supplied for maintain".to_string()),
own: Err("no value supplied for own".to_string()),
}
}
}
impl RoleMap {
pub fn commit<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::MappedRole>,
T::Error: ::std::fmt::Display,
{
self.commit = value
.try_into()
.map_err(|e| format!("error converting supplied value for commit: {e}"));
self
}
pub fn maintain<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::MappedRole>,
T::Error: ::std::fmt::Display,
{
self.maintain = value
.try_into()
.map_err(|e| format!("error converting supplied value for maintain: {e}"));
self
}
pub fn own<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::MappedRole>,
T::Error: ::std::fmt::Display,
{
self.own = value
.try_into()
.map_err(|e| format!("error converting supplied value for own: {e}"));
self
}
}
impl ::std::convert::TryFrom<RoleMap> for super::RoleMap {
type Error = super::error::ConversionError;
fn try_from(value: RoleMap) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
commit: value.commit?,
maintain: value.maintain?,
own: value.own?,
})
}
}
impl ::std::convert::From<super::RoleMap> for RoleMap {
fn from(value: super::RoleMap) -> Self {
Self {
commit: Ok(value.commit),
maintain: Ok(value.maintain),
own: Ok(value.own),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/git-ns/namespace/list/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Did\": {\n \"description\": \"A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.\",\n \"maxLength\": 2048,\n \"pattern\": \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\",\n \"title\": \"Did\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"ForgeHost\": {\n \"description\": \"The lowercased DNS host of a forge: `github.com`, a GitHub Enterprise Server host, `codeberg.org`, or a self-hosted Forgejo instance such as `git.example.org`. No scheme, no port, no path. The host is a segment of every resource, so a right never crosses forges.\",\n \"maxLength\": 253,\n \"minLength\": 3,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+$\",\n \"title\": \"ForgeHost\",\n \"type\": \"string\"\n },\n \"ForgeId\": {\n \"description\": \"An identifier the forge itself assigns — a repository id, a user or organisation id — carried as a string so a forge whose ids are not numbers needs no new version. GitHub and Forgejo ids are decimal integers written as strings (`\\\"812736451\\\"`). Unlike a name, it survives renames and transfers, which is why rights and bindings are keyed by it.\",\n \"maxLength\": 64,\n \"minLength\": 1,\n \"title\": \"ForgeId\",\n \"type\": \"string\"\n },\n \"ForgeStatus\": {\n \"additionalProperties\": false,\n \"description\": \"What the bridge serving the namespace last reported about its standing on the forge owner — its app, its installation and what the owner's plan allows. Display only: it changes no decision the VTC takes. Every member but `missingPermissions` is absent until the bridge reports it.\",\n \"properties\": {\n \"appName\": {\n \"description\": \"The app's display name.\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"appRegistration\": {\n \"description\": \"Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"appSlug\": {\n \"description\": \"The app's URL slug on the forge.\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"bridgePostedCheck\": {\n \"description\": \"The bridge can post the verify-trust check itself, the fallback where no required workflow is available.\",\n \"type\": \"boolean\"\n },\n \"installationId\": {\n \"description\": \"The forge's identifier for its installation of the community's app (GitHub).\",\n \"maxLength\": 64,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"missingPermissions\": {\n \"description\": \"Permissions the app needs and the installation has not granted, in the forge's vocabulary. Empty when none are missing, or none were reported.\",\n \"items\": {\n \"maxLength\": 128,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"maxItems\": 256,\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"orgRulesets\": {\n \"description\": \"Organisation rulesets are available on the owner's plan.\",\n \"type\": \"boolean\"\n },\n \"permissionUpgradePending\": {\n \"description\": \"A new version of the app asks for permissions the forge owner has not approved yet.\",\n \"type\": \"boolean\"\n },\n \"reportedAt\": {\n \"description\": \"When the VTC received the report.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"requiredWorkflow\": {\n \"description\": \"The organisation ruleset requiring the verify-trust workflow is in force.