//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `git-ns/right/list`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///One right as the administrator's rights console shows it: a recorded `RightRecord` restated with the membership facts an administrator needs (`subjectMember`, `granterDeparted`), or a role-derived grant that carries no record. `git-ns/right/list` and `git-ns/right/issued-by-departed` are its only producers.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "AdminRightRow",
/// "description": "One right as the administrator's rights console shows it: a recorded `RightRecord` restated with the membership facts an administrator needs (`subjectMember`, `granterDeparted`), or a role-derived grant that carries no record. `git-ns/right/list` and `git-ns/right/issued-by-departed` are its only producers.",
/// "type": "object",
/// "required": [
/// "granterDeparted",
/// "origin",
/// "resource",
/// "right",
/// "subject",
/// "subjectMember"
/// ],
/// "properties": {
/// "breakGlass": {
/// "description": "Present exactly when `origin` is `recorded` and the record carries `breakGlass` — see `RightRecord.breakGlass`. Absent for a role-derived grant, which cannot be self-granted through break-glass.",
/// "$ref": "#/definitions/BreakGlass"
/// },
/// "expiresAt": {
/// "description": "When the right lapses. Absent: no expiry, or `origin` is `roleDerived` (a role-derived grant never expires on its own — it is withdrawn by editing `[hooks.git-trust] grant_on_role`).",
/// "type": "string",
/// "format": "date-time"
/// },
/// "grantedAt": {
/// "description": "Present exactly when `origin` is `recorded`.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "grantedBy": {
/// "description": "Who caused the right (see `RightRecord.grantedBy`). Present exactly when `origin` is `recorded`; a role-derived grant is published by the hook relay from configuration, not by an actor.",
/// "$ref": "#/definitions/Did"
/// },
/// "granterDeparted": {
/// "description": "Whether `grantedBy` was a member at the time of the grant and has since left. Always `false` when `origin` is `roleDerived`, or when the record's granter was never itself a member (the VTC's own DID, for a right it derives from configuration).",
/// "type": "boolean"
/// },
/// "origin": {
/// "$ref": "#/definitions/RightOrigin"
/// },
/// "reason": {
/// "description": "The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.",
/// "type": "string",
/// "maxLength": 1024
/// },
/// "resource": {
/// "$ref": "#/definitions/Resource"
/// },
/// "right": {
/// "$ref": "#/definitions/Right"
/// },
/// "subject": {
/// "description": "Who holds the right.",
/// "$ref": "#/definitions/Did"
/// },
/// "subjectMember": {
/// "description": "Whether `subject` is a current member of the community. `false` marks a right held by someone who has since left, or by an external signer the community never enrolled.",
/// "type": "boolean"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AdminRightRow {
///Present exactly when `origin` is `recorded` and the record carries `breakGlass` — see `RightRecord.breakGlass`. Absent for a role-derived grant, which cannot be self-granted through break-glass.
#[serde(
rename = "breakGlass",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub break_glass: ::std::option::Option<BreakGlass>,
///When the right lapses. Absent: no expiry, or `origin` is `roleDerived` (a role-derived grant never expires on its own — it is withdrawn by editing `[hooks.git-trust] grant_on_role`).
#[serde(
rename = "expiresAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub expires_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///Present exactly when `origin` is `recorded`.
#[serde(
rename = "grantedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub granted_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///Who caused the right (see `RightRecord.grantedBy`). Present exactly when `origin` is `recorded`; a role-derived grant is published by the hook relay from configuration, not by an actor.
#[serde(
rename = "grantedBy",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub granted_by: ::std::option::Option<Did>,
///Whether `grantedBy` was a member at the time of the grant and has since left. Always `false` when `origin` is `roleDerived`, or when the record's granter was never itself a member (the VTC's own DID, for a right it derives from configuration).
#[serde(rename = "granterDeparted")]
pub granter_departed: bool,
pub origin: RightOrigin,
///The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub reason: ::std::option::Option<AdminRightRowReason>,
pub resource: Resource,
pub right: Right,
///Who holds the right.
pub subject: Did,
///Whether `subject` is a current member of the community. `false` marks a right held by someone who has since left, or by an external signer the community never enrolled.
#[serde(rename = "subjectMember")]
pub subject_member: bool,
}
impl AdminRightRow {
pub fn builder() -> builder::AdminRightRow {
Default::default()
}
}
///The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.",
/// "type": "string",
/// "maxLength": 1024
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct AdminRightRowReason(::std::string::String);
impl ::std::ops::Deref for AdminRightRowReason {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<AdminRightRowReason> for ::std::string::String {
fn from(value: AdminRightRowReason) -> Self {
value.0
}
}
impl ::std::str::FromStr for AdminRightRowReason {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 1024usize {
return Err("longer than 1024 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for AdminRightRowReason {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for AdminRightRowReason {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for AdminRightRowReason {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for AdminRightRowReason {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///How a self-granted right came to be, and whether another administrator has since ratified it. A record whose `breakGlass` has no `ratifiedBy` is **unratified**: it is live and published like any other right, it does not count toward the last-owner or last-admin invariants, and any community administrator or namespace admin of its namespace may revoke it. Ratification (git-ns/right/ratify) sets `ratifiedBy` and `ratifiedAt`; from then on the record is an ordinary grant, and `breakGlass` stays as its history. Never published to the Trust Registry.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "BreakGlass",
/// "description": "How a self-granted right came to be, and whether another administrator has since ratified it. A record whose `breakGlass` has no `ratifiedBy` is **unratified**: it is live and published like any other right, it does not count toward the last-owner or last-admin invariants, and any community administrator or namespace admin of its namespace may revoke it. Ratification (git-ns/right/ratify) sets `ratifiedBy` and `ratifiedAt`; from then on the record is an ordinary grant, and `breakGlass` stays as its history. Never published to the Trust Registry.",
/// "type": "object",
/// "required": [
/// "at",
/// "by",
/// "justification"
/// ],
/// "properties": {
/// "at": {
/// "description": "When the VTC recorded the break-glass.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "by": {
/// "description": "Who broke the glass: always the record's `subject`, restated so the flag reads on its own.",
/// "$ref": "#/definitions/Did"
/// },
/// "effectiveAt": {
/// "description": "When the right takes effect, where the community's policy imposed a delay. Absent: it took effect at `at`. Until this instant the record confers nothing and is not published, and any administrator who may revoke it may do so.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "justification": {
/// "description": "The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1,
/// "pattern": "\\S"
/// },
/// "ratifiedAt": {
/// "description": "When it was ratified. Present exactly when `ratifiedBy` is.",
/// "type": "string",
/// "format": "date-time"
/// },
/// "ratifiedBy": {
/// "description": "The administrator who ratified the record — never its subject. Absent while unratified.",
/// "$ref": "#/definitions/Did"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct BreakGlass {
///When the VTC recorded the break-glass.
