//! Generated by `trust-tasks-codegen` — do not edit by hand.
//!
//! Spec slug: `trust-task-next-step`. Version: `0.1`.
#[allow(unused_imports)]
use serde::{Deserialize, Serialize};
/// Error types.
pub mod error {
/// Error from a `TryFrom` or `FromStr` implementation.
pub struct ConversionError(::std::borrow::Cow<'static, str>);
impl ::std::error::Error for ConversionError {}
impl ::std::fmt::Display for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Display::fmt(&self.0, f)
}
}
impl ::std::fmt::Debug for ConversionError {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> Result<(), ::std::fmt::Error> {
::std::fmt::Debug::fmt(&self.0, f)
}
}
impl From<&'static str> for ConversionError {
fn from(value: &'static str) -> Self {
Self(value.into())
}
}
impl From<String> for ConversionError {
fn from(value: String) -> Self {
Self(value.into())
}
}
}
///Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "title": "Ext",
/// "description": "Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.",
/// "type": "object",
/// "minProperties": 1,
/// "additionalProperties": true,
/// "propertyNames": {
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
/// }
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(transparent)]
pub struct Ext(pub ::std::collections::HashMap<ExtKey, ::serde_json::Value>);
impl ::std::ops::Deref for Ext {
type Target = ::std::collections::HashMap<ExtKey, ::serde_json::Value>;
fn deref(&self) -> &::std::collections::HashMap<ExtKey, ::serde_json::Value> {
&self.0
}
}
impl ::std::convert::From<Ext> for ::std::collections::HashMap<ExtKey, ::serde_json::Value> {
fn from(value: Ext) -> Self {
value.0
}
}
impl ::std::convert::From<::std::collections::HashMap<ExtKey, ::serde_json::Value>> for Ext {
fn from(value: ::std::collections::HashMap<ExtKey, ::serde_json::Value>) -> Self {
Self(value)
}
}
///`ExtKey`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "string",
/// "pattern": "^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$"
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct ExtKey(::std::string::String);
impl ::std::ops::Deref for ExtKey {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<ExtKey> for ::std::string::String {
fn from(value: ExtKey) -> Self {
value.0
}
}
impl ::std::str::FromStr for ExtKey {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
static PATTERN: ::std::sync::LazyLock<::regress::Regex> =
::std::sync::LazyLock::new(|| {
::regress::Regex::new("^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$").unwrap()
});
if PATTERN.find(value).is_none() {
return Err("doesn't match pattern \"^[a-z][a-z0-9-]*(\\.[a-z0-9-]+)+$\"".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for ExtKey {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for ExtKey {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/**
The recipient-suggested continuation reserved at SPEC.md §8.6: the original task was understood, but cannot complete in isolation, and this names what the recipient party expects in order to proceed.
A next step is neither a success response nor a failure. The originating task is left open — a consumer that means 'no' returns a trust-task-error instead, and one that means 'done' returns the originating specification's #response variant.
This specification declares no response anchor: a producer answers a next step by issuing a document of the expected type, not by responding to this one.*/
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "$id": "https://trusttasks.org/spec/trust-task-next-step/0.1",
/// "title": "Payload",
/// "description": "\nThe recipient-suggested continuation reserved at SPEC.md §8.6: the original task was understood, but cannot complete in isolation, and this names what the recipient party expects in order to proceed.\n\nA next step is neither a success response nor a failure. The originating task is left open — a consumer that means 'no' returns a trust-task-error instead, and one that means 'done' returns the originating specification's #response variant.\n\nThis specification declares no response anchor: a producer answers a next step by issuing a document of the expected type, not by responding to this one.",
/// "type": "object",
/// "required": [
/// "expects"
/// ],
/// "properties": {
/// "continuation": {
/// "description": "What happens once an expected task completes. `resubmit` (the default) means the expected task is a PREREQUISITE and the producer re-issues the originating request to continue — a new document with a fresh id and the same threadId, which SPEC §8.4 distinguishes from a retry, since a retry is bit-for-bit identical and is not what happens here; this matches the established pattern of task-consent/granted, where the requester re-submits once approval lands. `proceed` means the expected task IS the continuation and the originating request is not re-issued, as in an offer answered by a request.",
/// "default": "resubmit",
/// "enum": [
/// "resubmit",
/// "proceed"
/// ],
/// "$comment": "Two values rather than a boolean, because 'resubmit: false' reads as a negation of something the reader has to reconstruct."
