//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `vtc/website/upload/chunk`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///The chunk's bytes, base64url-encoded without padding (RFC 4648 §5). Bounded at 349526 characters, the unpadded encoding of a 262144-byte chunk. These are bytes of the encrypted bundle, so a chunk read in isolation reveals nothing of the agent's state — but a complete set of chunks is the export, and is to be handled as such.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChunkData",
/// "description": "The chunk's bytes, base64url-encoded without padding (RFC 4648 §5). Bounded at 349526 characters, the unpadded encoding of a 262144-byte chunk. These are bytes of the encrypted bundle, so a chunk read in isolation reveals nothing of the agent's state — but a complete set of chunks is the export, and is to be handled as such.",
/// "type": "string",
/// "maxLength": 349526,
/// "minLength": 2,
/// "pattern": "^[A-Za-z0-9_-]+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ChunkData(::std::string::String);
impl ::std::ops::Deref for ChunkData {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ChunkData> for ::std::string::String {
fn from(value: ChunkData) -> Self {
value.0
}
}
impl ::std::str::FromStr for ChunkData {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() > 349526usize {
return Err("longer than 349526 characters".into());
}
if value.chars().count() < 2usize {
return Err("shorter than 2 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| ::regress::Regex::new("^[A-Za-z0-9_-]+$").unwrap());
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[A-Za-z0-9_-]+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ChunkData {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ChunkData {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ChunkData {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ChunkData {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///Zero-based position of a chunk within its bundle. Valid values are 0 to chunkCount − 1; an index outside that range is refused with chunkOutOfRange rather than validated here, because the bound depends on the bundle.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ChunkIndex",
/// "description": "Zero-based position of a chunk within its bundle. Valid values are 0 to chunkCount − 1; an index outside that range is refused with chunkOutOfRange rather than validated here, because the bound depends on the bundle.",
/// "type": "integer",
/// "maximum": 4095.0,
/// "minimum": 0.0
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ChunkIndex(pub i64);
impl ::std::ops::Deref for ChunkIndex {
type Target = i64;
fn deref(&self) -> &i64 {
&self.0
}
}
impl ::std::convert::From<ChunkIndex> for i64 {
fn from(value: ChunkIndex) -> Self {
value.0
}
}
impl ::std::convert::From<i64> for ChunkIndex {
fn from(value: i64) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ChunkIndex {
type Err = <i64 as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ChunkIndex {
type Error = <i64 as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ChunkIndex {
type Error = <i64 as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ChunkIndex {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
/**
A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.
Multihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.
This definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.
Restricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that "interoperability is not guaranteed between implementations using such values", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.*/
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "DigestMultibase",
/// "description": "\nA cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\n\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\n\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\n\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \"interoperability is not guaranteed between implementations using such values\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.",
/// "examples": [
/// "zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR"
/// ],
/// "type": "string",
/// "minLength": 16,
/// "pattern": "^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct DigestMultibase(::std::string::String);
impl ::std::ops::Deref for DigestMultibase {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<DigestMultibase> for ::std::string::String {
fn from(value: DigestMultibase) -> Self {
value.0
}
}
impl ::std::str::FromStr for DigestMultibase {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 16usize {
return Err("shorter than 16 characters".into());
}
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\"".into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for DigestMultibase {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for DigestMultibase {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "ExpiresAt",
/// "description": "After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.",
/// "type": "string",
/// "format": "date-time"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct ExpiresAt(pub ::chrono::DateTime<::chrono::offset::Utc>);
impl ::std::ops::Deref for ExpiresAt {
type Target = ::chrono::DateTime<::chrono::offset::Utc>;
fn deref(&self) -> &::chrono::DateTime<::chrono::offset::Utc> {
&self.0
}
}
impl ::std::convert::From<ExpiresAt> for ::chrono::DateTime<::chrono::offset::Utc> {
fn from(value: ExpiresAt) -> Self {
value.0
}
}
impl ::std::convert::From<::chrono::DateTime<::chrono::offset::Utc>> for ExpiresAt {
fn from(value: ::chrono::DateTime<::chrono::offset::Utc>) -> Self {
Self(value)
}
}
impl ::std::str::FromStr for ExpiresAt {
type Err = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn from_str(value: &str) -> ::std::result::Result<Self, Self::Err> {
Ok(Self(value.parse()?))