\",\n \"type\": \"boolean\"\n }\n },\n \"required\": [\n \"missingPermissions\"\n ],\n \"title\": \"ForgeStatus\",\n \"type\": \"object\"\n },\n \"MappedRole\": {\n \"description\": \"A level of the bridge's forge-neutral role ladder, lowest first: the vocabulary role drift's `observed` and `expected` are reported in. `none` is no direct role on the repository.\",\n \"enum\": [\n \"none\",\n \"read\",\n \"triage\",\n \"write\",\n \"maintain\",\n \"admin\"\n ],\n \"title\": \"MappedRole\",\n \"type\": \"string\"\n },\n \"NamespaceId\": {\n \"description\": \"The VTC's opaque identifier for a namespace, assigned when it is bound. Stable for the life of the binding; never reused for another binding.\",\n \"maxLength\": 128,\n \"minLength\": 1,\n \"title\": \"NamespaceId\",\n \"type\": \"string\"\n },\n \"NamespaceStatus\": {\n \"additionalProperties\": false,\n \"description\": \"One namespace as its administrators govern it: the binding, who administers it, how many repositories it holds, and what its bridge last reported.\",\n \"properties\": {\n \"admins\": {\n \"description\": \"Everyone holding a live, explicitly recorded `git.ns.admin` on the namespace. Each of them can grant anything in it.\",\n \"items\": {\n \"$ref\": \"#/$defs/Did\"\n },\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"boundAt\": {\n \"description\": \"When binding completed. Absent while `pending`.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"boundBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who bound it.\"\n },\n \"bridgeDid\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"The bridge that serves the namespace. Absent in manual mode.\"\n },\n \"cascadeOnDeparture\": {\n \"description\": \"Whether the community's policy revokes the grants a member made when that member leaves. Community-wide, as `roleDrift`.\",\n \"type\": \"boolean\"\n },\n \"forge\": {\n \"$ref\": \"#/$defs/ForgeHost\"\n },\n \"forgeStatus\": {\n \"$ref\": \"#/$defs/ForgeStatus\"\n },\n \"headless\": {\n \"description\": \"Bound, with no live admin: its last admin left or lapsed. Nobody can grant in it until an administrator reseats one (`git-ns/namespace/reseat`).\",\n \"type\": \"boolean\"\n },\n \"id\": {\n \"$ref\": \"#/$defs/NamespaceId\"\n },\n \"installationRemoved\": {\n \"description\": \"The bridge reported losing its access to the forge owner, and has not reported access since.\",\n \"type\": \"boolean\"\n },\n \"kind\": {\n \"description\": \"Whether the owner is an organisation or a personal account, once the forge has said.\",\n \"enum\": [\n \"organization\",\n \"user\"\n ],\n \"type\": \"string\"\n },\n \"mode\": {\n \"description\": \"As `GitNamespace.mode` in the shared schema.\",\n \"enum\": [\n \"bridge\",\n \"manual\"\n ],\n \"type\": \"string\"\n },\n \"owner\": {\n \"$ref\": \"#/$defs/Segment\",\n \"description\": \"The organisation or user on the forge, lowercased.\"\n },\n \"ownerId\": {\n \"$ref\": \"#/$defs/ForgeId\",\n \"description\": \"The forge's id for the owner, once the forge has said. Unlike `owner`, it survives a rename.\"\n },\n \"repoCount\": {\n \"description\": \"How many repositories the VTC records in the namespace, in any state.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"requestedAt\": {\n \"description\": \"When binding was requested.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"resource\": {\n \"$ref\": \"#/$defs/Resource\",\n \"description\": \"The namespace as a resource: `<forge>/<owner>`.\"\n },\n \"roleDrift\": {\n \"description\": \"What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.\",\n \"enum\": [\n \"report\",\n \"enforce\"\n ],\n \"type\": \"string\"\n },\n \"roleMap\": {\n \"$ref\": \"#/$defs/RoleMap\",\n \"description\": \"The forge role each right projects to on a repository without a map of its own, as the serving bridge last reported it. Absent while `roleMapSource` is `unknown`: no map, the default included, is assumed.\"\n },\n \"roleMapReportedAt\": {\n \"description\": \"The `issuedAt` of the role-map report held, on the bridge's clock.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"roleMapSource\": {\n \"description\": \"`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.\",\n \"enum\": [\n \"reported\",\n \"unknown\"\n ],\n \"type\": \"string\"\n },\n \"state\": {\n \"description\": \"As `GitNamespace.state` in the shared schema.\",\n \"enum\": [\n \"pending\",\n \"bound\"\n ],\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"id\",\n \"forge\",\n \"owner\",\n \"resource\",\n \"mode\",\n \"state\",\n \"boundBy\",\n \"requestedAt\",\n \"admins\",\n \"repoCount\",\n \"headless\",\n \"installationRemoved\",\n \"roleDrift\",\n \"cascadeOnDeparture\",\n \"roleMapSource\"\n ],\n \"title\": \"NamespaceStatus\",\n \"type\": \"object\"\n },\n \"Resource\": {\n \"description\": \"A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.