/// },
/// "expects": {
/// "description": "The continuations the recipient will accept, in the producer's order of preference where the recipient has one. More than one entry means ALTERNATIVES — satisfying any single entry unblocks the exchange, never all of them. A recipient that needs several things done first names the one it wants next and issues a further next step afterwards; expressing a conjunction here would be a flow definition, which belongs to a ceremony rather than to a single response.",
/// "type": "array",
/// "items": {
/// "type": "object",
/// "required": [
/// "typeUri"
/// ],
/// "properties": {
/// "hint": {
/// "description": "Optional structured data the producer MAY use when composing the expected document — a challenge to echo, an identifier to quote, a presentation definition to satisfy. Its shape is governed by the specification named in typeUri, not by this one. A producer MUST NOT treat a hint as authoritative for any value it can determine itself.",
/// "type": "object"
/// },
/// "reason": {
/// "description": "Human-readable explanation of why this continuation is expected. Non-normative; intended for operator UI and logs.",
/// "type": "string"
/// },
/// "typeUri": {
/// "description": "The Type URI of the Trust Task the recipient expects next, including any #request fragment. A suggestion only: it confers no authorization to perform that task, and the producer applies its own policy before acting (see the specification's Security & Privacy section).",
/// "type": "string",
/// "format": "uri",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
/// },
/// "minItems": 1
/// },
/// "ext": {
/// "$ref": "#/definitions/Ext"
/// },
/// "inResponseTo": {
/// "description": "Identifies the Trust Task document this next step answers. SHOULD be populated, for the reason SPEC §8.2 gives for the identical member on an error response: threadId correlates the exchange only for a party that already saw the request, so a retained next step otherwise names neither the task it interrupted nor the instance.",
/// "type": "object",
/// "required": [
/// "typeUri"
/// ],
/// "properties": {
/// "id": {
/// "description": "The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.",
/// "type": "string",
/// "minLength": 1
/// },
/// "typeUri": {
/// "description": "The Type URI of the document being answered, including any fragment it carried.",
/// "type": "string",
/// "format": "uri",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
/// },
/// "message": {
/// "description": "Human-readable description of why the task cannot complete in isolation. Non-normative. Subject to the same restraint as an error message: it reaches a party that may not be entitled to learn why.",
/// "type": "string"
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct Payload {
///What happens once an expected task completes. `resubmit` (the default) means the expected task is a PREREQUISITE and the producer re-issues the originating request to continue — a new document with a fresh id and the same threadId, which SPEC §8.4 distinguishes from a retry, since a retry is bit-for-bit identical and is not what happens here; this matches the established pattern of task-consent/granted, where the requester re-submits once approval lands. `proceed` means the expected task IS the continuation and the originating request is not re-issued, as in an offer answered by a request.
#[serde(default = "defaults::payload_continuation")]
pub continuation: PayloadContinuation,
///The continuations the recipient will accept, in the producer's order of preference where the recipient has one. More than one entry means ALTERNATIVES — satisfying any single entry unblocks the exchange, never all of them. A recipient that needs several things done first names the one it wants next and issues a further next step afterwards; expressing a conjunction here would be a flow definition, which belongs to a ceremony rather than to a single response.