}
}
impl ::std::convert::TryFrom<&str> for ExpiresAt {
type Error = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn try_from(value: &str) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::convert::TryFrom<String> for ExpiresAt {
type Error = <::chrono::DateTime<::chrono::offset::Utc> as ::std::str::FromStr>::Err;
fn try_from(value: String) -> ::std::result::Result<Self, Self::Error> {
value.parse()
}
}
impl ::std::fmt::Display for ExpiresAt {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
self.0.fmt(f)
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
///One chunk of an open upload. The outer document members are owned by the framework — SPEC §6.3.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/vtc/website/upload/chunk/0.1",
/// "title": "Payload",
/// "description": "One chunk of an open upload. The outer document members are owned by the framework — SPEC §6.3.",
/// "type": "object",
/// "required": [
/// "data",
/// "digestMultibase",
/// "index",
/// "uploadId"
/// ],
/// "properties": {
/// "data": {
/// "$ref": "#/definitions/ChunkData"
/// },
/// "digestMultibase": {
/// "$ref": "#/definitions/DigestMultibase"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "index": {
/// "$ref": "#/definitions/ChunkIndex"
/// },
/// "uploadId": {
/// "$ref": "#/definitions/UploadId"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Payload {
pub data: ChunkData,
#[serde(rename = "digestMultibase")]
pub digest_multibase: DigestMultibase,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
pub index: ChunkIndex,
#[serde(rename = "uploadId")]
pub upload_id: UploadId,
}
impl Payload {
pub fn builder() -> builder::Payload {
Default::default()
}
}
///`Response`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Response",
/// "type": "object",
/// "required": [
/// "expiresAt",
/// "index",
/// "remainingCount",
/// "stored",
/// "uploadId"
/// ],
/// "properties": {
/// "expiresAt": {
/// "$ref": "#/definitions/ExpiresAt"
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "index": {
/// "$ref": "#/definitions/ChunkIndex"
/// },
/// "remainingCount": {
/// "description": "Indices still missing after this write.",
/// "type": "integer",
/// "maximum": 4095.0,
/// "minimum": 0.0
/// },
/// "stored": {
/// "description": "Whether this request is what stored the chunk. False means identical bytes were already staged at this index — a success, and why a chunk can be re-sent safely.",
/// "type": "boolean"
/// },
/// "uploadId": {
/// "$ref": "#/definitions/UploadId"
/// }
/// },
/// "additionalProperties": false,
/// "$anchor": "response"
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
#[non_exhaustive]
pub struct Response {
#[serde(rename = "expiresAt")]
pub expires_at: ExpiresAt,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
pub index: ChunkIndex,
///Indices still missing after this write.
#[serde(rename = "remainingCount")]
pub remaining_count: i64,
///Whether this request is what stored the chunk. False means identical bytes were already staged at this index — a success, and why a chunk can be re-sent safely.
pub stored: bool,
#[serde(rename = "uploadId")]
pub upload_id: UploadId,
}
impl Response {
pub fn builder() -> builder::Response {
Default::default()
}
}
///Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "UploadId",
/// "description": "Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.",
/// "type": "string",
/// "pattern": "^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct UploadId(::std::string::String);
impl ::std::ops::Deref for UploadId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<UploadId> for ::std::string::String {
fn from(value: UploadId) -> Self {
value.0
}
}
impl ::std::str::FromStr for UploadId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new(
"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$",
)
.unwrap()
});
if PATTERN.find(value).is_none() {
return Err(
"doesn't match pattern \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\""
.into(),
);
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for UploadId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for UploadId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for UploadId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for UploadId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Types for composing complex structures.