pub at: ::chrono::DateTime<::chrono::offset::Utc>,
///Who broke the glass: always the record's `subject`, restated so the flag reads on its own.
pub by: Did,
///When the right takes effect, where the community's policy imposed a delay. Absent: it took effect at `at`. Until this instant the record confers nothing and is not published, and any administrator who may revoke it may do so.
#[serde(
rename = "effectiveAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub effective_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.
pub justification: BreakGlassJustification,
///When it was ratified. Present exactly when `ratifiedBy` is.
#[serde(
rename = "ratifiedAt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub ratified_at: ::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
///The administrator who ratified the record — never its subject. Absent while unratified.
#[serde(
rename = "ratifiedBy",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub ratified_by: ::std::option::Option<Did>,
}
impl BreakGlass {
pub fn builder() -> builder::BreakGlass {
Default::default()
}
}
///The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.",
/// "type": "string",
/// "maxLength": 2048,
/// "minLength": 1,
/// "pattern": "\\S"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct BreakGlassJustification(::std::string::String);
impl ::std::ops::Deref for BreakGlassJustification {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<BreakGlassJustification> for ::std::string::String {
fn from(value: BreakGlassJustification) -> Self {
value.0
}
}
impl ::std::str::FromStr for BreakGlassJustification {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("\\S").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"\\S\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for BreakGlassJustification {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for BreakGlassJustification {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for BreakGlassJustification {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for BreakGlassJustification {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Did",
/// "description": "A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.",
/// "type": "string",
/// "maxLength": 2048,
/// "pattern": "^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct Did(::std::string::String);
impl ::std::ops::Deref for Did {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<Did> for ::std::string::String {
fn from(value: Did) -> Self {
value.0
}
}
impl ::std::str::FromStr for Did {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 2048usize {
return Err("longer than 2048 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> = ::std::sync::LazyLock::new(
|| {
::regress::Regex::new(
"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$",
)
.unwrap()
},
);
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for Did {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Did {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Did {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for Did {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///A community administrator enumerates every git right the VTC knows of, recorded and role-derived alike, across every namespace. The outer document members (id, type, issuer, recipient, issuedAt, expiresAt, proof) are owned by the framework — SPEC §6.3.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/git-ns/right/list/0.1",
/// "title": "Payload",
/// "description": "A community administrator enumerates every git right the VTC knows of, recorded and role-derived alike, across every namespace. The outer document members (id, type, issuer, recipient, issuedAt, expiresAt, proof) are owned by the framework — SPEC §6.3.",
/// "type": "object",
/// "properties": {
/// "cursor": {
/// "description": "Opaque continuation token from a previous response's `nextCursor`. A consumer supplying a `cursor` MUST NOT also change `resource` or `subject` from the request that produced it — start a fresh query instead.",
/// "type": "string"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "limit": {
/// "description": "Maximum rows to return in this page. A VTC clamps to 1..=500 (default 100).",
/// "type": "integer",
/// "maximum": 500.0,
/// "minimum": 1.0
/// },
/// "resource": {
/// "description": "Only rights on this resource or inside it. Absent: every resource.",
/// "$ref": "#/definitions/Resource"
/// },
/// "subject": {
/// "description": "Only rights held by this DID. Absent: every subject.",
/// "$ref": "#/definitions/Did"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
///Opaque continuation token from a previous response's `nextCursor`. A consumer supplying a `cursor` MUST NOT also change `resource` or `subject` from the request that produced it — start a fresh query instead.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub cursor: ::std::option::Option<::std::string::String>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Maximum rows to return in this page. A VTC clamps to 1..=500 (default 100).
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub limit: ::std::option::Option<::std::num::NonZeroU64>,
///Only rights on this resource or inside it. Absent: every resource.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub resource: ::std::option::Option<Resource>,
///Only rights held by this DID. Absent: every subject.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub subject: ::std::option::Option<Did>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
cursor: Default::default(),
ext: Default::default(),
limit: Default::default(),
resource: Default::default(),
subject: Default::default(),
}
}
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Resource",
/// "description": "A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.",
/// "type": "string",
/// "maxLength": 455,
/// "pattern": "^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct Resource(::std::string::String);
impl ::std::ops::Deref for Resource {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<Resource> for ::std::string::String {
fn from(value: Resource) -> Self {
value.0
}
}
impl ::std::str::FromStr for Resource {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 455usize {
return Err("longer than 455 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> = ::std::sync::LazyLock::new(
|| {
::regress::Regex::new(
"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$",
)
.unwrap()
},
);
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for Resource {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Resource {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Resource {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for Resource {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///The matching rows, ordered by resource then subject.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "The matching rows, ordered by resource then subject.",
/// "type": "object",
/// "required": [
/// "rights"
/// ],
/// "properties": {
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "nextCursor": {
/// "description": "Continuation token for the next page, or `null` when this is the last.",
/// "type": [
/// "string",
/// "null"
/// ]
/// },
/// "rights": {
/// "description": "Rows matching `resource` and `subject`, ordered by `resource` then `subject`. A break-glass record waiting out a policy delay is included — it is exactly the one other administrators have a window to revoke.",
/// "type": "array",
/// "items": {
/// "$ref": "#/definitions/AdminRightRow"
/// }
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
///Continuation token for the next page, or `null` when this is the last.
