//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `trust-task-discovery`. Version: `0.3`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///The freshness bounds a responder applies, as a consumer, to the `issuedAt` of a document it receives (SPEC.md §7.2 item 13). A responder refuses a document when now > issuedAt + maxAgeSeconds + clockSkewSeconds, and when issuedAt > now + clockSkewSeconds. It says nothing about `expiresAt`, which is honoured independently (SPEC.md §7.2 item 4). Both members are whole seconds.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Acceptance window",
/// "description": "The freshness bounds a responder applies, as a consumer, to the `issuedAt` of a document it receives (SPEC.md §7.2 item 13). A responder refuses a document when now > issuedAt + maxAgeSeconds + clockSkewSeconds, and when issuedAt > now + clockSkewSeconds. It says nothing about `expiresAt`, which is honoured independently (SPEC.md §7.2 item 4). Both members are whole seconds.",
/// "type": "object",
/// "required": [
/// "clockSkewSeconds",
/// "maxAgeSeconds"
/// ],
/// "properties": {
/// "clockSkewSeconds": {
/// "description": "The clock-skew tolerance, in whole seconds, the responder applies in both directions: added to maxAgeSeconds for a document in its past, and allowed for an `issuedAt` in its future (SPEC.md §4.2, §7.2 item 13). Zero when it applies none.",
/// "type": "integer",
/// "minimum": 0.0
/// },
/// "maxAgeSeconds": {
/// "description": "The greatest age, in whole seconds, of a document's `issuedAt` at which the responder still accepts the document, before any clock-skew tolerance is applied.",
/// "type": "integer",
/// "minimum": 1.0
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct AcceptanceWindow {
///The clock-skew tolerance, in whole seconds, the responder applies in both directions: added to maxAgeSeconds for a document in its past, and allowed for an `issuedAt` in its future (SPEC.md §4.2, §7.2 item 13). Zero when it applies none.
#[serde(rename = "clockSkewSeconds")]
pub clock_skew_seconds: u64,
///The greatest age, in whole seconds, of a document's `issuedAt` at which the responder still accepts the document, before any clock-skew tolerance is applied.
#[serde(rename = "maxAgeSeconds")]
pub max_age_seconds: ::std::num::NonZeroU64,
}
impl AcceptanceWindow {
pub fn builder() -> builder::AcceptanceWindow {
Default::default()
}
}
///Request payload for the framework-defined trust-task-discovery exchange. Carries zero or more slug-glob patterns the discoverer wants the responder to filter against. The response payload schema is reachable via $anchor: 'response'.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/trust-task-discovery/0.3",
/// "title": "Payload",
/// "description": "Request payload for the framework-defined trust-task-discovery exchange. Carries zero or more slug-glob patterns the discoverer wants the responder to filter against. The response payload schema is reachable via $anchor: 'response'.",
/// "type": "object",
/// "properties": {
/// "patterns": {
/// "description": "Patterns are ORed: a slug matches the query if at least one pattern matches it. If the array is omitted or empty, the responder MUST treat the query as ['*'] — return every supported task. Bounded at 16 entries as parser hardening (SPEC.md §12.2), not as a capability limit: matching an unbounded pattern list against every published slug is work a responder does on an unauthenticated request, and a discoverer wanting more asks for '*' and filters locally.",
/// "type": "array",
/// "items": {
/// "description": "Slug-glob pattern. Matches: '*' (every slug); '<prefix>/*' (any slug starting with '<prefix>/' — e.g. 'acl/*' matches 'acl/grant', 'acl/revoke', 'acl/grant/sub'); otherwise an exact slug match. Wildcards anywhere other than as a trailing segment are not interpreted — the only sigils are the trailing '/*' and the bare '*'.",
/// "type": "string",
/// "minLength": 1
/// },
/// "maxItems": 16
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
///Patterns are ORed: a slug matches the query if at least one pattern matches it. If the array is omitted or empty, the responder MUST treat the query as ['*'] — return every supported task. Bounded at 16 entries as parser hardening (SPEC.md §12.2), not as a capability limit: matching an unbounded pattern list against every published slug is work a responder does on an unauthenticated request, and a discoverer wanting more asks for '*' and filters locally.
