vtc-client 0.16.0

Client SDK for Verifiable Trust Communities (VTC) — auth, members, join, removal, policies
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
//! The community's ACL: the canonical `acl/{list,show,grant,update,change-role,
//! revoke}` tasks, at **0.2** for the reads and the writes that state
//! administrative authority (role-based administration:
//! `docs/05-design-notes/vtc-admin-roles.md`) and at 0.1 for the community-role
//! change and the removal.
//!
//! At 0.2 an entry's `role` is its **administrative role** (`community-admin`,
//! `moderator`, `vetting-lead`, `repo-manager`, `credential-officer`,
//! `auditor`, `approver`, or `member` for none), and every axis — `act`,
//! `capabilities`, `approve`, `approveCapabilities`, `keys` — is stated. The
//! community role travels in `ext["org.openvtc"].communityRole`.
//!
//! Every one of them is a signed Trust Task, sent the way every `cnm access`
//! call goes — over the DIDComm or TSP session when the client holds one
//! ([`VtcClient::connect_tsp`], [`VtcClient::connect_didcomm`]), otherwise
//! signed with a [`HolderKey`] and posted to `POST {base}/trust-tasks`. As for
//! `git-ns/*` ([`crate::git_ns`]): over a session the VTC takes the document
//! only when its proof, its `issuer` and the envelope's sender are the same
//! DID, so `key` must be the session's own identity — a call signed as any
//! other DID is refused here before anything is sent. A refusal reads the
//! same either way — [`VtcError::Refused`] over a session,
//! [`VtcError::Http`]'s body over HTTPS — carrying the `trust-task-error`
//! document as the VTC wrote it.
//!
//! Requests are built from the generated schema and validated against it
//! before they are sent; replies are decoded into the generated `Response`
//! types, so a VTC that answers off-schema is an error here rather than a
//! silently half-read struct.

use chrono::{DateTime, Utc};
use serde::Serialize;
use serde::de::DeserializeOwned;
use serde_json::Value;
use trust_tasks_rs::validate::ValidatedPayload;

use crate::{HolderKey, MAX_DOCUMENT_RESPONSE_BYTES, VtcClient, VtcError, decode_payload};

/// The generated wire types for the family, re-exported so a caller names the
/// reply types without depending on `trust-tasks-rs` itself.
pub use trust_tasks_rs::specs::acl::{
    change_role::v0_1 as change_role, grant::v0_1 as grant, grant::v0_2 as grant_v0_2,
    list::v0_1 as list, list::v0_2 as list_v0_2, revoke::v0_1 as revoke, show::v0_1 as show,
    show::v0_2 as show_v0_2, swap_key::v0_1 as swap_key, update::v0_1 as update,
    update::v0_2 as update_v0_2,
};

/// The Type URI of each task in the family, read off the generated payloads.
pub mod task {
    use trust_tasks_rs::Payload;

    pub const LIST: &str = <super::list::Payload as Payload>::TYPE_URI;
    pub const SHOW: &str = <super::show::Payload as Payload>::TYPE_URI;
    pub const GRANT: &str = <super::grant::Payload as Payload>::TYPE_URI;
    pub const UPDATE: &str = <super::update::Payload as Payload>::TYPE_URI;
    pub const CHANGE_ROLE: &str = <super::change_role::Payload as Payload>::TYPE_URI;
    pub const REVOKE: &str = <super::revoke::Payload as Payload>::TYPE_URI;
    pub const LIST_V0_2: &str = <super::list_v0_2::Payload as Payload>::TYPE_URI;
    pub const SHOW_V0_2: &str = <super::show_v0_2::Payload as Payload>::TYPE_URI;
    pub const GRANT_V0_2: &str = <super::grant_v0_2::Payload as Payload>::TYPE_URI;
    pub const UPDATE_V0_2: &str = <super::update_v0_2::Payload as Payload>::TYPE_URI;
    pub const SWAP_KEY: &str = <super::swap_key::Payload as Payload>::TYPE_URI;
}