#[serde(
rename = "nextCursor",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub next_cursor: ::std::option::Option<::std::string::String>,
///Rows matching `resource` and `subject`, ordered by `resource` then `subject`. A break-glass record waiting out a policy delay is included — it is exactly the one other administrators have a window to revoke.
pub rights: ::std::vec::Vec<AdminRightRow>,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///One of the five git rights. Each string is also the TRQP `action` the VTC publishes the right under in its Trust Registry, so it is carried verbatim. `git.ns.admin` and `git.repo.create` apply to a namespace resource; `git.repo.own` and `git.repo.maintain` to a repository resource; `git.commit.sign` to either.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Right",
/// "description": "One of the five git rights. Each string is also the TRQP `action` the VTC publishes the right under in its Trust Registry, so it is carried verbatim. `git.ns.admin` and `git.repo.create` apply to a namespace resource; `git.repo.own` and `git.repo.maintain` to a repository resource; `git.commit.sign` to either.",
/// "type": "string",
/// "enum": [
/// "git.ns.admin",
/// "git.repo.create",
/// "git.repo.own",
/// "git.repo.maintain",
/// "git.commit.sign"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum Right {
#[serde(rename = "git.ns.admin")]
GitNsAdmin,
#[serde(rename = "git.repo.create")]
GitRepoCreate,
#[serde(rename = "git.repo.own")]
GitRepoOwn,
#[serde(rename = "git.repo.maintain")]
GitRepoMaintain,
#[serde(rename = "git.commit.sign")]
GitCommitSign,
}
impl ::std::fmt::Display for Right {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::GitNsAdmin => f.write_str("git.ns.admin"),
Self::GitRepoCreate => f.write_str("git.repo.create"),
Self::GitRepoOwn => f.write_str("git.repo.own"),
Self::GitRepoMaintain => f.write_str("git.repo.maintain"),
Self::GitCommitSign => f.write_str("git.commit.sign"),
}
}
}
impl ::std::str::FromStr for Right {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"git.ns.admin" => Ok(Self::GitNsAdmin),
"git.repo.create" => Ok(Self::GitRepoCreate),
"git.repo.own" => Ok(Self::GitRepoOwn),
"git.repo.maintain" => Ok(Self::GitRepoMaintain),
"git.commit.sign" => Ok(Self::GitCommitSign),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for Right {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for Right {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for Right {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
///Where a right an administrator sees came from. `recorded` — a `git-ns/*` record, governed by the rights model and returned nowhere the subject cannot eventually see it through `git-ns/view`. `roleDerived` — a v0.1 `[hooks.git-trust] grant_on_role` grant: published by the hook relay from the community's own role configuration, never written by any `git-ns/*` task, and not itself a `RightRecord` — it has no `grantedAt`, no `expiresAt` and no `reason`, only a subject, a right and a resource.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "RightOrigin",
/// "description": "Where a right an administrator sees came from. `recorded` — a `git-ns/*` record, governed by the rights model and returned nowhere the subject cannot eventually see it through `git-ns/view`. `roleDerived` — a v0.1 `[hooks.git-trust] grant_on_role` grant: published by the hook relay from the community's own role configuration, never written by any `git-ns/*` task, and not itself a `RightRecord` — it has no `grantedAt`, no `expiresAt` and no `reason`, only a subject, a right and a resource.",
/// "type": "string",
/// "enum": [
/// "recorded",
/// "roleDerived"
/// ]
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
#[non_exhaustive]
pub enum RightOrigin {
#[serde(rename = "recorded")]
Recorded,
#[serde(rename = "roleDerived")]
RoleDerived,
}
impl ::std::fmt::Display for RightOrigin {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Recorded => f.write_str("recorded"),
Self::RoleDerived => f.write_str("roleDerived"),
}
}
}
impl ::std::str::FromStr for RightOrigin {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"recorded" => Ok(Self::Recorded),
"roleDerived" => Ok(Self::RoleDerived),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for RightOrigin {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for RightOrigin {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for RightOrigin {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct AdminRightRow {
break_glass:
::std::result::Result<::std::option::Option<super::BreakGlass>, ::std::string::String>,
expires_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
granted_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
granted_by: ::std::result::Result<::std::option::Option<super::Did>, ::std::string::String>,
granter_departed: ::std::result::Result<bool, ::std::string::String>,
origin: ::std::result::Result<super::RightOrigin, ::std::string::String>,
reason: ::std::result::Result<
::std::option::Option<super::AdminRightRowReason>,
::std::string::String,
>,
resource: ::std::result::Result<super::Resource, ::std::string::String>,
right: ::std::result::Result<super::Right, ::std::string::String>,
subject: ::std::result::Result<super::Did, ::std::string::String>,
subject_member: ::std::result::Result<bool, ::std::string::String>,
}
impl ::std::default::Default for AdminRightRow {
fn default() -> Self {
Self {
break_glass: Ok(Default::default()),
expires_at: Ok(Default::default()),
granted_at: Ok(Default::default()),
granted_by: Ok(Default::default()),
granter_departed: Err("no value supplied for granter_departed".to_string()),
origin: Err("no value supplied for origin".to_string()),
reason: Ok(Default::default()),
resource: Err("no value supplied for resource".to_string()),
right: Err("no value supplied for right".to_string()),
subject: Err("no value supplied for subject".to_string()),
subject_member: Err("no value supplied for subject_member".to_string()),
}
}
}
impl AdminRightRow {
pub fn break_glass<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::BreakGlass>>,
T::Error: ::std::fmt::Display,
{
self.break_glass = value
.try_into()
.map_err(|e| format!("error converting supplied value for break_glass: {e}"));
self
}
pub fn expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.expires_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_at: {e}"));
self
}
pub fn granted_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.granted_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for granted_at: {e}"));