pub mod builder {
#[derive(Clone, Debug)]
pub struct Payload {
data: ::std::result::Result<super::ChunkData, ::std::string::String>,
digest_multibase: ::std::result::Result<super::DigestMultibase, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
index: ::std::result::Result<super::ChunkIndex, ::std::string::String>,
upload_id: ::std::result::Result<super::UploadId, ::std::string::String>,
}
impl ::std::default::Default for Payload {
fn default() -> Self {
Self {
data: Err("no value supplied for data".to_string()),
digest_multibase: Err("no value supplied for digest_multibase".to_string()),
ext: Ok(Default::default()),
index: Err("no value supplied for index".to_string()),
upload_id: Err("no value supplied for upload_id".to_string()),
}
}
}
impl Payload {
pub fn data<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkData>,
T::Error: ::std::fmt::Display,
{
self.data = value
.try_into()
.map_err(|e| format!("error converting supplied value for data: {e}"));
self
}
pub fn digest_multibase<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::DigestMultibase>,
T::Error: ::std::fmt::Display,
{
self.digest_multibase = value
.try_into()
.map_err(|e| format!("error converting supplied value for digest_multibase: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn index<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkIndex>,
T::Error: ::std::fmt::Display,
{
self.index = value
.try_into()
.map_err(|e| format!("error converting supplied value for index: {e}"));
self
}
pub fn upload_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::UploadId>,
T::Error: ::std::fmt::Display,
{
self.upload_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for upload_id: {e}"));
self
}
}
impl ::std::convert::TryFrom<Payload> for super::Payload {
type Error = super::error::ConversionError;
fn try_from(value: Payload) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
data: value.data?,
digest_multibase: value.digest_multibase?,
ext: value.ext?,
index: value.index?,
upload_id: value.upload_id?,
})
}
}
impl ::std::convert::From<super::Payload> for Payload {
fn from(value: super::Payload) -> Self {
Self {
data: Ok(value.data),
digest_multibase: Ok(value.digest_multibase),
ext: Ok(value.ext),
index: Ok(value.index),
upload_id: Ok(value.upload_id),
}
}
}
#[derive(Clone, Debug)]
pub struct Response {
expires_at: ::std::result::Result<super::ExpiresAt, ::std::string::String>,
ext: ::std::result::Result<::std::option::Option<super::Ext>, ::std::string::String>,
index: ::std::result::Result<super::ChunkIndex, ::std::string::String>,
remaining_count: ::std::result::Result<i64, ::std::string::String>,
stored: ::std::result::Result<bool, ::std::string::String>,
upload_id: ::std::result::Result<super::UploadId, ::std::string::String>,
}
impl ::std::default::Default for Response {
fn default() -> Self {
Self {
expires_at: Err("no value supplied for expires_at".to_string()),
ext: Ok(Default::default()),
index: Err("no value supplied for index".to_string()),
remaining_count: Err("no value supplied for remaining_count".to_string()),
stored: Err("no value supplied for stored".to_string()),
upload_id: Err("no value supplied for upload_id".to_string()),
}
}
}
impl Response {
pub fn expires_at<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ExpiresAt>,
T::Error: ::std::fmt::Display,
{
self.expires_at = value
.try_into()
.map_err(|e| format!("error converting supplied value for expires_at: {e}"));
self
}
pub fn ext<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<::std::option::Option<super::Ext>>,
T::Error: ::std::fmt::Display,
{
self.ext = value
.try_into()
.map_err(|e| format!("error converting supplied value for ext: {e}"));
self
}
pub fn index<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::ChunkIndex>,
T::Error: ::std::fmt::Display,
{
self.index = value
.try_into()
.map_err(|e| format!("error converting supplied value for index: {e}"));