/// How long a swap link proof lives: the VTC refuses one longer-lived than
/// fifteen minutes (VTI-CLT-026, short-lived), and the swap is sent at once.
pub const SWAP_LINK_PROOF_TTL_SECS: u64 = 300;

/// `acl/list/0.2` filters. Every member is optional. `resource` (and the
/// unused-at-a-community `context`) need a `direction`: `actingIn`, `subtree`
/// or `any`.
#[derive(Debug, Clone, Default, Serialize)]
#[serde(rename_all = "camelCase")]
pub struct AclListFilterV02 {
    /// An administrative role, or `member` for entries holding none.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub role: Option<String>,
    /// Only entries whose effective capability set includes this capability.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub capability: Option<String>,
    /// A resource qualifier (`git-ns:github.com/acme`), read in `direction`.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub resource: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub direction: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub subject_prefix: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub page_size: Option<u32>,
    /// The previous page's `cursor`, verbatim.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub cursor: Option<String>,
}

/// An `acl/grant/0.2` entry: the administrative authority the subject should
/// hold, every axis stated.
#[derive(Debug, Clone, Default)]
pub struct AclGrantV02 {
    pub subject: String,
    /// The administrative role, or `member` for none.
    pub admin_role: String,
    /// `cap` or `cap@resource` — narrows the role's ceiling to these. `None`
    /// holds the full ceiling (`{"scope": "ceiling"}`); an empty list holds
    /// none (`{"scope": "none"}`).
    pub capabilities: Option<Vec<String>>,
    /// Whether the subject may approve, within its role's approve ceiling.
    /// `false` states `{"scope": "none"}` rather than omitting it.
    pub approve: bool,
    /// Whether the subject acts at all. `false` is the least-privilege
    /// approver's `{"scope": "none"}`.
    pub act: bool,
    /// The community role (`member`, `moderator`, …), when it should differ
    /// from the one the administrative role implies.
    pub community_role: Option<String>,
    pub label: Option<String>,
    pub expires_at: Option<DateTime<Utc>>,
    pub reason: Option<String>,
}

/// An `acl/update/0.2` amendment. `None` leaves a member unchanged.
#[derive(Debug, Clone, Default)]
pub struct AclUpdateV02 {
    pub subject: String,
    /// Replace the capability set: `Some(None)` returns it to the role's full
    /// ceiling, `Some(Some(list))` lists it (empty: none).
    pub capabilities: Option<Option<Vec<String>>>,
    pub approve: Option<bool>,
    pub label: Option<Option<String>>,
    pub expires_at: Option<Option<DateTime<Utc>>>,
    pub reason: Option<String>,
}

/// `cap` / `cap@resource` strings as a 0.2 capability scope.
pub fn capability_scope(caps: Option<&[String]>) -> serde_json::Value {
    match caps {
        None => serde_json::json!({ "scope": "ceiling" }),
        Some([]) => serde_json::json!({ "scope": "none" }),
        Some(list) => serde_json::json!({
            "scope": "listed",
            "grants": list
                .iter()
                .map(|c| match c.split_once('@') {
                    Some((cap, res)) => serde_json::json!({ "capability": cap, "resource": res }),
                    None => serde_json::json!({ "capability": c }),
                })
                .collect::<Vec<_>>(),
        }),
    }
}

fn explicit_scope(on: bool) -> serde_json::Value {
    serde_json::json!({ "scope": if on { "all" } else { "none" } })
}

/// `acl/list/0.1` filters. Every member is optional; an empty filter lists the
/// first page of every entry the caller may see.
#[derive(Debug, Clone, Default, Serialize)]
#[serde(rename_all = "camelCase")]
pub struct AclListFilter {
    #[serde(skip_serializing_if = "Option::is_none")]
    pub role: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub scope: Option<String>,
    /// `acting-in` (the default), `subtree` or `any`.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub direction: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub subject_prefix: Option<String>,
    #[serde(skip_serializing_if = "Option::is_none")]
    pub page_size: Option<u32>,
    /// The previous page's `cursor`, verbatim.
    #[serde(skip_serializing_if = "Option::is_none")]
    pub cursor: Option<String>,
}