self
}
pub fn granted_by<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Did>>,
T::Error: ::std::fmt::Display,
{
self.granted_by = value
.try_into()
.map_err(|e| format!("error converting supplied value for granted_by: {e}"));
self
}
pub fn granter_departed<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.granter_departed = value
.try_into()
.map_err(|e| format!("error converting supplied value for granter_departed: {e}"));
self
}
pub fn origin<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::RightOrigin>,
T::Error: ::std::fmt::Display,
{
self.origin = value
.try_into()
.map_err(|e| format!("error converting supplied value for origin: {e}"));
self
}
pub fn reason<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::AdminRightRowReason>>,
T::Error: ::std::fmt::Display,
{
self.reason = value
.try_into()
.map_err(|e| format!("error converting supplied value for reason: {e}"));
self
}
pub fn resource<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Resource>,
T::Error: ::std::fmt::Display,
{
self.resource = value
.try_into()
.map_err(|e| format!("error converting supplied value for resource: {e}"));
self
}
pub fn right<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Right>,
T::Error: ::std::fmt::Display,
{
self.right = value
.try_into()
.map_err(|e| format!("error converting supplied value for right: {e}"));
self
}
pub fn subject<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Did>,
T::Error: ::std::fmt::Display,
{
self.subject = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject: {e}"));
self
}
pub fn subject_member<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.subject_member = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject_member: {e}"));
self
}
}
impl ::std::convert::TryFrom<AdminRightRow> for super::AdminRightRow {
type Error = super::error::ConversionError;
fn try_from(
value: AdminRightRow,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
break_glass: value.break_glass?,
expires_at: value.expires_at?,
granted_at: value.granted_at?,
granted_by: value.granted_by?,
granter_departed: value.granter_departed?,
origin: value.origin?,
reason: value.reason?,
resource: value.resource?,
right: value.right?,
subject: value.subject?,
subject_member: value.subject_member?,
})
}
}
impl ::std::convert::From<super::AdminRightRow> for AdminRightRow {
fn from(value: super::AdminRightRow) -> Self {
Self {
break_glass: Ok(value.break_glass),
expires_at: Ok(value.expires_at),
granted_at: Ok(value.granted_at),
granted_by: Ok(value.granted_by),
granter_departed: Ok(value.granter_departed),
origin: Ok(value.origin),
reason: Ok(value.reason),
resource: Ok(value.resource),
right: Ok(value.right),
subject: Ok(value.subject),
subject_member: Ok(value.subject_member),
}
}
}
#[derive(Clone, Debug)]
pub struct BreakGlass {
at: ::std::result::Result<::chrono::DateTime<::chrono::offset::Utc>, ::std::string::String>,
by: ::std::result::Result<super::Did, ::std::string::String>,
effective_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
justification: ::std::result::Result<super::BreakGlassJustification, ::std::string::String>,
ratified_at: ::std::result::Result<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
::std::string::String,
>,
ratified_by:
::std::result::Result<::std::option::Option<super::Did>, ::std::string::String>,
}
impl ::std::default::Default for BreakGlass {
fn default() -> Self {
Self {
at: Err("no value supplied for at".to_string()),
by: Err("no value supplied for by".to_string()),
effective_at: Ok(Default::default()),
justification: Err("no value supplied for justification".to_string()),
ratified_at: Ok(Default::default()),
ratified_by: Ok(Default::default()),
}
}
}
impl BreakGlass {
pub fn at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::chrono::DateTime<::chrono::offset::Utc>>,
T::Error: ::std::fmt::Display,
{
self.at = value
.try_into()
.map_err(|e| format!("error converting supplied value for at: {e}"));
self
}
pub fn by<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::Did>,
T::Error: ::std::fmt::Display,
{
self.by = value
.try_into()
.map_err(|e| format!("error converting supplied value for by: {e}"));
self
}
pub fn effective_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.effective_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for effective_at: {e}"));
self
}
pub fn justification<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::BreakGlassJustification>,
T::Error: ::std::fmt::Display,
{
self.justification = value
.try_into()
.map_err(|e| format!("error converting supplied value for justification: {e}"));
self
}
pub fn ratified_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<
::std::option::Option<::chrono::DateTime<::chrono::offset::Utc>>,
>,
T::Error: ::std::fmt::Display,
{
self.ratified_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for ratified_at: {e}"));
self
}
pub fn ratified_by<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Did>>,
T::Error: ::std::fmt::Display,
{
self.ratified_by = value
.try_into()
.map_err(|e| format!("error converting supplied value for ratified_by: {e}"));
self
}
}
impl ::std::convert::TryFrom<BreakGlass> for super::BreakGlass {
type Error = super::error::ConversionError;
fn try_from(
value: BreakGlass,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
at: value.at?,
by: value.by?,
effective_at: value.effective_at?,
justification: value.justification?,
ratified_at: value.ratified_at?,
ratified_by: value.ratified_by?,
})
}
}
impl ::std::convert::From<super::BreakGlass> for BreakGlass {
fn from(value: super::BreakGlass) -> Self {
Self {
at: Ok(value.at),
by: Ok(value.by),
effective_at: Ok(value.effective_at),
justification: Ok(value.justification),
ratified_at: Ok(value.ratified_at),
ratified_by: Ok(value.ratified_by),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
cursor: ::std::result::Result<
::std::option::Option<::std::string::String>,
::std::string::String,
>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
limit: ::std::result::Result<
::std::option::Option<::std::num::NonZeroU64>,
::std::string::String,
>,
resource:
::std::result::Result<::std::option::Option<super::Resource>, ::std::string::String>,
subject: ::std::result::Result<::std::option::Option<super::Did>, ::std::string::String>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
cursor: Ok(Default::default()),
ext: Ok(Default::default()),
limit: Ok(Default::default()),
resource: Ok(Default::default()),
subject: Ok(Default::default()),