#[serde(default, skip_serializing_if = "::std::vec::Vec::is_empty")]
pub patterns: ::std::vec::Vec<PayloadPatternsItem>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
patterns: Default::default(),
}
}
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///Slug-glob pattern. Matches: '*' (every slug); '<prefix>/*' (any slug starting with '<prefix>/' — e.g. 'acl/*' matches 'acl/grant', 'acl/revoke', 'acl/grant/sub'); otherwise an exact slug match. Wildcards anywhere other than as a trailing segment are not interpreted — the only sigils are the trailing '/*' and the bare '*'.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Slug-glob pattern. Matches: '*' (every slug); '<prefix>/*' (any slug starting with '<prefix>/' — e.g. 'acl/*' matches 'acl/grant', 'acl/revoke', 'acl/grant/sub'); otherwise an exact slug match. Wildcards anywhere other than as a trailing segment are not interpreted — the only sigils are the trailing '/*' and the bare '*'.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadPatternsItem(::std::string::String);
impl ::std::ops::Deref for PayloadPatternsItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadPatternsItem> for ::std::string::String {
fn from(value: PayloadPatternsItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadPatternsItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadPatternsItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadPatternsItem {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadPatternsItem {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadPatternsItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///List of bare Type URIs the responding party supports. Carried in a Trust Task document whose type is https://trusttasks.org/spec/trust-task-discovery/0.3#response. A response-level `acceptanceWindow` is the window the responder applies to every listed Type URI whose entry carries none of its own. Where neither is present for an entry, the discoverer has learnt nothing about that entry's window and MUST NOT read the absence as the absence of a window.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "description": "List of bare Type URIs the responding party supports. Carried in a Trust Task document whose type is https://trusttasks.org/spec/trust-task-discovery/0.3#response. A response-level `acceptanceWindow` is the window the responder applies to every listed Type URI whose entry carries none of its own. Where neither is present for an entry, the discoverer has learnt nothing about that entry's window and MUST NOT read the absence as the absence of a window.",
/// "type": "object",
/// "required": [
/// "supportedTypes"
/// ],
/// "properties": {
/// "acceptanceWindow": {
/// "$ref": "#/definitions/AcceptanceWindow"
/// },
/// "frameworkVersion": {
/// "description": "MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.",
/// "type": "string",
/// "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)$"
/// },
/// "supportedTypes": {
/// "description": "Each entry's Type URI MUST match at least one of the request's patterns (if any were supplied). Order is not significant. Duplicates by Type URI are not permitted, regardless of whether the entry is in shorthand or expanded form.",
/// "type": "array",
/// "items": {
/// "description": "An entry in the supportedTypes list. SHORTHAND: a bare Type URI string. EXPANDED: an object with `type` and optional capability annotations (`requiredExt`, `acceptanceWindow`).",
/// "oneOf": [
/// {
/// "description": "Shorthand form: a bare Type URI string. Equivalent to an object with only the `type` member set.",
/// "type": "string",
/// "format": "uri"
/// },
/// {
/// "description": "Object form: lists a Type URI together with optional capability annotations. An `acceptanceWindow` here is the window the responder applies to documents of this Type URI, and takes precedence over the response-level `acceptanceWindow` for this entry.",
/// "type": "object",
/// "required": [
/// "type"
/// ],
/// "properties": {
/// "acceptanceWindow": {
/// "$ref": "#/definitions/AcceptanceWindow"
/// },
/// "requiredExt": {
/// "description": "Reverse-DNS `ext` namespaces this responder requires on inbound documents of this Type URI as a matter of local policy (SPEC.md §4.5.1, §7.2). A producer that does not populate every listed namespace will receive a `malformedRequest` rejection. Optional; reserved-but-recognized in 0.1, RECOMMENDED in future revisions for responders that enforce such policies.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// },
/// "minItems": 1,
/// "uniqueItems": true
/// },
/// "type": {
/// "description": "A bare Type URI (no #request or #response fragment). The responder supports both request and response variants of every entry it lists.",
/// "type": "string",
/// "format": "uri"
/// }
/// },
/// "additionalProperties": false
/// }
/// ]
/// }
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(
rename = "acceptanceWindow",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub acceptance_window: ::std::option::Option<AcceptanceWindow>,
///MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.