pub expects: ::std::vec::Vec<PayloadExpectsItem>,
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub ext: ::std::option::Option<Ext>,
#[serde(
rename = "inResponseTo",
default,
skip_serializing_if = "::std::option::Option::is_none"
)]
pub in_response_to: ::std::option::Option<PayloadInResponseTo>,
///Human-readable description of why the task cannot complete in isolation. Non-normative. Subject to the same restraint as an error message: it reaches a party that may not be entitled to learn why.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub message: ::std::option::Option<::std::string::String>,
}
///What happens once an expected task completes. `resubmit` (the default) means the expected task is a PREREQUISITE and the producer re-issues the originating request to continue — a new document with a fresh id and the same threadId, which SPEC §8.4 distinguishes from a retry, since a retry is bit-for-bit identical and is not what happens here; this matches the established pattern of task-consent/granted, where the requester re-submits once approval lands. `proceed` means the expected task IS the continuation and the originating request is not re-issued, as in an offer answered by a request.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "What happens once an expected task completes. `resubmit` (the default) means the expected task is a PREREQUISITE and the producer re-issues the originating request to continue — a new document with a fresh id and the same threadId, which SPEC §8.4 distinguishes from a retry, since a retry is bit-for-bit identical and is not what happens here; this matches the established pattern of task-consent/granted, where the requester re-submits once approval lands. `proceed` means the expected task IS the continuation and the originating request is not re-issued, as in an offer answered by a request.",
/// "default": "resubmit",
/// "enum": [
/// "resubmit",
/// "proceed"
/// ],
/// "$comment": "Two values rather than a boolean, because 'resubmit: false' reads as a negation of something the reader has to reconstruct."
///}
/// ```
/// </details>
#[derive(
::serde::Deserialize,
::serde::Serialize,
Clone,
Copy,
Debug,
Eq,
Hash,
Ord,
PartialEq,
PartialOrd,
)]
pub enum PayloadContinuation {
#[serde(rename = "resubmit")]
Resubmit,
#[serde(rename = "proceed")]
Proceed,
}
impl ::std::fmt::Display for PayloadContinuation {
fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
match *self {
Self::Resubmit => f.write_str("resubmit"),
Self::Proceed => f.write_str("proceed"),
}
}
}
impl ::std::str::FromStr for PayloadContinuation {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
match value {
"resubmit" => Ok(Self::Resubmit),
"proceed" => Ok(Self::Proceed),
_ => Err("invalid value".into()),
}
}
}
impl ::std::convert::TryFrom<&str> for PayloadContinuation {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadContinuation {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadContinuation {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::default::Default for PayloadContinuation {
fn default() -> Self {
PayloadContinuation::Resubmit
}
}
///`PayloadExpectsItem`
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "type": "object",
/// "required": [
/// "typeUri"
/// ],
/// "properties": {
/// "hint": {
/// "description": "Optional structured data the producer MAY use when composing the expected document — a challenge to echo, an identifier to quote, a presentation definition to satisfy. Its shape is governed by the specification named in typeUri, not by this one. A producer MUST NOT treat a hint as authoritative for any value it can determine itself.",
/// "type": "object"
/// },
/// "reason": {
/// "description": "Human-readable explanation of why this continuation is expected. Non-normative; intended for operator UI and logs.",
/// "type": "string"
/// },
/// "typeUri": {
/// "description": "The Type URI of the Trust Task the recipient expects next, including any #request fragment. A suggestion only: it confers no authorization to perform that task, and the producer applies its own policy before acting (see the specification's Security & Privacy section).",
/// "type": "string",
/// "format": "uri",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct PayloadExpectsItem {
///Optional structured data the producer MAY use when composing the expected document — a challenge to echo, an identifier to quote, a presentation definition to satisfy. Its shape is governed by the specification named in typeUri, not by this one. A producer MUST NOT treat a hint as authoritative for any value it can determine itself.
#[serde(default, skip_serializing_if = "::serde_json::Map::is_empty")]
pub hint: ::serde_json::Map<::std::string::String, ::serde_json::Value>,
///Human-readable explanation of why this continuation is expected. Non-normative; intended for operator UI and logs.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub reason: ::std::option::Option<::std::string::String>,
///The Type URI of the Trust Task the recipient expects next, including any #request fragment. A suggestion only: it confers no authorization to perform that task, and the producer applies its own policy before acting (see the specification's Security & Privacy section).