self
}
pub fn remaining_count<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<i64>,
T::Error: ::std::fmt::Display,
{
self.remaining_count = value
.try_into()
.map_err(|e| format!("error converting supplied value for remaining_count: {e}"));
self
}
pub fn stored<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<bool>,
T::Error: ::std::fmt::Display,
{
self.stored = value
.try_into()
.map_err(|e| format!("error converting supplied value for stored: {e}"));
self
}
pub fn upload_id<T>(mut self, value: T) -> Self
where
T: ::std::convert::TryInto<super::UploadId>,
T::Error: ::std::fmt::Display,
{
self.upload_id = value
.try_into()
.map_err(|e| format!("error converting supplied value for upload_id: {e}"));
self
}
}
impl ::std::convert::TryFrom<Response> for super::Response {
type Error = super::error::ConversionError;
fn try_from(value: Response) -> ::std::result::Result<Self, super::error::ConversionError> {
Ok(Self {
expires_at: value.expires_at?,
ext: value.ext?,
index: value.index?,
remaining_count: value.remaining_count?,
stored: value.stored?,
upload_id: value.upload_id?,
})
}
}
impl ::std::convert::From<super::Response> for Response {
fn from(value: super::Response) -> Self {
Self {
expires_at: Ok(value.expires_at),
ext: Ok(value.ext),
index: Ok(value.index),
remaining_count: Ok(value.remaining_count),
stored: Ok(value.stored),
upload_id: Ok(value.upload_id),
}
}
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/vtc/website/upload/chunk/0.1";
const IS_PROOF_REQUIRED: bool = true;
const IS_ISSUED_AT_REQUIRED: bool = true;
const MAX_DOCUMENT_BYTES: Option<usize> = Some(360448usize);
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"ChunkData\": {\n \"description\": \"The chunk's bytes, base64url-encoded without padding (RFC 4648 §5). Bounded at 349526 characters, the unpadded encoding of a 262144-byte chunk. These are bytes of the encrypted bundle, so a chunk read in isolation reveals nothing of the agent's state — but a complete set of chunks is the export, and is to be handled as such.\",\n \"maxLength\": 349526,\n \"minLength\": 2,\n \"pattern\": \"^[A-Za-z0-9_-]+$\",\n \"title\": \"ChunkData\",\n \"type\": \"string\"\n },\n \"ChunkIndex\": {\n \"description\": \"Zero-based position of a chunk within its bundle. Valid values are 0 to chunkCount − 1; an index outside that range is refused with chunkOutOfRange rather than validated here, because the bound depends on the bundle.\",\n \"maximum\": 4095,\n \"minimum\": 0,\n \"title\": \"ChunkIndex\",\n \"type\": \"integer\"\n },\n \"DigestMultibase\": {\n \"description\": \"A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\\n\\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\\n\\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\\n\\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \\\"interoperability is not guaranteed between implementations using such values\\\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.\",\n \"examples\": [\n \"zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR\"\n ],\n \"minLength\": 16,\n \"pattern\": \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\",\n \"title\": \"DigestMultibase\",\n \"type\": \"string\"\n },\n \"ExpiresAt\": {\n \"description\": \"After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.\",\n \"format\": \"date-time\",\n \"title\": \"ExpiresAt\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"expiresAt\": {\n \"$ref\": \"#/$defs/ExpiresAt\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"index\": {\n \"$ref\": \"#/$defs/ChunkIndex\"\n },\n \"remainingCount\": {\n \"description\": \"Indices still missing after this write.\",\n \"maximum\": 4095,\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"stored\": {\n \"description\": \"Whether this request is what stored the chunk. False means identical bytes were already staged at this index — a success, and why a chunk can be re-sent safely.