}
}
}
impl Payload {
pub fn cursor<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.cursor = value
.try_into()
.map_err(|e| format!("error converting supplied value for cursor: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn limit<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::num::NonZeroU64>>,
T::Error: ::std::fmt::Display,
{
self.limit = value
.try_into()
.map_err(|e| format!("error converting supplied value for limit: {e}"));
self
}
pub fn resource<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Resource>>,
T::Error: ::std::fmt::Display,
{
self.resource = value
.try_into()
.map_err(|e| format!("error converting supplied value for resource: {e}"));
self
}
pub fn subject<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Did>>,
T::Error: ::std::fmt::Display,
{
self.subject = value
.try_into()
.map_err(|e| format!("error converting supplied value for subject: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
cursor: value.cursor?,
ext: value.ext?,
limit: value.limit?,
resource: value.resource?,
subject: value.subject?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
cursor: Ok(value.cursor),
ext: Ok(value.ext),
limit: Ok(value.limit),
resource: Ok(value.resource),
subject: Ok(value.subject),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
next_cursor: ::std::result::Result<
::std::option::Option<::std::string::String>,
::std::string::String,
>,
rights: ::std::result::Result<::std::vec::Vec<super::AdminRightRow>, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
ext: Ok(Default::default()),
next_cursor: Ok(Default::default()),
rights: Err("no value supplied for rights".to_string()),
}
}
}
impl Response {
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn next_cursor<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<::std::string::String>>,
T::Error: ::std::fmt::Display,
{
self.next_cursor = value
.try_into()
.map_err(|e| format!("error converting supplied value for next_cursor: {e}"));
self
}
pub fn rights<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::AdminRightRow>>,
T::Error: ::std::fmt::Display,
{
self.rights = value
.try_into()
.map_err(|e| format!("error converting supplied value for rights: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
ext: value.ext?,
next_cursor: value.next_cursor?,
rights: value.rights?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
ext: Ok(value.ext),
next_cursor: Ok(value.next_cursor),
rights: Ok(value.rights),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/git-ns/right/list/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AdminRightRow\": {\n \"additionalProperties\": false,\n \"description\": \"One right as the administrator's rights console shows it: a recorded `RightRecord` restated with the membership facts an administrator needs (`subjectMember`, `granterDeparted`), or a role-derived grant that carries no record. `git-ns/right/list` and `git-ns/right/issued-by-departed` are its only producers.\",\n \"properties\": {\n \"breakGlass\": {\n \"$ref\": \"#/$defs/BreakGlass\",\n \"description\": \"Present exactly when `origin` is `recorded` and the record carries `breakGlass` — see `RightRecord.breakGlass`. Absent for a role-derived grant, which cannot be self-granted through break-glass.\"\n },\n \"expiresAt\": {\n \"description\": \"When the right lapses. Absent: no expiry, or `origin` is `roleDerived` (a role-derived grant never expires on its own — it is withdrawn by editing `[hooks.git-trust] grant_on_role`).\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"grantedAt\": {\n \"description\": \"Present exactly when `origin` is `recorded`.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"grantedBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who caused the right (see `RightRecord.grantedBy`). Present exactly when `origin` is `recorded`; a role-derived grant is published by the hook relay from configuration, not by an actor.\"\n },\n \"granterDeparted\": {\n \"description\": \"Whether `grantedBy` was a member at the time of the grant and has since left. Always `false` when `origin` is `roleDerived`, or when the record's granter was never itself a member (the VTC's own DID, for a right it derives from configuration).\",\n \"type\": \"boolean\"\n },\n \"origin\": {\n \"$ref\": \"#/$defs/RightOrigin\"\n },\n \"reason\": {\n \"description\": \"The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.\",\n \"maxLength\": 1024,\n \"type\": \"string\"\n },\n \"resource\": {\n \"$ref\": \"#/$defs/Resource\"\n },\n \"right\": {\n \"$ref\": \"#/$defs/Right\"\n },\n \"subject\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who holds the right.\"\n },\n \"subjectMember\": {\n \"description\": \"Whether `subject` is a current member of the community. `false` marks a right held by someone who has since left, or by an external signer the community never enrolled.\",\n \"type\": \"boolean\"\n }\n },\n \"required\": [\n \"subject\",\n \"right\",\n \"resource\",\n \"origin\",\n \"subjectMember\",\n \"granterDeparted\"\n ],\n \"title\": \"AdminRightRow\",\n \"type\": \"object\"\n },\n \"BreakGlass\": {\n \"additionalProperties\": false,\n \"description\": \"How a self-granted right came to be, and whether another administrator has since ratified it. A record whose `breakGlass` has no `ratifiedBy` is **unratified**: it is live and published like any other right, it does not count toward the last-owner or last-admin invariants, and any community administrator or namespace admin of its namespace may revoke it. Ratification (git-ns/right/ratify) sets `ratifiedBy` and `ratifiedAt`; from then on the record is an ordinary grant, and `breakGlass` stays as its history. Never published to the Trust Registry.\",\n \"properties\": {\n \"at\": {\n \"description\": \"When the VTC recorded the break-glass.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"by\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who broke the glass: always the record's `subject`, restated so the flag reads on its own.\"\n },\n \"effectiveAt\": {\n \"description\": \"When the right takes effect, where the community's policy imposed a delay. Absent: it took effect at `at`. Until this instant the record confers nothing and is not published, and any administrator who may revoke it may do so.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"justification\": {\n \"description\": \"The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.