#[serde(
rename = "frameworkVersion",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub framework_version: ::std::option::Option<ResponseFrameworkVersion>,
///Each entry's Type URI MUST match at least one of the request's patterns (if any were supplied). Order is not significant. Duplicates by Type URI are not permitted, regardless of whether the entry is in shorthand or expanded form.
#[serde(rename = "supportedTypes")]
pub supported_types: ::std::vec::Vec<ResponseSupportedTypesItem>,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.",
/// "type": "string",
/// "pattern": "^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseFrameworkVersion(::std::string::String);
impl ::std::ops::Deref for ResponseFrameworkVersion {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseFrameworkVersion> for ::std::string::String {
fn from(value: ResponseFrameworkVersion) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseFrameworkVersion {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)$")
.unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)\\.(0|[1-9][0-9]*)$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseFrameworkVersion {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ResponseFrameworkVersion {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ResponseFrameworkVersion {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseFrameworkVersion {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///An entry in the supportedTypes list. SHORTHAND: a bare Type URI string. EXPANDED: an object with `type` and optional capability annotations (`requiredExt`, `acceptanceWindow`).
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "An entry in the supportedTypes list. SHORTHAND: a bare Type URI string. EXPANDED: an object with `type` and optional capability annotations (`requiredExt`, `acceptanceWindow`).",
/// "oneOf": [
/// {
/// "description": "Shorthand form: a bare Type URI string. Equivalent to an object with only the `type` member set.",
/// "type": "string",
/// "format": "uri"
/// },
/// {
/// "description": "Object form: lists a Type URI together with optional capability annotations. An `acceptanceWindow` here is the window the responder applies to documents of this Type URI, and takes precedence over the response-level `acceptanceWindow` for this entry.",
/// "type": "object",
/// "required": [
/// "type"
/// ],
/// "properties": {
/// "acceptanceWindow": {
/// "$ref": "#/definitions/AcceptanceWindow"
/// },
/// "requiredExt": {
/// "description": "Reverse-DNS `ext` namespaces this responder requires on inbound documents of this Type URI as a matter of local policy (SPEC.md §4.5.1, §7.2). A producer that does not populate every listed namespace will receive a `malformedRequest` rejection. Optional; reserved-but-recognized in 0.1, RECOMMENDED in future revisions for responders that enforce such policies.",
/// "type": "array",
/// "items": {
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// },
/// "minItems": 1,
/// "uniqueItems": true
/// },
/// "type": {
/// "description": "A bare Type URI (no #request or #response fragment). The responder supports both request and response variants of every entry it lists.",
/// "type": "string",
/// "format": "uri"
/// }
/// },
/// "additionalProperties": false
/// }
/// ]
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(untagged, deny_unknown_fields)]
#[non_exhaustive]
pub enum ResponseSupportedTypesItem {
Uri(::std::string::String),
Object {
#[serde(
rename = "acceptanceWindow",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
acceptance_window: ::std::option::Option<AcceptanceWindow>,
///Reverse-DNS `ext` namespaces this responder requires on inbound documents of this Type URI as a matter of local policy (SPEC.md §4.5.1, §7.2). A producer that does not populate every listed namespace will receive a `malformedRequest` rejection. Optional; reserved-but-recognized in 0.1, RECOMMENDED in future revisions for responders that enforce such policies.
#[serde(
rename = "requiredExt",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
required_ext: ::std::option::Option<Vec<ResponseSupportedTypesItemObjectRequiredExtItem>>,
///A bare Type URI (no #request or #response fragment). The responder supports both request and response variants of every entry it lists.