\",\n \"type\": \"boolean\"\n },\n \"uploadId\": {\n \"$ref\": \"#/$defs/UploadId\"\n }\n },\n \"required\": [\n \"uploadId\",\n \"index\",\n \"stored\",\n \"remainingCount\",\n \"expiresAt\"\n ],\n \"title\": \"VTC Website — Upload — Chunk — response payload\",\n \"type\": \"object\"\n },\n \"UploadId\": {\n \"description\": \"Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.\",\n \"pattern\": \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\",\n \"title\": \"UploadId\",\n \"type\": \"string\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/vtc/website/upload/chunk/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"One chunk of an open upload. The outer document members are owned by the framework — SPEC §6.3.\",\n \"properties\": {\n \"data\": {\n \"$ref\": \"#/$defs/ChunkData\"\n },\n \"digestMultibase\": {\n \"$ref\": \"#/$defs/DigestMultibase\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"index\": {\n \"$ref\": \"#/$defs/ChunkIndex\"\n },\n \"uploadId\": {\n \"$ref\": \"#/$defs/UploadId\"\n }\n },\n \"required\": [\n \"uploadId\",\n \"index\",\n \"digestMultibase\",\n \"data\"\n ],\n \"title\": \"VTC Website — Upload — Chunk — payload\",\n \"type\": \"object\"\n}\n",
);
}
impl crate::Payload for Response {
const TYPE_URI: &'static str =
"https://trusttasks.org/spec/vtc/website/upload/chunk/0.1#response";
const IS_ISSUED_AT_REQUIRED: bool = true;
const IS_RECIPIENT_REQUIRED: bool = true;
const PAYLOAD_SCHEMA: Option<&'static str> = Some(
"{\n \"$defs\": {\n \"ChunkData\": {\n \"description\": \"The chunk's bytes, base64url-encoded without padding (RFC 4648 §5). Bounded at 349526 characters, the unpadded encoding of a 262144-byte chunk. These are bytes of the encrypted bundle, so a chunk read in isolation reveals nothing of the agent's state — but a complete set of chunks is the export, and is to be handled as such.\",\n \"maxLength\": 349526,\n \"minLength\": 2,\n \"pattern\": \"^[A-Za-z0-9_-]+$\",\n \"title\": \"ChunkData\",\n \"type\": \"string\"\n },\n \"ChunkIndex\": {\n \"description\": \"Zero-based position of a chunk within its bundle. Valid values are 0 to chunkCount − 1; an index outside that range is refused with chunkOutOfRange rather than validated here, because the bound depends on the bundle.\",\n \"maximum\": 4095,\n \"minimum\": 0,\n \"title\": \"ChunkIndex\",\n \"type\": \"integer\"\n },\n \"DigestMultibase\": {\n \"description\": \"A cryptographic digest as a multibase-encoded multihash — the encoding the W3C Verifiable Credentials Data Model 2.0 defines for `digestMultibase`, and the one `did:webvh` uses for its SCID and entry hashes.\\n\\nMultihash carries the hash algorithm in-band, so the value is self-describing and the wire format survives an algorithm change without a schema revision; multibase does the same for the base encoding, so a verifier never infers base58 from base64url by context. A bare hex string or a `sha-256:`-style prefix hard-codes one algorithm into the wire contract and is non-conforming here.\\n\\nThis definition constrains the *encoding only*. What the digest is computed over is stated by each referencing field, because it differs legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS) canonicalization, while a digest over an opaque artifact is taken over its bytes. A field whose input is a JSON document and which does not name a canonicalization is not reproducible.\\n\\nRestricted to the two multibase headers W3C Controlled Identifiers 1.0 §2.4 normatively requires — `z` (base58btc) and `u` (base64url-no-pad). CID permits others but states that \\\"interoperability is not guaranteed between implementations using such values\\\", and a registry whose purpose is interoperability should not mint digests a conforming verifier may be unable to read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I and l, and an earlier permissive pattern let three published examples carry digests that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with `did:key` and `did:webvh`.