/// An `acl/grant/0.1` entry: what the subject should hold.
#[derive(Debug, Clone, Default)]
pub struct AclGrant {
    pub subject: String,
    pub role: String,
    pub scopes: Vec<String>,
    pub label: Option<String>,
    pub expires_at: Option<DateTime<Utc>>,
    pub reason: Option<String>,
}

/// An `acl/update/0.1` amendment. `None` leaves a member unchanged; for
/// `label` and `expires_at`, `Some(None)` clears it — which for the expiry
/// makes the entry permanent.
#[derive(Debug, Clone, Default)]
pub struct AclUpdate {
    pub subject: String,
    pub label: Option<Option<String>>,
    /// The **whole** intended set. A set that drops a scope the entry holds is
    /// refused (`acl/update:narrowingNotPermitted`); use [`VtcClient::acl_revoke`].
    pub scopes: Option<Vec<String>>,
    pub expires_at: Option<Option<DateTime<Utc>>>,
    pub reason: Option<String>,
}

impl VtcClient {
    /// One page of the ACL entries this caller may see. Manage authority.
    pub async fn acl_list(
        &self,
        filter: &AclListFilter,
        key: &HolderKey,
    ) -> Result<list::Response, VtcError> {
        let payload = checked::<list::Payload>(serde_json::to_value(filter).map_err(bad)?)?;
        self.acl_task(task::LIST, payload, key, &[]).await
    }

    /// Every ACL entry this caller may see, following the cursor to the end.
    pub async fn acl_list_all(
        &self,
        filter: &AclListFilter,
        key: &HolderKey,
    ) -> Result<Vec<list::AclEntry>, VtcError> {
        let mut filter = filter.clone();
        let mut out = Vec::new();
        loop {
            let page = self.acl_list(&filter, key).await?;
            out.extend(page.entries);
            match (page.truncated, page.cursor) {
                (true, Some(cursor)) => filter.cursor = Some(cursor),
                // Truncated with no cursor: the VTC cannot page from here. Say
                // so rather than return a partial list that reads as complete.
                (true, None) => {
                    return Err(VtcError::Http {
                        status: 200,
                        body: "acl/list answered a truncated page with no cursor".into(),
                    });
                }
                (false, _) => return Ok(out),
            }
        }
    }

    /// One entry. [`VtcError::Http`] 404 (or the document's `notFound`) when
    /// the subject holds none this caller may see.
    pub async fn acl_show(
        &self,
        subject: &str,
        key: &HolderKey,
    ) -> Result<show::Response, VtcError> {
        let payload = checked::<show::Payload>(serde_json::json!({ "subject": subject }))?;
        self.acl_task(task::SHOW, payload, key, &[]).await
    }

    /// Write the entry `grant.subject` should hold. Conferring administrator
    /// authority needs a passkey gesture bound to this grant, and
    /// community-wide authority another administrator's consent; the refusal
    /// carries the ceremony in its `details`.
    pub async fn acl_grant(
        &self,
        grant: &AclGrant,
        key: &HolderKey,
    ) -> Result<grant::Response, VtcError> {
        let mut entry = serde_json::json!({
            "subject": grant.subject,
            "role": grant.role,
            "scopes": grant.scopes,
        });
        if let Some(label) = &grant.label {
            entry["label"] = serde_json::json!(label);
        }
        if let Some(at) = grant.expires_at {
            entry["expiresAt"] = serde_json::json!(at.to_rfc3339());
        }
        let mut body = serde_json::json!({ "entry": entry });
        if let Some(reason) = &grant.reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<grant::Payload>(body)?;
        self.acl_task(task::GRANT, payload, key, &[]).await
    }