\",\n \"maxLength\": 455,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\",\n \"title\": \"Resource\",\n \"type\": \"string\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The namespaces the caller administers, or the one asked for.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"namespaces\": {\n \"description\": \"Every administered namespace, `pending` ones included, ordered by `resource`. Empty only for a holder of the community-administrator capability on a VTC with no namespace.\",\n \"items\": {\n \"$ref\": \"#/$defs/NamespaceStatus\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"namespaces\"\n ],\n \"title\": \"Git Namespaces — List Namespaces — response payload\",\n \"type\": \"object\"\n },\n \"RoleMap\": {\n \"additionalProperties\": false,\n \"description\": \"The forge role each repository right is given, as the forge applies it: after the forge's own ladder has rounded it down. `own` is the role `git.repo.own` projects to, `maintain` that of `git.repo.maintain`, `commit` that of `git.commit.sign` (`none` is fork-based contribution). There is no member for `git.ns.admin` or `git.repo.create`, which project to no forge role whatever a bridge is configured with. Ordered: `own` is at least `maintain`, which is at least `commit`, and `commit` is at most `write`.\",\n \"properties\": {\n \"commit\": {\n \"$ref\": \"#/$defs/MappedRole\"\n },\n \"maintain\": {\n \"$ref\": \"#/$defs/MappedRole\"\n },\n \"own\": {\n \"$ref\": \"#/$defs/MappedRole\"\n }\n },\n \"required\": [\n \"own\",\n \"maintain\",\n \"commit\"\n ],\n \"title\": \"RoleMap\",\n \"type\": \"object\"\n },\n \"Segment\": {\n \"description\": \"One lowercased owner or repository name. Forges compare these case-insensitively, so the wire form is always lowercase and a producer lowercases before sending. A leading `.` is refused, which rules out `.` and `..`.\",\n \"maxLength\": 100,\n \"minLength\": 1,\n \"pattern\": \"^[a-z0-9_-][a-z0-9._-]*$\",\n \"title\": \"Segment\",\n \"type\": \"string\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/git-ns/namespace/list/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"An administrator lists the namespaces they administer — every one, for a holder of the community-administrator capability — with each one's admins, repository count, bridge and forge status.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"namespace\": {\n \"$ref\": \"#/$defs/NamespaceId\",\n \"description\": \"Only this namespace. It must be one the caller administers; a namespace they do not administer, or one this VTC does not have, is refused with `notAdministrator` alike.\"\n }\n },\n \"required\": [],\n \"title\": \"Git Namespaces — List Namespaces — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/git-ns/namespace/list/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"Did\": {\n \"description\": \"A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.\",\n \"maxLength\": 2048,\n \"pattern\": \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\",\n \"title\": \"Did\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"ForgeHost\": {\n \"description\": \"The lowercased DNS host of a forge: `github.com`, a GitHub Enterprise Server host, `codeberg.org`, or a self-hosted Forgejo instance such as `git.example.org`. No scheme, no port, no path. The host is a segment of every resource, so a right never crosses forges.\",\n \"maxLength\": 253,\n \"minLength\": 3,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+$\",\n \"title\": \"ForgeHost\",\n \"type\": \"string\"\n },\n \"ForgeId\": {\n \"description\": \"An identifier the forge itself assigns — a repository id, a user or organisation id — carried as a string so a forge whose ids are not numbers needs no new version. GitHub and Forgejo ids are decimal integers written as strings (`\\\"812736451\\\"`). Unlike a name, it survives renames and transfers, which is why rights and bindings are keyed by it.\",\n \"maxLength\": 64,\n \"minLength\": 1,\n \"title\": \"ForgeId\",\n \"type\": \"string\"\n },\n \"ForgeStatus\": {\n \"additionalProperties\": false,\n \"description\": \"What the bridge serving the namespace last reported about its standing on the forge owner — its app, its installation and what the owner's plan allows. Display only: it changes no decision the VTC takes. Every member but `missingPermissions` is absent until the bridge reports it.\",\n \"properties\": {\n \"appName\": {\n \"description\": \"The app's display name.