#[serde(rename = "type")]
type_: ::std::string::String,
},
}
///`ResponseSupportedTypesItemObjectRequiredExtItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ResponseSupportedTypesItemObjectRequiredExtItem(::std::string::String);
impl ::std::ops::Deref for ResponseSupportedTypesItemObjectRequiredExtItem {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ResponseSupportedTypesItemObjectRequiredExtItem>
for ::std::string::String
{
fn from(value: ResponseSupportedTypesItemObjectRequiredExtItem) -> Self {
value.0
}
}
impl ::std::str::FromStr for ResponseSupportedTypesItemObjectRequiredExtItem {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ResponseSupportedTypesItemObjectRequiredExtItem {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String>
for ResponseSupportedTypesItemObjectRequiredExtItem
{
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String>
for ResponseSupportedTypesItemObjectRequiredExtItem
{
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ResponseSupportedTypesItemObjectRequiredExtItem {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct AcceptanceWindow {
clock_skew_seconds: ::std::result::Result<u64, ::std::string::String>,
max_age_seconds: ::std::result::Result<::std::num::NonZeroU64, ::std::string::String>,
}
impl ::std::default::Default for AcceptanceWindow {
fn default() -> Self {
Self {
clock_skew_seconds: Err("no value supplied for clock_skew_seconds".to_string()),
max_age_seconds: Err("no value supplied for max_age_seconds".to_string()),
}
}
}
impl AcceptanceWindow {
pub fn clock_skew_seconds<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<u64>,
T::Error: ::std::fmt::Display,
{
self.clock_skew_seconds = value.try_into().map_err(|e| {
format!("error converting supplied value for clock_skew_seconds: {e}")
});
self
}
pub fn max_age_seconds<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::num::NonZeroU64>,
T::Error: ::std::fmt::Display,
{
self.max_age_seconds = value
.try_into()
.map_err(|e| format!("error converting supplied value for max_age_seconds: {e}"));
self
}
}
impl ::std::convert::TryFrom<AcceptanceWindow> for super::AcceptanceWindow {
type Error = super::error::ConversionError;
fn try_from(
value: AcceptanceWindow,
) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
clock_skew_seconds: value.clock_skew_seconds?,
max_age_seconds: value.max_age_seconds?,
})
}
}
impl ::std::convert::From<super::AcceptanceWindow> for AcceptanceWindow {
fn from(value: super::AcceptanceWindow) -> Self {
Self {
clock_skew_seconds: Ok(value.clock_skew_seconds),
max_age_seconds: Ok(value.max_age_seconds),
}
}
}
#[derive(Clone, Debug)]
pub struct Payload {
patterns: ::std::result::Result<
::std::vec::Vec<super::PayloadPatternsItem>,
::std::string::String,
>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
patterns: Ok(Default::default()),
}
}
}
impl Payload {
pub fn patterns<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::PayloadPatternsItem>>,
T::Error: ::std::fmt::Display,
{
self.patterns = value
.try_into()
.map_err(|e| format!("error converting supplied value for patterns: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
patterns: value.patterns?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
patterns: Ok(value.patterns),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
acceptance_window: ::std::result::Result<
::std::option::Option<super::AcceptanceWindow>,
::std::string::String,
>,
framework_version: ::std::result::Result<
::std::option::Option<super::ResponseFrameworkVersion>,
::std::string::String,
>,
supported_types: ::std::result::Result<
::std::vec::Vec<super::ResponseSupportedTypesItem>,
::std::string::String,
>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
acceptance_window: Ok(Default::default()),
framework_version: Ok(Default::default()),
supported_types: Err("no value supplied for supported_types".to_string()),
}
}
}
impl Response {
pub fn acceptance_window<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::AcceptanceWindow>>,
T::Error: ::std::fmt::Display,
{
self.acceptance_window = value
.try_into()
.map_err(|e| format!("error converting supplied value for acceptance_window: {e}"));
self
}
pub fn framework_version<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::ResponseFrameworkVersion>>,
T::Error: ::std::fmt::Display,
{
self.framework_version = value
.try_into()
.map_err(|e| format!("error converting supplied value for framework_version: {e}"));
self
}
pub fn supported_types<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::vec::Vec<super::ResponseSupportedTypesItem>>,