    /// Amend an existing entry's label, scopes or expiry.
    pub async fn acl_update(
        &self,
        update: &AclUpdate,
        key: &HolderKey,
    ) -> Result<update::Response, VtcError> {
        let mut body = serde_json::json!({ "subject": update.subject });
        if let Some(label) = &update.label {
            body["label"] = serde_json::json!(label);
        }
        if let Some(scopes) = &update.scopes {
            body["scopes"] = serde_json::json!(scopes);
        }
        if let Some(at) = &update.expires_at {
            body["expiresAt"] = serde_json::json!(at.map(|t| t.to_rfc3339()));
        }
        if let Some(reason) = &update.reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<update::Payload>(body)?;
        self.acl_task(task::UPDATE, payload, key, update::ERROR_CODES)
            .await
    }

    /// Move `subject` from `from_role` to `to_role`, compare-and-swapped on
    /// `from_role`. A promotion to admin needs a bound passkey gesture.
    pub async fn acl_change_role(
        &self,
        subject: &str,
        from_role: &str,
        to_role: &str,
        reason: Option<&str>,
        key: &HolderKey,
    ) -> Result<change_role::Response, VtcError> {
        let mut body = serde_json::json!({
            "subject": subject,
            "fromRole": from_role,
            "toRole": to_role,
        });
        if let Some(reason) = reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<change_role::Payload>(body)?;
        self.acl_task(task::CHANGE_ROLE, payload, key, &[]).await
    }

    /// Remove `subject`'s entry, or — with `scopes` — only those scopes. The
    /// reply's `entry` is `None` after a removal and the reduced entry after a
    /// reduction.
    pub async fn acl_revoke(
        &self,
        subject: &str,
        scopes: Option<&[String]>,
        reason: Option<&str>,
        key: &HolderKey,
    ) -> Result<revoke::Response, VtcError> {
        let mut body = serde_json::json!({ "subject": subject });
        if let Some(scopes) = scopes {
            body["scopes"] = serde_json::json!(scopes);
        }
        if let Some(reason) = reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<revoke::Payload>(body)?;
        self.acl_task(task::REVOKE, payload, key, revoke::ERROR_CODES)
            .await
    }

    /// One page of the ACL at 0.2 — every entry with every axis stated. Any
    /// administrative role may read it.
    pub async fn acl_list_v0_2(
        &self,
        filter: &AclListFilterV02,
        key: &HolderKey,
    ) -> Result<list_v0_2::Response, VtcError> {
        let payload = checked::<list_v0_2::Payload>(serde_json::to_value(filter).map_err(bad)?)?;
        self.acl_task(task::LIST_V0_2, payload, key, list_v0_2::ERROR_CODES)
            .await
    }

    /// Every ACL entry at 0.2, following the cursor to the end.
    pub async fn acl_list_all_v0_2(
        &self,
        filter: &AclListFilterV02,
        key: &HolderKey,
    ) -> Result<Vec<list_v0_2::AclEntry>, VtcError> {
        let mut filter = filter.clone();
        let mut out = Vec::new();
        loop {
            let page = self.acl_list_v0_2(&filter, key).await?;
            out.extend(page.entries);
            match (page.truncated, page.cursor) {
                (true, Some(cursor)) => filter.cursor = Some(cursor.to_string()),
                (true, None) => {
                    return Err(VtcError::Http {
                        status: 200,
                        body: "acl/list answered a truncated page with no cursor".into(),
                    });
                }
                (false, _) => return Ok(out),
            }
        }
    }

    /// One entry at 0.2; `entry` is `None` when the subject holds none.
    pub async fn acl_show_v0_2(
        &self,
        subject: &str,
        key: &HolderKey,
    ) -> Result<show_v0_2::Response, VtcError> {
        let payload = checked::<show_v0_2::Payload>(serde_json::json!({ "subject": subject }))?;
        self.acl_task(task::SHOW_V0_2, payload, key, &[]).await
    }