\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"appRegistration\": {\n \"description\": \"Where the app's manifest registration stands, in the bridge's words (`registered`, `pending`).\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"appSlug\": {\n \"description\": \"The app's URL slug on the forge.\",\n \"maxLength\": 256,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"bridgePostedCheck\": {\n \"description\": \"The bridge can post the verify-trust check itself, the fallback where no required workflow is available.\",\n \"type\": \"boolean\"\n },\n \"installationId\": {\n \"description\": \"The forge's identifier for its installation of the community's app (GitHub).\",\n \"maxLength\": 64,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"missingPermissions\": {\n \"description\": \"Permissions the app needs and the installation has not granted, in the forge's vocabulary. Empty when none are missing, or none were reported.\",\n \"items\": {\n \"maxLength\": 128,\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"maxItems\": 256,\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"orgRulesets\": {\n \"description\": \"Organisation rulesets are available on the owner's plan.\",\n \"type\": \"boolean\"\n },\n \"permissionUpgradePending\": {\n \"description\": \"A new version of the app asks for permissions the forge owner has not approved yet.\",\n \"type\": \"boolean\"\n },\n \"reportedAt\": {\n \"description\": \"When the VTC received the report.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"requiredWorkflow\": {\n \"description\": \"The organisation ruleset requiring the verify-trust workflow is in force.\",\n \"type\": \"boolean\"\n }\n },\n \"required\": [\n \"missingPermissions\"\n ],\n \"title\": \"ForgeStatus\",\n \"type\": \"object\"\n },\n \"MappedRole\": {\n \"description\": \"A level of the bridge's forge-neutral role ladder, lowest first: the vocabulary role drift's `observed` and `expected` are reported in. `none` is no direct role on the repository.\",\n \"enum\": [\n \"none\",\n \"read\",\n \"triage\",\n \"write\",\n \"maintain\",\n \"admin\"\n ],\n \"title\": \"MappedRole\",\n \"type\": \"string\"\n },\n \"NamespaceId\": {\n \"description\": \"The VTC's opaque identifier for a namespace, assigned when it is bound. Stable for the life of the binding; never reused for another binding.\",\n \"maxLength\": 128,\n \"minLength\": 1,\n \"title\": \"NamespaceId\",\n \"type\": \"string\"\n },\n \"NamespaceStatus\": {\n \"additionalProperties\": false,\n \"description\": \"One namespace as its administrators govern it: the binding, who administers it, how many repositories it holds, and what its bridge last reported.\",\n \"properties\": {\n \"admins\": {\n \"description\": \"Everyone holding a live, explicitly recorded `git.ns.admin` on the namespace. Each of them can grant anything in it.\",\n \"items\": {\n \"$ref\": \"#/$defs/Did\"\n },\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"boundAt\": {\n \"description\": \"When binding completed. Absent while `pending`.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"boundBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who bound it.\"\n },\n \"bridgeDid\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"The bridge that serves the namespace. Absent in manual mode.\"\n },\n \"cascadeOnDeparture\": {\n \"description\": \"Whether the community's policy revokes the grants a member made when that member leaves. Community-wide, as `roleDrift`.\",\n \"type\": \"boolean\"\n },\n \"forge\": {\n \"$ref\": \"#/$defs/ForgeHost\"\n },\n \"forgeStatus\": {\n \"$ref\": \"#/$defs/ForgeStatus\"\n },\n \"headless\": {\n \"description\": \"Bound, with no live admin: its last admin left or lapsed. Nobody can grant in it until an administrator reseats one (`git-ns/namespace/reseat`).\",\n \"type\": \"boolean\"\n },\n \"id\": {\n \"$ref\": \"#/$defs/NamespaceId\"\n },\n \"installationRemoved\": {\n \"description\": \"The bridge reported losing its access to the forge owner, and has not reported access since.\",\n \"type\": \"boolean\"\n },\n \"kind\": {\n \"description\": \"Whether the owner is an organisation or a personal account, once the forge has said.\",\n \"enum\": [\n \"organization\",\n \"user\"\n ],\n \"type\": \"string\"\n },\n \"mode\": {\n \"description\": \"As `GitNamespace.mode` in the shared schema.\",\n \"enum\": [\n \"bridge\",\n \"manual\"\n ],\n \"type\": \"string\"\n },\n \"owner\": {\n \"$ref\": \"#/$defs/Segment\",\n \"description\": \"The organisation or user on the forge, lowercased.\"\n },\n \"ownerId\": {\n \"$ref\": \"#/$defs/ForgeId\",\n \"description\": \"The forge's id for the owner, once the forge has said. Unlike `owner`, it survives a rename.