T::Error: ::std::fmt::Display,
{
self.supported_types = value
.try_into()
.map_err(|e| format!("error converting supplied value for supported_types: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
acceptance_window: value.acceptance_window?,
framework_version: value.framework_version?,
supported_types: value.supported_types?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
acceptance_window: Ok(value.acceptance_window),
framework_version: Ok(value.framework_version),
supported_types: Ok(value.supported_types),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/trust-task-discovery/0.3";
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AcceptanceWindow\": {\n \"additionalProperties\": false,\n \"description\": \"The freshness bounds a responder applies, as a consumer, to the `issuedAt` of a document it receives (SPEC.md §7.2 item 13). A responder refuses a document when now > issuedAt + maxAgeSeconds + clockSkewSeconds, and when issuedAt > now + clockSkewSeconds. It says nothing about `expiresAt`, which is honoured independently (SPEC.md §7.2 item 4). Both members are whole seconds.\",\n \"properties\": {\n \"clockSkewSeconds\": {\n \"description\": \"The clock-skew tolerance, in whole seconds, the responder applies in both directions: added to maxAgeSeconds for a document in its past, and allowed for an `issuedAt` in its future (SPEC.md §4.2, §7.2 item 13). Zero when it applies none.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"maxAgeSeconds\": {\n \"description\": \"The greatest age, in whole seconds, of a document's `issuedAt` at which the responder still accepts the document, before any clock-skew tolerance is applied.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"maxAgeSeconds\",\n \"clockSkewSeconds\"\n ],\n \"title\": \"Acceptance window\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"List of bare Type URIs the responding party supports. Carried in a Trust Task document whose type is https://trusttasks.org/spec/trust-task-discovery/0.3#response. A response-level `acceptanceWindow` is the window the responder applies to every listed Type URI whose entry carries none of its own. Where neither is present for an entry, the discoverer has learnt nothing about that entry's window and MUST NOT read the absence as the absence of a window.\",\n \"properties\": {\n \"acceptanceWindow\": {\n \"$ref\": \"#/$defs/AcceptanceWindow\"\n },\n \"frameworkVersion\": {\n \"description\": \"MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.\",\n \"pattern\": \"^(0|[1-9][0-9]*)\\\\.(0|[1-9][0-9]*)\\\\.(0|[1-9][0-9]*)$\",\n \"type\": \"string\"\n },\n \"supportedTypes\": {\n \"description\": \"Each entry's Type URI MUST match at least one of the request's patterns (if any were supplied). Order is not significant. Duplicates by Type URI are not permitted, regardless of whether the entry is in shorthand or expanded form.\",\n \"items\": {\n \"description\": \"An entry in the supportedTypes list. SHORTHAND: a bare Type URI string. EXPANDED: an object with `type` and optional capability annotations (`requiredExt`, `acceptanceWindow`).\",\n \"oneOf\": [\n {\n \"description\": \"Shorthand form: a bare Type URI string. Equivalent to an object with only the `type` member set.\",\n \"format\": \"uri\",\n \"type\": \"string\"\n },\n {\n \"additionalProperties\": false,\n \"description\": \"Object form: lists a Type URI together with optional capability annotations. An `acceptanceWindow` here is the window the responder applies to documents of this Type URI, and takes precedence over the response-level `acceptanceWindow` for this entry.\",\n \"properties\": {\n \"acceptanceWindow\": {\n \"$ref\": \"#/$defs/AcceptanceWindow\"\n },\n \"requiredExt\": {\n \"description\": \"Reverse-DNS `ext` namespaces this responder requires on inbound documents of this Type URI as a matter of local policy (SPEC.md §4.5.1, §7.2). A producer that does not populate every listed namespace will receive a `malformedRequest` rejection. Optional; reserved-but-recognized in 0.1, RECOMMENDED in future revisions for responders that enforce such policies.\",\n \"items\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\",\n \"type\": \"string\"\n },\n \"minItems\": 1,\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"type\": {\n \"description\": \"A bare Type URI (no #request or #response fragment). The responder supports both request and response variants of every entry it lists.