    /// Write the entry `grant.subject` should hold, at 0.2. A grant is bounded
    /// by the caller's own entry; widening administrative authority needs a
    /// passkey gesture bound to it, and an authority-conferring capability its
    /// other holders' consent (the refusal or the parked action says so).
    pub async fn acl_grant_v0_2(
        &self,
        grant: &AclGrantV02,
        key: &HolderKey,
    ) -> Result<grant_v0_2::Response, VtcError> {
        let mut entry = serde_json::json!({
            "subject": grant.subject,
            "role": grant.admin_role,
            "act": explicit_scope(grant.act),
            "keys": { "scope": "none" },
            "capabilities": capability_scope(grant.capabilities.as_deref()),
            "approve": explicit_scope(grant.approve),
        });
        if grant.approve {
            entry["approveCapabilities"] = serde_json::json!({ "scope": "ceiling" });
        }
        if let Some(label) = &grant.label {
            entry["label"] = serde_json::json!(label);
        }
        if let Some(at) = grant.expires_at {
            entry["expiresAt"] = serde_json::json!(at.to_rfc3339());
        }
        if let Some(role) = &grant.community_role {
            entry["ext"] = serde_json::json!({ "org.openvtc": { "communityRole": role } });
        }
        let mut body = serde_json::json!({ "entry": entry });
        if let Some(reason) = &grant.reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<grant_v0_2::Payload>(body)?;
        self.acl_task(task::GRANT_V0_2, payload, key, grant_v0_2::ERROR_CODES)
            .await
    }

    /// Amend an existing entry at 0.2: its capabilities, approve scope, label
    /// or expiry. Narrowing is a privilege reduction applied at once.
    pub async fn acl_update_v0_2(
        &self,
        update: &AclUpdateV02,
        key: &HolderKey,
    ) -> Result<update_v0_2::Response, VtcError> {
        let mut body = serde_json::json!({ "subject": update.subject });
        if let Some(caps) = &update.capabilities {
            body["capabilities"] = capability_scope(caps.as_deref());
        }
        if let Some(approve) = update.approve {
            body["approve"] = explicit_scope(approve);
            body["approveCapabilities"] = if approve {
                serde_json::json!({ "scope": "ceiling" })
            } else {
                serde_json::json!({ "scope": "none" })
            };
        }
        if let Some(label) = &update.label {
            body["label"] = serde_json::json!(label);
        }
        if let Some(at) = &update.expires_at {
            body["expiresAt"] = serde_json::json!(at.map(|t| t.to_rfc3339()));
        }
        if let Some(reason) = &update.reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<update_v0_2::Payload>(body)?;
        self.acl_task(task::UPDATE_V0_2, payload, key, update_v0_2::ERROR_CODES)
            .await
    }