#[serde(rename = "typeUri")]
pub type_uri: ::std::string::String,
}
///Identifies the Trust Task document this next step answers. SHOULD be populated, for the reason SPEC §8.2 gives for the identical member on an error response: threadId correlates the exchange only for a party that already saw the request, so a retained next step otherwise names neither the task it interrupted nor the instance.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "Identifies the Trust Task document this next step answers. SHOULD be populated, for the reason SPEC §8.2 gives for the identical member on an error response: threadId correlates the exchange only for a party that already saw the request, so a retained next step otherwise names neither the task it interrupted nor the instance.",
/// "type": "object",
/// "required": [
/// "typeUri"
/// ],
/// "properties": {
/// "id": {
/// "description": "The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.",
/// "type": "string",
/// "minLength": 1
/// },
/// "typeUri": {
/// "description": "The Type URI of the document being answered, including any fragment it carried.",
/// "type": "string",
/// "format": "uri",
/// "minLength": 1
/// }
/// },
/// "additionalProperties": false
///}
/// ```
/// </details>
#[derive(::serde::Deserialize, ::serde::Serialize, Clone, Debug)]
#[serde(deny_unknown_fields)]
pub struct PayloadInResponseTo {
///The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.
#[serde(default, skip_serializing_if = "::std::option::Option::is_none")]
pub id: ::std::option::Option<PayloadInResponseToId>,
///The Type URI of the document being answered, including any fragment it carried.
#[serde(rename = "typeUri")]
pub type_uri: ::std::string::String,
}
///The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.
///
/// <details><summary>JSON schema</summary>
///
/// ```json
///{
/// "description": "The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.",
/// "type": "string",
/// "minLength": 1
///}
/// ```
/// </details>
#[derive(::serde::Serialize, Clone, Debug, Eq, Hash, Ord, PartialEq, PartialOrd)]
#[serde(transparent)]
pub struct PayloadInResponseToId(::std::string::String);
impl ::std::ops::Deref for PayloadInResponseToId {
type Target = ::std::string::String;
fn deref(&self) -> &::std::string::String {
&self.0
}
}
impl ::std::convert::From<PayloadInResponseToId> for ::std::string::String {
fn from(value: PayloadInResponseToId) -> Self {
value.0
}
}
impl ::std::str::FromStr for PayloadInResponseToId {
type Err = self::error::ConversionError;
fn from_str(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
if value.chars().count() < 1usize {
return Err("shorter than 1 characters".into());
}
Ok(Self(value.to_string()))
}
}
impl ::std::convert::TryFrom<&str> for PayloadInResponseToId {
type Error = self::error::ConversionError;
fn try_from(value: &str) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<&::std::string::String> for PayloadInResponseToId {
type Error = self::error::ConversionError;
fn try_from(
value: &::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl ::std::convert::TryFrom<::std::string::String> for PayloadInResponseToId {
type Error = self::error::ConversionError;
fn try_from(
value: ::std::string::String,
) -> ::std::result::Result<Self, self::error::ConversionError> {
value.parse()
}
}
impl<'de> ::serde::Deserialize<'de> for PayloadInResponseToId {
fn deserialize<D>(deserializer: D) -> ::std::result::Result<Self, D::Error>
where
D: ::serde::Deserializer<'de>,
{
::std::string::String::deserialize(deserializer)?
.parse()
.map_err(|e: self::error::ConversionError| {
<D::Error as ::serde::de::Error>::custom(e.to_string())
})
}
}
/// Generation of default values for serde.