\"\n },\n \"repoCount\": {\n \"description\": \"How many repositories the VTC records in the namespace, in any state.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"requestedAt\": {\n \"description\": \"When binding was requested.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"resource\": {\n \"$ref\": \"#/$defs/Resource\",\n \"description\": \"The namespace as a resource: `<forge>/<owner>`.\"\n },\n \"roleDrift\": {\n \"description\": \"What the community's policy does with a forge role nobody granted: `report` it as drift for an administrator to resolve, or `enforce` the projection by reverting it. Community-wide; repeated on every namespace so that each row stands alone.\",\n \"enum\": [\n \"report\",\n \"enforce\"\n ],\n \"type\": \"string\"\n },\n \"roleMap\": {\n \"$ref\": \"#/$defs/RoleMap\",\n \"description\": \"The forge role each right projects to on a repository without a map of its own, as the serving bridge last reported it. Absent while `roleMapSource` is `unknown`: no map, the default included, is assumed.\"\n },\n \"roleMapReportedAt\": {\n \"description\": \"The `issuedAt` of the role-map report held, on the bridge's clock.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"roleMapSource\": {\n \"description\": \"`reported` — the bridge serving the namespace reported its role map. `unknown` — it has not, since the namespace was bound or came to be served by it.\",\n \"enum\": [\n \"reported\",\n \"unknown\"\n ],\n \"type\": \"string\"\n },\n \"state\": {\n \"description\": \"As `GitNamespace.state` in the shared schema.\",\n \"enum\": [\n \"pending\",\n \"bound\"\n ],\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"id\",\n \"forge\",\n \"owner\",\n \"resource\",\n \"mode\",\n \"state\",\n \"boundBy\",\n \"requestedAt\",\n \"admins\",\n \"repoCount\",\n \"headless\",\n \"installationRemoved\",\n \"roleDrift\",\n \"cascadeOnDeparture\",\n \"roleMapSource\"\n ],\n \"title\": \"NamespaceStatus\",\n \"type\": \"object\"\n },\n \"Resource\": {\n \"description\": \"A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.\",\n \"maxLength\": 455,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\",\n \"title\": \"Resource\",\n \"type\": \"string\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The namespaces the caller administers, or the one asked for.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"namespaces\": {\n \"description\": \"Every administered namespace, `pending` ones included, ordered by `resource`. Empty only for a holder of the community-administrator capability on a VTC with no namespace.\",\n \"items\": {\n \"$ref\": \"#/$defs/NamespaceStatus\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"namespaces\"\n ],\n \"title\": \"Git Namespaces — List Namespaces — response payload\",\n \"type\": \"object\"\n },\n \"RoleMap\": {\n \"additionalProperties\": false,\n \"description\": \"The forge role each repository right is given, as the forge applies it: after the forge's own ladder has rounded it down. `own` is the role `git.repo.own` projects to, `maintain` that of `git.repo.maintain`, `commit` that of `git.commit.sign` (`none` is fork-based contribution). There is no member for `git.ns.admin` or `git.repo.create`, which project to no forge role whatever a bridge is configured with. Ordered: `own` is at least `maintain`, which is at least `commit`, and `commit` is at most `write`.\",\n \"properties\": {\n \"commit\": {\n \"$ref\": \"#/$defs/MappedRole\"\n },\n \"maintain\": {\n \"$ref\": \"#/$defs/MappedRole\"\n },\n \"own\": {\n \"$ref\": \"#/$defs/MappedRole\"\n }\n },\n \"required\": [\n \"own\",\n \"maintain\",\n \"commit\"\n ],\n \"title\": \"RoleMap\",\n \"type\": \"object\"\n },\n \"Segment\": {\n \"description\": \"One lowercased owner or repository name. Forges compare these case-insensitively, so the wire form is always lowercase and a producer lowercases before sending. A leading `.` is refused, which rules out `.` and `..`.\",\n \"maxLength\": 100,\n \"minLength\": 1,\n \"pattern\": \"^[a-z0-9_-][a-z0-9._-]*$\",\n \"title\": \"Segment\",\n \"type\": \"string\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[error_codes::NOT_ADMINISTRATOR];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `git-ns/namespace/list:notAdministrator`
///
/// The caller administers no namespace — they hold neither the community-administrator capability nor a live, explicitly recorded `git.ns.admin` — or `namespace` names one they do not administer or one this VTC does not have. The three are answered alike, so the code cannot be used to learn which namespaces exist.