    /// Roll `key`'s own ACL entry onto a new key (`acl/swap-key/0.1`,
    /// VTI-CLT-025 – 032): the entry moves to `new_did` with its authority
    /// exactly as it was, and `key`'s DID loses all standing.
    ///
    /// The document is signed by `key` — the entry's current subject, never a
    /// key acting for it — and carries the link proof the VTC requires: a
    /// short-lived VP-JWT signed by the new key and addressed to this VTC,
    /// proving the new key consents and is held. `new_did` must be the
    /// `did:key` of `new_private_key_multibase`.
    ///
    /// The caller persists the new key **before** this returns to anything
    /// that could fail: once the VTC answers, the old key is worthless.
    pub async fn acl_swap_key(
        &self,
        key: &HolderKey,
        new_did: &str,
        new_private_key_multibase: &str,
        reason: Option<&str>,
    ) -> Result<swap_key::Response, VtcError> {
        let seed = vta_sdk::did_key::decode_private_key_multibase(new_private_key_multibase)
            .map_err(|e| VtcError::Signing(format!("the new key does not decode: {e}")))?;
        let signing = ed25519_dalek::SigningKey::from_bytes(&seed);
        let derived = format!(
            "did:key:{}",
            vta_sdk::did_key::ed25519_multibase_pubkey(&signing.verifying_key().to_bytes())
        );
        if derived != new_did {
            return Err(VtcError::Signing(format!(
                "{new_did} is not the did:key of the new private key ({derived})"
            )));
        }
        let now = std::time::SystemTime::now()
            .duration_since(std::time::UNIX_EPOCH)
            .map(|d| d.as_secs())
            .unwrap_or(0);
        let link_proof = vta_sdk::protocols::acl_management::swap::build_swap_presentation(
            &signing,
            new_did,
            &self.vtc_did,
            now,
            SWAP_LINK_PROOF_TTL_SECS,
            None,
        );
        let mut body = serde_json::json!({
            "currentSubject": key.holder_did(),
            "newSubject": new_did,
            "linkProof": link_proof,
        });
        if let Some(reason) = reason {
            body["reason"] = serde_json::json!(reason);
        }
        let payload = checked::<swap_key::Payload>(body)?;
        self.acl_task(task::SWAP_KEY, payload, key, swap_key::ERROR_CODES)
            .await
    }

    /// Sign one `acl/*` document as `key` and send it, over the client's
    /// session when it holds one — `key` must then be the session's identity
    /// — otherwise signed with `key` and posted to the document endpoint.
    /// `declared` is the task's declared error codes, honoured only on the
    /// HTTPS path (a 404 naming one becomes [`VtcError::NotFound`]); a session
    /// refusal is always [`VtcError::Refused`].
    async fn acl_task<R: DeserializeOwned>(
        &self,
        type_uri: &str,
        payload: Value,
        key: &HolderKey,
        declared: &[trust_tasks_rs::DeclaredErrorCode],
    ) -> Result<R, VtcError> {
        #[cfg(feature = "didcomm")]
        if self.documents.is_some() {
            return self
                .acl_over_session(type_uri, payload, key.holder_did())
                .await;
        }
        let doc =
            vta_sdk::trust_task_sign::build_signed_with(type_uri, payload, key, &self.vtc_did)
                .await
                .map_err(|e| VtcError::Signing(e.to_string()))?;
        let reply = self
            .post_document(doc, declared, MAX_DOCUMENT_RESPONSE_BYTES)
            .await?;
        decode_payload(reply, type_uri)
    }

    /// One `acl/*` task over the client's session, attributed to `signer_did`.
    ///
    /// The session signs the document as its own DID and the VTC binds that
    /// proof to the envelope's sender, so a task meant to be signed as any
    /// other DID cannot go this way: it is refused here, before anything is
    /// sent, rather than arrive attributed to the wrong member — the same
    /// guard [`crate::git_ns`] applies to `git-ns/*`.
    #[cfg(feature = "didcomm")]
    async fn acl_over_session<R: DeserializeOwned>(
        &self,
        type_uri: &str,
        payload: Value,
        signer_did: &str,
    ) -> Result<R, VtcError> {
        let (Some(documents), Some(session_did)) = (&self.documents, &self.session_did) else {
            return Err(VtcError::Session("this client holds no session".into()));
        };
        let base = |d: &str| d.split('#').next().unwrap_or(d).to_string();
        if base(signer_did) != base(session_did) {
            return Err(VtcError::Signing(format!(
                "{type_uri} is to be signed as {signer_did}, but this client's session is \
                 {session_did}; over a session the VTC accepts a document only from the DID \
                 that signed it"
            )));
        }
        let reply = documents
            .dispatch_trust_task_document(type_uri, payload, crate::SESSION_TIMEOUT_SECS)
            .await
            .map_err(|e| VtcError::Session(e.to_string()))?;
        let refused = reply
            .get("type")
            .and_then(Value::as_str)
            .is_some_and(|t| t.starts_with("https://trusttasks.org/spec/trust-task-error/"));
        if refused {
            return Err(VtcError::Refused {
                document: reply.to_string(),
            });
        }
        let payload = reply.get("payload").cloned().unwrap_or(Value::Null);
        // Parked for other administrators' approval (VTI-APV-017).
        if let Some(parked) = crate::parked_from_next_step(
            reply
                .get("type")
                .and_then(Value::as_str)
                .unwrap_or_default(),
            &payload,
        ) {
            return Err(parked);
        }
        serde_json::from_value(payload).map_err(|e| VtcError::Http {
            status: 200,
            body: format!("{type_uri} response does not fit its schema: {e}"),
        })
    }
}