pub mod defaults {
pub(super) fn payload_continuation() -> super::PayloadContinuation {
super::PayloadContinuation::Resubmit
}
}
impl crate::Payload for Payload {
const TYPE_URI: &'static str = "https://trusttasks.org/spec/trust-task-next-step/0.1";
const IS_RECIPIENT_REQUIRED: bool = true;
}
#[cfg(feature = "validate")]
impl crate::validate::ValidatedPayload for Payload {
const SCHEMA_JSON: &'static str = "{\n \"$defs\": {\n \"Ext\": {\n \"additionalProperties\": true,\n \"description\": \"Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a reverse-DNS namespace; structure under each namespace is opaque to the framework.\",\n \"minProperties\": 1,\n \"propertyNames\": {\n \"pattern\": \"^[a-z][a-z0-9-]*(\\\\.[a-z0-9-]+)+$\"\n },\n \"title\": \"Ext\",\n \"type\": \"object\"\n }\n },\n \"$id\": \"https://trusttasks.org/spec/trust-task-next-step/0.1\",\n \"$schema\": \"https://json-schema.org/draft/2020-12/schema\",\n \"additionalProperties\": false,\n \"description\": \"The recipient-suggested continuation reserved at SPEC.md §8.6: the original task was understood, but cannot complete in isolation, and this names what the recipient party expects in order to proceed.\\n\\nA next step is neither a success response nor a failure. The originating task is left open — a consumer that means 'no' returns a trust-task-error instead, and one that means 'done' returns the originating specification's #response variant.\\n\\nThis specification declares no response anchor: a producer answers a next step by issuing a document of the expected type, not by responding to this one.\",\n \"properties\": {\n \"continuation\": {\n \"$comment\": \"Two values rather than a boolean, because 'resubmit: false' reads as a negation of something the reader has to reconstruct.\",\n \"default\": \"resubmit\",\n \"description\": \"What happens once an expected task completes. `resubmit` (the default) means the expected task is a PREREQUISITE and the producer re-issues the originating request to continue — a new document with a fresh id and the same threadId, which SPEC §8.4 distinguishes from a retry, since a retry is bit-for-bit identical and is not what happens here; this matches the established pattern of task-consent/granted, where the requester re-submits once approval lands. `proceed` means the expected task IS the continuation and the originating request is not re-issued, as in an offer answered by a request.\",\n \"enum\": [\n \"resubmit\",\n \"proceed\"\n ]\n },\n \"expects\": {\n \"description\": \"The continuations the recipient will accept, in the producer's order of preference where the recipient has one. More than one entry means ALTERNATIVES — satisfying any single entry unblocks the exchange, never all of them. A recipient that needs several things done first names the one it wants next and issues a further next step afterwards; expressing a conjunction here would be a flow definition, which belongs to a ceremony rather than to a single response.\",\n \"items\": {\n \"additionalProperties\": false,\n \"properties\": {\n \"hint\": {\n \"description\": \"Optional structured data the producer MAY use when composing the expected document — a challenge to echo, an identifier to quote, a presentation definition to satisfy. Its shape is governed by the specification named in typeUri, not by this one. A producer MUST NOT treat a hint as authoritative for any value it can determine itself.\",\n \"type\": \"object\"\n },\n \"reason\": {\n \"description\": \"Human-readable explanation of why this continuation is expected. Non-normative; intended for operator UI and logs.\",\n \"type\": \"string\"\n },\n \"typeUri\": {\n \"description\": \"The Type URI of the Trust Task the recipient expects next, including any #request fragment. A suggestion only: it confers no authorization to perform that task, and the producer applies its own policy before acting (see the specification's Security & Privacy section).\",\n \"format\": \"uri\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"typeUri\"\n ],\n \"type\": \"object\"\n },\n \"minItems\": 1,\n \"type\": \"array\"\n },\n \"ext\": {\n \"$ref\": \"#/$defs/Ext\"\n },\n \"inResponseTo\": {\n \"additionalProperties\": false,\n \"description\": \"Identifies the Trust Task document this next step answers. SHOULD be populated, for the reason SPEC §8.2 gives for the identical member on an error response: threadId correlates the exchange only for a party that already saw the request, so a retained next step otherwise names neither the task it interrupted nor the instance.\",\n \"properties\": {\n \"id\": {\n \"description\": \"The id of the specific document being answered (SPEC §4.3). Globally unique and never reused, so it names one instance where threadId names an exchange.\",\n \"minLength\": 1,\n \"type\": \"string\"\n },\n \"typeUri\": {\n \"description\": \"The Type URI of the document being answered, including any fragment it carried.\",\n \"format\": \"uri\",\n \"minLength\": 1,\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"typeUri\"\n ],\n \"type\": \"object\"\n },\n \"message\": {\n \"description\": \"Human-readable description of why the task cannot complete in isolation. Non-normative. Subject to the same restraint as an error message: it reaches a party that may not be entitled to learn why.\",\n \"type\": \"string\"\n }\n },\n \"required\": [\n \"expects\"\n ],\n \"title\": \"Trust Task Next Step — payload\",\n \"type\": \"object\"\n}\n";
}
#[cfg(test)]
mod conformance {
//! Round-trip tests harvested from the spec's `spec.md`,
//! plus a `rejects_invalid_examples` test for any fixtures
//! in `payload.invalid-examples.json` (validate feature).