\",\n \"format\": \"uri\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"type\"\n ],\n \"type\": \"object\"\n }\n ]\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"supportedTypes\"\n ],\n \"title\": \"Trust Task Discovery — response payload\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/trust-task-discovery/0.3\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"Request payload for the framework-defined trust-task-discovery exchange. Carries zero or more slug-glob patterns the discoverer wants the responder to filter against. The response payload schema is reachable via $anchor: 'response'.\",\n \"properties\": {\n \"patterns\": {\n \"description\": \"Patterns are ORed: a slug matches the query if at least one pattern matches it. If the array is omitted or empty, the responder MUST treat the query as ['*'] — return every supported task. Bounded at 16 entries as parser hardening (SPEC.md §12.2), not as a capability limit: matching an unbounded pattern list against every published slug is work a responder does on an unauthenticated request, and a discoverer wanting more asks for '*' and filters locally.\",\n \"items\": {\n \"description\": \"Slug-glob pattern. Matches: '*' (every slug); '<prefix>/*' (any slug starting with '<prefix>/' — e.g. 'acl/*' matches 'acl/grant', 'acl/revoke', 'acl/grant/sub'); otherwise an exact slug match. Wildcards anywhere other than as a trailing segment are not interpreted — the only sigils are the trailing '/*' and the bare '*'.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"maxItems\": 16,\n \"type\": \"array\"\n }\n },\n \"title\": \"Trust Task Discovery — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/trust-task-discovery/0.3#response";
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"AcceptanceWindow\": {\n \"additionalProperties\": false,\n \"description\": \"The freshness bounds a responder applies, as a consumer, to the `issuedAt` of a document it receives (SPEC.md §7.2 item 13). A responder refuses a document when now > issuedAt + maxAgeSeconds + clockSkewSeconds, and when issuedAt > now + clockSkewSeconds. It says nothing about `expiresAt`, which is honoured independently (SPEC.md §7.2 item 4). Both members are whole seconds.\",\n \"properties\": {\n \"clockSkewSeconds\": {\n \"description\": \"The clock-skew tolerance, in whole seconds, the responder applies in both directions: added to maxAgeSeconds for a document in its past, and allowed for an `issuedAt` in its future (SPEC.md §4.2, §7.2 item 13). Zero when it applies none.\",\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"maxAgeSeconds\": {\n \"description\": \"The greatest age, in whole seconds, of a document's `issuedAt` at which the responder still accepts the document, before any clock-skew tolerance is applied.\",\n \"minimum\": 1,\n \"type\": \"integer\"\n }\n },\n \"required\": [\n \"maxAgeSeconds\",\n \"clockSkewSeconds\"\n ],\n \"title\": \"Acceptance window\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"description\": \"List of bare Type URIs the responding party supports. Carried in a Trust Task document whose type is https://trusttasks.org/spec/trust-task-discovery/0.3#response. A response-level `acceptanceWindow` is the window the responder applies to every listed Type URI whose entry carries none of its own. Where neither is present for an entry, the discoverer has learnt nothing about that entry's window and MUST NOT read the absence as the absence of a window.\",\n \"properties\": {\n \"acceptanceWindow\": {\n \"$ref\": \"#/$defs/AcceptanceWindow\"\n },\n \"frameworkVersion\": {\n \"description\": \"MAJOR.MINOR.PATCH version of the Trust Tasks framework specification (SPEC.md) the responder targets — three-part, as the framework has been versioned since 0.4.0 (SPEC.md §5.1.1), and exactly the value a Trust Task specification declares as its target framework version. Lets a discoverer reason about compatibility (SPEC.md §5.2) and select the envelope schema a responder's documents are validated against, which is keyed by the full release: a PATCH is never substituted for another. RECOMMENDED. Two-part in trust-task-discovery/0.1, which could not express a PATCH.\",\n \"pattern\": \"^(0|[1-9][0-9]*)\\\\.(0|[1-9][0-9]*)\\\\.(0|[1-9][0-9]*)$\",\n \"type\": \"string\"\n },\n \"supportedTypes\": {\n \"description\": \"Each entry's Type URI MUST match at least one of the request's patterns (if any were supplied). Order is not significant. Duplicates by Type URI are not permitted, regardless of whether the entry is in shorthand or expanded form.