\",\n \"maxLength\": 2048,\n \"minLength\": 1,\n \"pattern\": \"\\\\S\",\n \"type\": \"string\"\n },\n \"ratifiedAt\": {\n \"description\": \"When it was ratified. Present exactly when `ratifiedBy` is.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ratifiedBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"The administrator who ratified the record — never its subject. Absent while unratified.\"\n }\n },\n \"required\": [\n \"by\",\n \"at\",\n \"justification\"\n ],\n \"title\": \"BreakGlass\",\n \"type\": \"object\"\n },\n \"Did\": {\n \"description\": \"A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.\",\n \"maxLength\": 2048,\n \"pattern\": \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\",\n \"title\": \"Did\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Resource\": {\n \"description\": \"A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.\",\n \"maxLength\": 455,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\",\n \"title\": \"Resource\",\n \"type\": \"string\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The matching rows, ordered by resource then subject.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"nextCursor\": {\n \"description\": \"Continuation token for the next page, or `null` when this is the last.\",\n \"type\": [\n \"string\",\n \"null\"\n ]\n },\n \"rights\": {\n \"description\": \"Rows matching `resource` and `subject`, ordered by `resource` then `subject`. A break-glass record waiting out a policy delay is included — it is exactly the one other administrators have a window to revoke.\",\n \"items\": {\n \"$ref\": \"#/$defs/AdminRightRow\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"rights\"\n ],\n \"title\": \"Git Namespaces — List Rights — response payload\",\n \"type\": \"object\"\n },\n \"Right\": {\n \"description\": \"One of the five git rights. Each string is also the TRQP `action` the VTC publishes the right under in its Trust Registry, so it is carried verbatim. `git.ns.admin` and `git.repo.create` apply to a namespace resource; `git.repo.own` and `git.repo.maintain` to a repository resource; `git.commit.sign` to either.\",\n \"enum\": [\n \"git.ns.admin\",\n \"git.repo.create\",\n \"git.repo.own\",\n \"git.repo.maintain\",\n \"git.commit.sign\"\n ],\n \"title\": \"Right\",\n \"type\": \"string\"\n },\n \"RightOrigin\": {\n \"description\": \"Where a right an administrator sees came from. `recorded` — a `git-ns/*` record, governed by the rights model and returned nowhere the subject cannot eventually see it through `git-ns/view`. `roleDerived` — a v0.1 `[hooks.git-trust] grant_on_role` grant: published by the hook relay from the community's own role configuration, never written by any `git-ns/*` task, and not itself a `RightRecord` — it has no `grantedAt`, no `expiresAt` and no `reason`, only a subject, a right and a resource.\",\n \"enum\": [\n \"recorded\",\n \"roleDerived\"\n ],\n \"title\": \"RightOrigin\",\n \"type\": \"string\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/git-ns/right/list/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"A community administrator enumerates every git right the VTC knows of, recorded and role-derived alike, across every namespace. The outer document members (id, type, issuer, recipient, issuedAt, expiresAt, proof) are owned by the framework — SPEC §6.3.\",\n \"properties\": {\n \"cursor\": {\n \"description\": \"Opaque continuation token from a previous response's `nextCursor`. A consumer supplying a `cursor` MUST NOT also change `resource` or `subject` from the request that produced it — start a fresh query instead.\",\n \"type\": \"string\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"limit\": {\n \"description\": \"Maximum rows to return in this page. A VTC clamps to 1..=500 (default 100).\",\n \"maximum\": 500,\n \"minimum\": 1,\n \"type\": \"integer\"\n },\n \"resource\": {\n \"$ref\": \"#/$defs/Resource\",\n \"description\": \"Only rights on this resource or inside it. Absent: every resource.\"\n },\n \"subject\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Only rights held by this DID. Absent: every subject.\"\n }\n },\n \"title\": \"Git Namespaces — List Rights — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/git-ns/right/list/0.1#response";
const IS_PROOF_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AdminRightRow\": {\n \"additionalProperties\": false,\n \"description\": \"One right as the administrator's rights console shows it: a recorded `RightRecord` restated with the membership facts an administrator needs (`subjectMember`, `granterDeparted`), or a role-derived grant that carries no record. `git-ns/right/list` and `git-ns/right/issued-by-departed` are its only producers.\",\n \"properties\": {\n \"breakGlass\": {\n \"$ref\": \"#/$defs/BreakGlass\",\n \"description\": \"Present exactly when `origin` is `recorded` and the record carries `breakGlass` — see `RightRecord.breakGlass`. Absent for a role-derived grant, which cannot be self-granted through break-glass.\"\n },\n \"expiresAt\": {\n \"description\": \"When the right lapses. Absent: no expiry, or `origin` is `roleDerived` (a role-derived grant never expires on its own — it is withdrawn by editing `[hooks.git-trust] grant_on_role`).\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"grantedAt\": {\n \"description\": \"Present exactly when `origin` is `recorded`.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"grantedBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who caused the right (see `RightRecord.grantedBy`). Present exactly when `origin` is `recorded`; a role-derived grant is published by the hook relay from configuration, not by an actor.\"\n },\n \"granterDeparted\": {\n \"description\": \"Whether `grantedBy` was a member at the time of the grant and has since left. Always `false` when `origin` is `roleDerived`, or when the record's granter was never itself a member (the VTC's own DID, for a right it derives from configuration).\",\n \"type\": \"boolean\"\n },\n \"origin\": {\n \"$ref\": \"#/$defs/RightOrigin\"\n },\n \"reason\": {\n \"description\": \"The granter's free-text reason, restated from the `RightRecord`. Absent when `origin` is `roleDerived`, or the record carries none.\",\n \"maxLength\": 1024,\n \"type\": \"string\"\n },\n \"resource\": {\n \"$ref\": \"#/$defs/Resource\"\n },\n \"right\": {\n \"$ref\": \"#/$defs/Right\"\n },\n \"subject\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who holds the right.