pub struct RegisterTimelineOriginRequest {
pub client_operation_id: String,
pub thread: Option<ThreadRef>,
pub run: Option<RecordRef>,
pub origin: Option<TimelineOriginEndorsement>,
pub origin_credential_biscuit: Vec<u8>,
}Expand description
Optional pre-expiry registration of an unchanged origin endorsement. Before the handler, middleware verifies a fresh method-bound Tier-1 proof. The caller must be an enrolled independent device root or active paired_credentials receiver_kind=device, with a persisted enrollment/pairing proof for its account, endpoint and proof key. Its authenticated effective uploader key MUST equal origin.uploader_device_public_key. In the write transaction, recheck its live credential, revocation, exact Thread/Spool writer authority, sharing destination/facet, billing and deletion gates. For a NEW registration, the complete origin chain must be presented, verified, live, unrevoked and unexpired at that transaction; a client timestamp cannot date itself. Under (uploader account, client_operation_id), store registration_digest = SHA-256(UTF8(“heddle-timeline-registration-v1”) || 0x00 || counted(client_operation_id) || counted(spool UUID) || counted(ThreadId) || counted(run ID) || counted(origin_sha256)), where counted is u32be length plus exact bytes, UUIDs are canonical lowercase 36-byte ASCII, and origin_sha256 includes the complete signed endorsement. The presented chain and transport PoP are authorization evidence excluded from this digest. Store the original server transaction timestamp, verified identity, chain binding and full revocation set beside the digest. A different digest for the same operation ID conflicts. An identical retry with a FRESH transport proof returns the original registered_at and digest, even after origin expiry, without re-dating or re-registering; it still checks current uploader, sharing, deletion and billing gates. Revocation of the issued ancestor or any Biscuit block invalidates the registered admission basis immediately. Registration never overrides revocation and never authorizes a later range by itself once the original has been revoked; fresh acceptance is then required.
Fields§
§client_operation_id: StringCanonical UUID.
thread: Option<ThreadRef>Exact Spool and 32-byte Thread identity.
run: Option<RecordRef>Same Spool; run ID syntax above.
origin: Option<TimelineOriginEndorsement>§origin_credential_biscuit: Vec<u8>For offline_derived, required even on a same-digest retry; the stored result can replay after expiry without re-dating it. Empty for server_issued. At most 65536 raw Biscuit::to_vec() bytes, not base64. A NEW registration verifies this chain before recording the binding.
Trait Implementations§
impl Eq for RegisterTimelineOriginRequest
Source§impl Hash for RegisterTimelineOriginRequest
impl Hash for RegisterTimelineOriginRequest
Source§impl Message for RegisterTimelineOriginRequest
impl Message for RegisterTimelineOriginRequest
Source§fn encoded_len(&self) -> usize
fn encoded_len(&self) -> usize
Source§fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
fn encode(&self, buf: &mut impl BufMut) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
fn encode_length_delimited(
&self,
buf: &mut impl BufMut,
) -> Result<(), EncodeError>where
Self: Sized,
Source§fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
fn encode_length_delimited_to_vec(&self) -> Vec<u8> ⓘwhere
Self: Sized,
Source§fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
fn decode_length_delimited(buf: impl Buf) -> Result<Self, DecodeError>where
Self: Default,
Source§fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self. Read moreSource§fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
fn merge_length_delimited(&mut self, buf: impl Buf) -> Result<(), DecodeError>where
Self: Sized,
self.