\",\n \"items\": {\n \"description\": \"An entry in the supportedTypes list. SHORTHAND: a bare Type URI string. EXPANDED: an object with `type` and optional capability annotations (`requiredExt`, `acceptanceWindow`).\",\n \"oneOf\": [\n {\n \"description\": \"Shorthand form: a bare Type URI string. Equivalent to an object with only the `type` member set.\",\n \"format\": \"uri\",\n \"type\": \"string\"\n },\n {\n \"additionalProperties\": false,\n \"description\": \"Object form: lists a Type URI together with optional capability annotations. An `acceptanceWindow` here is the window the responder applies to documents of this Type URI, and takes precedence over the response-level `acceptanceWindow` for this entry.\",\n \"properties\": {\n \"acceptanceWindow\": {\n \"$ref\": \"#/$defs/AcceptanceWindow\"\n },\n \"requiredExt\": {\n \"description\": \"Reverse-DNS `ext` namespaces this responder requires on inbound documents of this Type URI as a matter of local policy (SPEC.md §4.5.1, §7.2). A producer that does not populate every listed namespace will receive a `malformedRequest` rejection. Optional; reserved-but-recognized in 0.1, RECOMMENDED in future revisions for responders that enforce such policies.\",\n \"items\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\",\n \"type\": \"string\"\n },\n \"minItems\": 1,\n \"type\": \"array\",\n \"uniqueItems\": true\n },\n \"type\": {\n \"description\": \"A bare Type URI (no #request or #response fragment). The responder supports both request and response variants of every entry it lists.\",\n \"format\": \"uri\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"type\"\n ],\n \"type\": \"object\"\n }\n ]\n },\n \"type\": \"array\"\n }\n },\n \"required\": [\n \"supportedTypes\"\n ],\n \"title\": \"Trust Task Discovery — response payload\",\n \"type\": \"object\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[];
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:6e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3\",\n \"issuer\": \"did:web:client.example\",\n \"recipient\": \"did:web:server.example\",\n \"issuedAt\": \"2026-06-20T10:00:00Z\",\n \"payload\": {}\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_2() {
const JSON: &str = "{\n \"id\": \"urn:uuid:7e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3\",\n \"issuer\": \"did:web:client.example\",\n \"recipient\": \"did:web:server.example\",\n \"issuedAt\": \"2026-06-20T10:00:00Z\",\n \"payload\": {\n \"patterns\": [\"acl/*\"]\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn request_example_3() {
const JSON: &str = "{\n \"id\": \"urn:uuid:8e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3\",\n \"issuer\": \"did:web:client.example\",\n \"recipient\": \"did:web:server.example\",\n \"issuedAt\": \"2026-06-20T10:00:00Z\",\n \"payload\": {\n \"patterns\": [\"acl/*\", \"consent/request\"]\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:9e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3#response\",\n \"threadId\": \"urn:uuid:6e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"issuer\": \"did:web:server.example\",\n \"recipient\": \"did:web:client.example\",\n \"issuedAt\": \"2026-06-20T10:00:01Z\",\n \"payload\": {\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/change-role/0.1\",\n \"https://trusttasks.org/spec/acl/grant/0.1\",\n \"https://trusttasks.org/spec/acl/list/0.1\",\n \"https://trusttasks.org/spec/acl/revoke/0.1\",\n \"https://trusttasks.org/spec/acl/show/0.1\"\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
#[test]
fn response_example_2() {
const JSON: &str = "{\n \"id\": \"urn:uuid:ae2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3#response\",\n \"threadId\": \"urn:uuid:7e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"issuer\": \"did:web:server.example\",\n \"recipient\": \"did:web:client.example\",\n \"issuedAt\": \"2026-06-20T10:00:01Z\",\n \"payload\": {\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/change-role/0.1\",\n \"https://trusttasks.org/spec/acl/grant/0.1\",\n \"https://trusttasks.org/spec/acl/list/0.1\",\n \"https://trusttasks.org/spec/acl/revoke/0.1\",\n \"https://trusttasks.org/spec/acl/show/0.1\"\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
#[test]
fn response_example_3() {
const JSON: &str = "{\n \"id\": \"urn:uuid:ce2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3#response\",\n \"threadId\": \"urn:uuid:7e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"issuer\": \"did:web:server.example\",\n \"recipient\": \"did:web:client.example\",\n \"issuedAt\": \"2026-06-20T10:00:01Z\",\n \"payload\": {\n \"frameworkVersion\": \"0.6.0\",\n \"supportedTypes\": [\n {\n \"type\": \"https://trusttasks.org/spec/acl/grant/0.1\",\n \"requiredExt\": [\"vnd.affinidi.webvh\"]\n },\n \"https://trusttasks.org/spec/acl/list/0.1\",\n \"https://trusttasks.org/spec/acl/show/0.1\"\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