\"\n },\n \"subjectMember\": {\n \"description\": \"Whether `subject` is a current member of the community. `false` marks a right held by someone who has since left, or by an external signer the community never enrolled.\",\n \"type\": \"boolean\"\n }\n },\n \"required\": [\n \"subject\",\n \"right\",\n \"resource\",\n \"origin\",\n \"subjectMember\",\n \"granterDeparted\"\n ],\n \"title\": \"AdminRightRow\",\n \"type\": \"object\"\n },\n \"BreakGlass\": {\n \"additionalProperties\": false,\n \"description\": \"How a self-granted right came to be, and whether another administrator has since ratified it. A record whose `breakGlass` has no `ratifiedBy` is **unratified**: it is live and published like any other right, it does not count toward the last-owner or last-admin invariants, and any community administrator or namespace admin of its namespace may revoke it. Ratification (git-ns/right/ratify) sets `ratifiedBy` and `ratifiedAt`; from then on the record is an ordinary grant, and `breakGlass` stays as its history. Never published to the Trust Registry.\",\n \"properties\": {\n \"at\": {\n \"description\": \"When the VTC recorded the break-glass.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"by\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"Who broke the glass: always the record's `subject`, restated so the flag reads on its own.\"\n },\n \"effectiveAt\": {\n \"description\": \"When the right takes effect, where the community's policy imposed a delay. Absent: it took effect at `at`. Until this instant the record confers nothing and is not published, and any administrator who may revoke it may do so.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"justification\": {\n \"description\": \"The actor's statement of why nobody else could grant this right. Shown to every community administrator, every namespace admin of the namespace and every owner of the resource; kept in the audit record; never published.\",\n \"maxLength\": 2048,\n \"minLength\": 1,\n \"pattern\": \"\\\\S\",\n \"type\": \"string\"\n },\n \"ratifiedAt\": {\n \"description\": \"When it was ratified. Present exactly when `ratifiedBy` is.\",\n \"format\": \"date-time\",\n \"type\": \"string\"\n },\n \"ratifiedBy\": {\n \"$ref\": \"#/$defs/Did\",\n \"description\": \"The administrator who ratified the record — never its subject. Absent while unratified.\"\n }\n },\n \"required\": [\n \"by\",\n \"at\",\n \"justification\"\n ],\n \"title\": \"BreakGlass\",\n \"type\": \"object\"\n },\n \"Did\": {\n \"description\": \"A bare DID in the W3C DID Core syntax (§3.1): `did:`, a method name of lowercase letters and digits, `:`, and a method-specific id of colon-separated segments drawn from `A-Z a-z 0-9 . - _` and percent-encoded octets, the last segment non-empty. A DID URL is not a DID: no path, query or fragment (`/`, `?`, `#`), so a verification-method id such as `did:key:z6Mk…#z6Mk…` is refused. Compared by exact string equality — no case folding or percent-decoding. A consumer MUST still treat the value as data: the pattern keeps shell metacharacters, whitespace and quotes out of the wire form, but it does not make a DID safe to splice into a command or markup.\",\n \"maxLength\": 2048,\n \"pattern\": \"^did:[a-z0-9]+:(?:(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})*:)*(?:[A-Za-z0-9._-]|%[0-9A-Fa-f]{2})+$\",\n \"title\": \"Did\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Resource\": {\n \"description\": \"A forge-qualified resource: `<forge-host>/<owner>` for a namespace, or `<forge-host>/<owner>/<repo>` for one repository, all lowercase — `github.com/acme`, `github.com/acme/widgets`, `codeberg.org/acme`. The forge is never implied: `acme/widgets` alone is not a resource. Containment is by whole segment: `github.com/acme` contains `github.com/acme/widgets` and does not contain `github.com/acme-labs/x` or `codeberg.org/acme/widgets`.\",\n \"maxLength\": 455,\n \"pattern\": \"^[a-z0-9](?:[a-z0-9-]*[a-z0-9])?(?:\\\\.[a-z0-9](?:[a-z0-9-]*[a-z0-9])?)+(?:/[a-z0-9_-][a-z0-9._-]{0,99}){1,2}$\",\n \"title\": \"Resource\",\n \"type\": \"string\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"The matching rows, ordered by resource then subject.\",\n \"properties\": {\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"nextCursor\": {\n \"description\": \"Continuation token for the next page, or `null` when this is the last.\",\n \"type\": [\n \"string\",\n \"null\"\n ]\n },\n \"rights\": {\n \"description\": \"Rows matching `resource` and `subject`, ordered by `resource` then `subject`. A break-glass record waiting out a policy delay is included — it is exactly the one other administrators have a window to revoke.\",\n \"items\": {\n \"$ref\": \"#/$defs/AdminRightRow\"\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"rights\"\n ],\n \"title\": \"Git Namespaces — List Rights — response payload\",\n \"type\": \"object\"\n },\n \"Right\": {\n \"description\": \"One of the five git rights. Each string is also the TRQP `action` the VTC publishes the right under in its Trust Registry, so it is carried verbatim. `git.ns.admin` and `git.repo.create` apply to a namespace resource; `git.repo.own` and `git.repo.maintain` to a repository resource; `git.commit.sign` to either.\",\n \"enum\": [\n \"git.ns.admin\",\n \"git.repo.create\",\n \"git.repo.own\",\n \"git.repo.maintain\",\n \"git.commit.sign\"\n ],\n \"title\": \"Right\",\n \"type\": \"string\"\n },\n \"RightOrigin\": {\n \"description\": \"Where a right an administrator sees came from. `recorded` — a `git-ns/*` record, governed by the rights model and returned nowhere the subject cannot eventually see it through `git-ns/view`. `roleDerived` — a v0.1 `[hooks.git-trust] grant_on_role` grant: published by the hook relay from the community's own role configuration, never written by any `git-ns/*` task, and not itself a `RightRecord` — it has no `grantedAt`, no `expiresAt` and no `reason`, only a subject, a right and a resource.\",\n \"enum\": [\n \"recorded\",\n \"roleDerived\"\n ],\n \"title\": \"RightOrigin\",\n \"type\": \"string\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[error_codes::NOT_COMMUNITY_ADMINISTRATOR];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `git-ns/right/list:notCommunityAdministrator`
///
/// The caller does not hold the community-administrator capability. Unlike `git-ns/namespace/list` and `git-ns/repo/list`, holding `git.ns.admin` on some namespace is not enough: this task's answer spans every namespace and includes every granter's reason, which only the community-administrator capability entitles a caller to see.
