mail4agent_core/lib.rs
1//! The mail4agent mailbox engine: participants, addressing, delivery,
2//! acknowledgement and the storage boundary. No HTTP, no framework -- see
3//! `mail4agent/CLAUDE.md` for this crate's place in the workspace.
4//!
5//! This crate owns the registry (who a participant is, what it may do, and
6//! -- since 2026-09-17 -- which live sessions exist under it) and the mail
7//! operations (send, inbox, ack, message lookup, plus unread counting).
8//! Persistence is a separate task: what lives here is the [`MailStore`]
9//! trait a persistent implementation will satisfy, and [`InMemoryStore`],
10//! the implementation this crate's own tests run against.
11//!
12//! **The rule that defines the mailbox** (`mail4agent/CLAUDE.md`): a sender
13//! is never a field the caller fills in. [`MailboxEngine::authenticate`] is
14//! the only way a [`mail4agent_api::ParticipantId`] (an *account*) enters
15//! the engine from the outside, and [`MailboxEngine::ensure_session`] is the
16//! only way one of its sessions does; every other operation takes an
17//! already-resolved [`mail4agent_api::Address`] as an argument, never one
18//! read out of a request. A session *is* a participant, not a new concept
19//! beside one -- see `MailboxEngine`'s own doc comments on `send`, `inbox`
20//! and `ack` for exactly how it inherits its account's permissions and
21//! reads its account's mail
22//! (`docs/gate4agent/plans/mailbox-service-extraction-and-signed-session-identity-2026-09-16.md`
23//! ยง5e).
24
25mod engine;
26mod store;
27
28pub use engine::{LivenessCheck, MailboxEngine, ParticipantPermissions, SECRET_HEX_LEN};
29pub use store::{
30 InMemoryStore, InsertMessageOutcome, MailStore, ParticipantRecord, ParticipantSummary, RoomRecord, RoomSummary,
31 SecretDigest, SessionRecord, StoreError,
32};
33
34#[cfg(test)]
35mod tests;