/// `payload`, once it validates against `P`'s published schema.
fn checked<P: ValidatedPayload>(payload: serde_json::Value) -> Result<serde_json::Value, VtcError> {
    P::validate_value(&payload).map_err(|e| VtcError::InvalidPayload(e.to_string()))?;
    Ok(payload)
}

fn bad(e: serde_json::Error) -> VtcError {
    VtcError::InvalidPayload(e.to_string())
}

#[cfg(test)]
mod tests {
    use super::*;

    #[test]
    fn a_list_filter_is_the_canonical_payload() {
        let filter = AclListFilter {
            scope: Some("ctx-a".into()),
            direction: Some("subtree".into()),
            page_size: Some(10),
            ..Default::default()
        };
        let v = checked::<list::Payload>(serde_json::to_value(&filter).unwrap()).unwrap();
        assert_eq!(
            v,
            serde_json::json!({ "scope": "ctx-a", "direction": "subtree", "pageSize": 10 })
        );
    }

    #[test]
    fn an_unknown_direction_is_refused_before_sending() {
        let filter = AclListFilter {
            direction: Some("sideways".into()),
            ..Default::default()
        };
        assert!(checked::<list::Payload>(serde_json::to_value(&filter).unwrap()).is_err());
    }

    #[test]
    fn an_empty_scope_reduction_is_refused_before_sending() {
        // `minItems: 1` — an empty list must never reach the VTC, where it
        // would be ambiguous with a full removal.
        let body = serde_json::json!({ "subject": "did:key:z6MkA", "scopes": [] });
        assert!(checked::<revoke::Payload>(body).is_err());
    }

    /// A 0.2 grant states every axis, and the capability strings become
    /// qualified grants.
    #[test]
    fn a_0_2_grant_states_every_axis() {
        let caps = vec![
            "git.repo.manage@git-ns:github.com/acme".to_string(),
            "git.ns.admin@git-ns:github.com/acme".to_string(),
        ];
        let scope = capability_scope(Some(&caps));
        assert_eq!(scope["scope"], "listed");
        assert_eq!(scope["grants"][0]["resource"], "git-ns:github.com/acme");
        assert_eq!(
            capability_scope(None),
            serde_json::json!({"scope": "ceiling"})
        );
        assert_eq!(
            capability_scope(Some(&[])),
            serde_json::json!({"scope": "none"})
        );
        let body = serde_json::json!({ "entry": {
            "subject": "did:key:z6MkA",
            "role": "repo-manager",
            "act": explicit_scope(true),
            "keys": { "scope": "none" },
            "capabilities": scope,
            "approve": explicit_scope(false),
        }});
        assert!(checked::<grant_v0_2::Payload>(body).is_ok());
    }

    #[test]
    fn the_task_uris_are_the_canonical_family() {
        for uri in [
            task::LIST,
            task::SHOW,
            task::GRANT,
            task::UPDATE,
            task::CHANGE_ROLE,
            task::REVOKE,
            task::LIST_V0_2,
            task::SHOW_V0_2,
            task::GRANT_V0_2,
            task::UPDATE_V0_2,
        ] {
            assert!(uri.starts_with("https://trusttasks.org/spec/acl/"), "{uri}");
        }
    }
}