\",\n \"examples\": [\n \"zQmbWqxBEKC3P8tqsKc98xmWNzrzDtRLMiMPL8wBuTGsMnR\"\n ],\n \"minLength\": 16,\n \"pattern\": \"^(z[1-9A-HJ-NP-Za-km-z]+|u[A-Za-z0-9_-]+)$\",\n \"title\": \"DigestMultibase\",\n \"type\": \"string\"\n },\n \"ExpiresAt\": {\n \"description\": \"After which the bundle is collected: staged bytes discarded, tokens and chunk requests refused. Short by design. For a chunked transfer a recipient may move it later as chunks are exchanged, never past its own ceiling — each chunk response reports the current value.\",\n \"format\": \"date-time\",\n \"title\": \"ExpiresAt\",\n \"type\": \"string\"\n },\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n },\n \"Response\": {\n \"$anchor\": \"response\",\n \"additionalProperties\": false,\n \"properties\": {\n \"expiresAt\": {\n \"$ref\": \"#/$defs/ExpiresAt\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"index\": {\n \"$ref\": \"#/$defs/ChunkIndex\"\n },\n \"remainingCount\": {\n \"description\": \"Indices still missing after this write.\",\n \"maximum\": 4095,\n \"minimum\": 0,\n \"type\": \"integer\"\n },\n \"stored\": {\n \"description\": \"Whether this request is what stored the chunk. False means identical bytes were already staged at this index — a success, and why a chunk can be re-sent safely.\",\n \"type\": \"boolean\"\n },\n \"uploadId\": {\n \"$ref\": \"#/$defs/UploadId\"\n }\n },\n \"required\": [\n \"uploadId\",\n \"index\",\n \"stored\",\n \"remainingCount\",\n \"expiresAt\"\n ],\n \"title\": \"VTC Website — Upload — Chunk — response payload\",\n \"type\": \"object\"\n },\n \"UploadId\": {\n \"description\": \"Handle for one upload across begin, chunk, commit and abort, and — for a bundle — deploy. Recipient-generated and unguessable, which is what lets a reference to somebody else's upload be answered as not-found without confirming it exists. Opaque: a producer quotes what it was given.\",\n \"pattern\": \"^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$\",\n \"title\": \"UploadId\",\n \"type\": \"string\"\n }\n },\n \"$ref\": \"#/$defs/Response\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\"\n}\n",
);
}
impl crate::RequestPayload for Payload {
type Response = Response;
}
/// The extended error codes this specification declares (SPEC §7.3 item 9,
/// §8.5), in declaration order. Empty when it declares none.
pub const ERROR_CODES: &[crate::DeclaredErrorCode] = &[
error_codes::NOT_FOUND,
error_codes::CHUNK_OUT_OF_RANGE,
error_codes::CHUNK_MISMATCH,
error_codes::ALREADY_STORED,
];
/// One constant per extended error code this specification declares
/// (SPEC §7.3 item 9), named for its local part.
///
/// Emit these rather than a string literal: the code is read from the
/// specification, so it cannot name a code the specification never
/// declared.
pub mod error_codes {
/// `vtc/website/upload/chunk:notFound`
///
/// No open upload with this id exists that the caller may write to. Conflates an unknown id, an expired or committed upload, and another administrator's upload.
///
/// Declared `retryable: false`.
pub const NOT_FOUND: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/chunk:notFound",
retryable: false,
};
/// `vtc/website/upload/chunk:chunkOutOfRange`
///
/// `index` is not below the manifest's `chunkCount`.
///
/// Declared `retryable: false`.
pub const CHUNK_OUT_OF_RANGE: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/chunk:chunkOutOfRange",
retryable: false,
};
/// `vtc/website/upload/chunk:chunkMismatch`
///
/// `digestMultibase` differs from the manifest entry for `index`, the decoded `data` does not match it, or its length is wrong for its position (every chunk but the last is exactly `chunkSize`). The chunk is not stored; re-send the right bytes.