/// Each fixture in `payload.invalid-examples.json` MUST be
/// rejected by at least one of: serde deserialization, or
/// JSON-Schema validation under the `validate` feature. The
/// fixture file documents the producer-side bug class that
/// each payload exemplifies; this generated test pins it.
#[cfg(feature = "validate")]
#[test]
fn rejects_invalid_examples() {
use crate::validate::ValidatedPayload;
let fixtures: &[(&str, &str)] = &[
("Empty payload omits the required member `expects`.", "{}"),
(
"`expects` must have at least one entry — a next step that names no continuation says nothing an error response would not say better.",
"{\n \"expects\": []\n}",
),
(
"An `expects` entry omits the required `typeUri`; a reason alone does not name a continuation.",
"{\n \"expects\": [\n {\n \"reason\": \"step up first\"\n }\n ]\n}",
),
(
"`expects` entry carries an unknown member (additionalProperties: false).",
"{\n \"expects\": [\n {\n \"__notARealMember__\": true,\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ]\n}",
),
(
"`expects` must be an array of objects, not an array of bare Type URI strings.",
"{\n \"expects\": [\n \"https://trusttasks.org/spec/auth/step-up/0.1\"\n ]\n}",
),
(
"`continuation` outside the permitted set. Only resubmit and proceed are defined.",
"{\n \"continuation\": \"retry\",\n \"expects\": [\n {\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ]\n}",
),
(
"`inResponseTo` omits the required `typeUri`.",
"{\n \"expects\": [\n {\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ],\n \"inResponseTo\": {\n \"id\": \"urn:uuid:0e9d4c2b-5f81-4d3e-9b51-7a3c89e3d1f2\"\n }\n}",
),
(
"`hint` must be an object; its shape is governed by the specification named in typeUri, but it is an object at this level.",
"{\n \"expects\": [\n {\n \"hint\": \"aal2\",\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ]\n}",
),
(
"Unknown top-level member is rejected (additionalProperties: false).",
"{\n \"__notARealMember__\": true,\n \"expects\": [\n {\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ]\n}",
),
(
"`ext` immediate keys must be reverse-DNS namespaced per SPEC §4.5.1; a bare key is non-conforming.",
"{\n \"expects\": [\n {\n \"typeUri\": \"https://trusttasks.org/spec/auth/step-up/0.1\"\n }\n ],\n \"ext\": {\n \"bareKey\": {\n \"a\": 1\n }\n }\n}",
),
];
for (i, (note, raw)) in fixtures.iter().enumerate() {
let value: serde_json::Value = match serde_json::from_str(raw) {
Ok(v) => v,
Err(_) => continue,
};
let serde_ok = serde_json::from_value::<super::Payload>(value.clone()).is_ok();
let schema_ok = super::Payload::validate_value(&value).is_ok();
assert!(
!(serde_ok && schema_ok),
"invalid-example #{} ({:?}) was accepted by both serde and JSON Schema; \
the fixture's stated failure class is no longer caught:\n{}",
i + 1,
note,
raw
);
}
}
}