///
/// Declared `retryable: false`.
pub const NOT_COMMUNITY_ADMINISTRATOR: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "git-ns/right/list:notCommunityAdministrator",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6b01\",\n \"type\": \"https://trusttasks.org/spec/git-ns/right/list/0.1\",\n \"threadId\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6b01\",\n \"issuer\": \"did:webvh:QmDanaScid8:acme-vtc.example:dana\",\n \"recipient\": \"did:webvh:QmVtcScid7:acme-vtc.example\",\n \"issuedAt\": \"2026-09-26T09:10:00Z\",\n \"payload\": {\n \"resource\": \"github.com/acme/widgets\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6b02\",\n \"type\": \"https://trusttasks.org/spec/git-ns/right/list/0.1#response\",\n \"threadId\": \"urn:uuid:7a2e4c10-3b5d-4f6e-9a1b-2c3d4e5f6b01\",\n \"issuer\": \"did:webvh:QmVtcScid7:acme-vtc.example\",\n \"recipient\": \"did:webvh:QmDanaScid8:acme-vtc.example:dana\",\n \"issuedAt\": \"2026-09-26T09:10:01Z\",\n \"payload\": {\n \"rights\": [\n {\n \"subject\": \"did:webvh:QmCarolScid3:acme-vtc.example:carol\",\n \"right\": \"git.repo.own\",\n \"resource\": \"github.com/acme/widgets\",\n \"origin\": \"recorded\",\n \"grantedBy\": \"did:webvh:QmBobScid2:acme-vtc.example:bob\",\n \"grantedAt\": \"2026-09-23T09:50:00Z\",\n \"reason\": \"Founding maintainer of the repository.\",\n \"subjectMember\": true,\n \"granterDeparted\": false\n },\n {\n \"subject\": \"did:webvh:QmEveScid11:acme-vtc.example:eve\",\n \"right\": \"git.repo.maintain\",\n \"resource\": \"github.com/acme/widgets\",\n \"origin\": \"recorded\",\n \"grantedBy\": \"did:webvh:QmEveScid11:acme-vtc.example:eve\",\n \"grantedAt\": \"2026-09-25T14:00:00Z\",\n \"reason\": \"On-call incident response; no maintainer was reachable.\",\n \"subjectMember\": true,\n \"granterDeparted\": false,\n \"breakGlass\": {\n \"by\": \"did:webvh:QmEveScid11:acme-vtc.example:eve\",\n \"at\": \"2026-09-25T14:00:00Z\",\n \"justification\": \"Production outage; every maintainer was unreachable and the fix could not wait for reseating.\"\n }\n },\n {\n \"subject\": \"did:webvh:QmFrankScid12:acme-vtc.example:frank\",\n \"right\": \"git.commit.sign\",\n \"resource\": \"github.com/acme/widgets\",\n \"origin\": \"roleDerived\",\n \"subjectMember\": true,\n \"granterDeparted\": false\n }\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"`resource` is not forge-qualified — no forge host segment, just an owner/repo pair.",
"{\n \"resource\": \"acme/widgets\"\n}",
),
(
"`subject` is a DID URL (carries a fragment), not a bare DID — SPEC's `Did` pattern refuses it.",
"{\n \"subject\": \"did:key:z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK#z6MkhaXgBZDvotDkL5257faiztiGiC2QtKLGpbnnEGta2doK\"\n}",
),
("`limit` above the declared maximum of 500.", "{\n \"limit\": 501\n}"),
(
"Bare/unnamespaced ext key — SPEC §4.5.1 requires every immediate child of ext to be reverse-DNS namespaced.",
"{\n \"ext\": {\n \"bare-key\": {\n \"anything\": \"here\"\n }\n }\n}",
),
(
"Unknown top-level payload member — additionalProperties: false catches `namespaceId`.",
"{\n \"namespaceId\": \"ns_01J8Z6Q4M2\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
/// Each `"variant": "response"` fixture in
/// `payload.invalid-examples.json` MUST be rejected as a
/// response payload by at least one of: serde deserialization
/// into `Response`, or JSON-Schema validation against the
/// `$anchor: "response"` sub-schema (validate feature).
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_response_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Response variant: unrecognised `origin` — the enum is closed to `recorded` and `roleDerived`.",
"{\n \"rights\": [\n {\n \"granterDeparted\": false,\n \"origin\": \"inherited\",\n \"resource\": \"github.com/acme/widgets\",\n \"right\": \"git.repo.own\",\n \"subject\": \"did:webvh:QmCarolScid3:acme-vtc.example:carol\",\n \"subjectMember\": true\n }\n ]\n}",
),
(
"Response variant: missing required `rights` member.",
"{\n \"nextCursor\": null\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Response>(value.clone()).is_ok();
let schema_ok = super::Response::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid response example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}