///
/// Declared `retryable: false`.
pub const CHUNK_MISMATCH: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/chunk:chunkMismatch",
retryable: false,
};
/// `vtc/website/upload/chunk:alreadyStored`
///
/// Different bytes are already staged at this index. Never returned for an identical re-send, which succeeds with `stored: false`.
///
/// Declared `retryable: false`.
pub const ALREADY_STORED: crate::DeclaredErrorCode = crate::DeclaredErrorCode {
code: "vtc/website/upload/chunk:alreadyStored",
retryable: false,
};
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
#[test]
fn request_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000004\",\n \"type\": \"https://trusttasks.org/spec/vtc/website/upload/chunk/0.1#request\",\n \"issuer\": \"did:example:administrator\",\n \"recipient\": \"did:example:community\",\n \"issuedAt\": \"2026-09-28T10:00:00Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000001ff\",\n \"payload\": {\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\",\n \"index\": 1,\n \"digestMultibase\": \"zQmT5NvUtoM5nWFfrQdVrFtvGfKFmG7AHE8P34isapyhCxX\",\n \"data\": \"PGh0bWw-PC9odG1sPgo\"\n }\n}\n";
let doc: crate::TrustTask<super::Payload> =
serde_json::from_str(JSON).expect("deserialize request example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "request example failed round-trip");
}
#[test]
fn response_example_1() {
const JSON: &str = "{\n \"id\": \"urn:uuid:00000000-0000-4000-8000-000000000005\",\n \"type\": \"https://trusttasks.org/spec/vtc/website/upload/chunk/0.1#response\",\n \"issuer\": \"did:example:community\",\n \"recipient\": \"did:example:administrator\",\n \"issuedAt\": \"2026-09-28T10:05:00Z\",\n \"threadId\": \"urn:uuid:00000000-0000-4000-8000-0000000001ff\",\n \"payload\": {\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\",\n \"index\": 1,\n \"stored\": true,\n \"remainingCount\": 0,\n \"expiresAt\": \"2026-09-28T11:05:00Z\"\n }\n}\n";
let doc: crate::TrustTask<super::Response> =
serde_json::from_str(JSON).expect("deserialize response example");
let rendered = serde_json::to_value(&doc).expect("re-serialize");
let expected: serde_json::Value = serde_json::from_str(JSON).expect("re-parse expected");
assert_eq!(rendered, expected, "response example failed round-trip");
}
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Standard base64 with padding — chunks are unpadded base64url.",
"{\n \"data\": \"PGh0bWw+PC9odG1sPgo=\",\n \"digestMultibase\": \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"index\": 0,\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\"\n}",
),
(
"No restated digest — a chunk sent to the wrong index would survive until reassembly.",
"{\n \"data\": \"PGh0bWw-PC9odG1sPgo\",\n \"index\": 0,\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\"\n}",
),
(
"A negative index.",
"{\n \"data\": \"PGh0bWw-PC9odG1sPgo\",\n \"digestMultibase\": \"zQmRq2ZwqJ3vWJrK1v8R8oPqWXhD4nVb1JmT9pV6uYh3aBc\",\n \"index\": -1,\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
/// Each `"variant": "response"` fixture in
/// `payload.invalid-examples.json` MUST be rejected as a
/// response payload by at least one of: serde deserialization
/// into `Response`, or JSON-Schema validation against the
/// `$anchor: "response"` sub-schema (validate feature).
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_response_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
(
"Response without `stored` — an idempotent re-send and a first write must be distinguishable.",
"{\n \"expiresAt\": \"2026-09-28T11:05:00Z\",\n \"index\": 1,\n \"remainingCount\": 0,\n \"uploadId\": \"8c7b6a59-4837-4261-9f0e-1d2c3b4a5968\"\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Response>(value.clone()).is_ok();
let schema_ok = super::Response::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid response example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}