///
/// Declared `retryable: false`.
pub const NOT_ADMINISTRATOR: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "git-ns/namespace/list:notAdministrator",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6a01\",\n \"type\": \"https://trusttasks.org/spec/git-ns/namespace/list/0.1\",\n \"threadId\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6a01\",\n \"issuer\": \"did:webvh:QmCarolScid3:acme-vtc.example:carol\",\n \"recipient\": \"did:webvh:QmVtcScid7:acme-vtc.example\",\n \"issuedAt\": \"2026-09-26T09:00:00Z\",\n \"payload\": {}\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6a02\",\n \"type\": \"https://trusttasks.org/spec/git-ns/namespace/list/0.1#response\",\n \"threadId\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6a01\",\n \"issuer\": \"did:webvh:QmVtcScid7:acme-vtc.example\",\n \"recipient\": \"did:webvh:QmCarolScid3:acme-vtc.example:carol\",\n \"issuedAt\": \"2026-09-26T09:00:01Z\",\n \"payload\": {\n \"namespaces\": [\n {\n \"id\": \"ns_01J8Z6Q4M2\",\n \"forge\": \"github.com\",\n \"owner\": \"acme\",\n \"resource\": \"github.com/acme\",\n \"mode\": \"bridge\",\n \"state\": \"bound\",\n \"kind\": \"organization\",\n \"ownerId\": \"4411023\",\n \"bridgeDid\": \"did:webvh:QmBridgeScid9:bridge.acme.example\",\n \"boundBy\": \"did:webvh:QmDanaScid8:acme-vtc.example:dana\",\n \"requestedAt\": \"2026-09-23T09:40:00Z\",\n \"boundAt\": \"2026-09-23T09:42:10Z\",\n \"admins\": [\n \"did:webvh:QmCarolScid3:acme-vtc.example:carol\"\n ],\n \"repoCount\": 2,\n \"headless\": false,\n \"installationRemoved\": false,\n \"forgeStatus\": {\n \"installationId\": \"55120034\",\n \"appName\": \"Acme VTC\",\n \"appSlug\": \"acme-vtc\",\n \"missingPermissions\": [\"administration:write\"],\n \"permissionUpgradePending\": true,\n \"orgRulesets\": true,\n \"requiredWorkflow\": true,\n \"reportedAt\": \"2026-09-26T08:30:00Z\"\n },\n \"roleDrift\": \"report\",\n \"cascadeOnDeparture\": false,\n \"roleMap\": {\n \"own\": \"admin\",\n \"maintain\": \"maintain\",\n \"commit\": \"write\"\n },\n \"roleMapSource\": \"reported\",\n \"roleMapReportedAt\": \"2026-09-23T09:42:30Z\"\n }\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"There is no subject: the answer is the caller's own administered namespaces, never someone else's.",
"{\n \"subject\": \"did:webvh:QmBobScid2:acme-vtc.example:bob\"\n}",
),
(
"`namespace` is the VTC's identifier, not a resource filter by pattern; it cannot be empty.",
"{\n \"namespace\": \"\"\n}",
),
(
"`namespace` names one namespace.",
"{\n \"namespace\": [\n \"ns_01J8Z6Q4M2\",\n \"ns_01J8Z6Q4M3\"\n ]\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}