#[test]
fn response_example_4() {
const JSON: &str = "{\n \"id\": \"urn:uuid:de2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3#response\",\n \"threadId\": \"urn:uuid:6e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"issuer\": \"did:web:server.example\",\n \"recipient\": \"did:web:client.example\",\n \"issuedAt\": \"2026-06-20T10:00:01Z\",\n \"payload\": {\n \"frameworkVersion\": \"0.6.0\",\n \"acceptanceWindow\": {\n \"maxAgeSeconds\": 600,\n \"clockSkewSeconds\": 60\n },\n \"supportedTypes\": [\n {\n \"type\": \"https://trusttasks.org/spec/acl/grant/0.1\",\n \"acceptanceWindow\": {\n \"maxAgeSeconds\": 120,\n \"clockSkewSeconds\": 30\n }\n },\n \"https://trusttasks.org/spec/acl/list/0.1\",\n \"https://trusttasks.org/spec/acl/show/0.1\"\n ]\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
#[test]
fn response_example_5() {
const JSON: &str = "{\n \"id\": \"urn:uuid:be2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"type\": \"https://trusttasks.org/spec/trust-task-discovery/0.3#response\",\n \"threadId\": \"urn:uuid:8e2c5e2a-1b81-4d3e-9b51-7a3c89e3d1f2\",\n \"issuer\": \"did:web:server.example\",\n \"recipient\": \"did:web:client.example\",\n \"issuedAt\": \"2026-06-20T10:00:01Z\",\n \"payload\": {\n \"supportedTypes\": []\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[(
"Unknown top-level member is rejected (additionalProperties: false).",
"{\n \"__notARealMember__\": true\n}",
)];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
/// Each `"variant": "response"` fixture in
/// `payload.invalid-examples.json` MUST be rejected as a
/// response payload by at least one of: serde deserialization
/// into `Response`, or JSON-Schema validation against the
/// `$anchor: "response"` sub-schema (validate feature).
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_response_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"acceptanceWindow without clockSkewSeconds — both members are required, so a discoverer never has to guess whether an absent tolerance means zero or the framework's typical sixty seconds.",
"{\n \"acceptanceWindow\": {\n \"maxAgeSeconds\": 600\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"acceptanceWindow with a zero maxAgeSeconds — a window no document can be accepted in is not a window, and a producer reading it would re-issue without end.",
"{\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": 60,\n \"maxAgeSeconds\": 0\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"Negative clockSkewSeconds — a tolerance is a width, never a shift, and a negative one would narrow the window below maxAgeSeconds without saying so.",
"{\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": -60,\n \"maxAgeSeconds\": 600\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"Fractional seconds — the window is carried in whole seconds; a fractional value is a different unit someone forgot to convert.",
"{\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": 60,\n \"maxAgeSeconds\": 600.5\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"A duration string instead of seconds — the members are integers, not ISO 8601 durations, so a discoverer does arithmetic rather than parsing.",
"{\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": 60,\n \"maxAgeSeconds\": \"PT10M\"\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"Unknown member inside acceptanceWindow — the object is closed, so a misspelt member (maxAge for maxAgeSeconds) is refused rather than read as an absent one.",
"{\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": 60,\n \"maxAge\": 600,\n \"maxAgeSeconds\": 600\n },\n \"supportedTypes\": [\n \"https://trusttasks.org/spec/acl/grant/0.1\"\n ]\n}",
),
(
"Entry-level acceptanceWindow missing maxAgeSeconds — the per-entry override has the same shape as the response-level member.",
"{\n \"supportedTypes\": [\n {\n \"acceptanceWindow\": {\n \"clockSkewSeconds\": 60\n },\n \"type\": \"https://trusttasks.org/spec/acl/grant/0.1\"\n }\n ]\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Response>(value.clone()).is_ok();
let schema_ok = super::Response::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid response example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}