pub struct DraftView {
pub headers: Vec<(String, String)>,
pub body: Option<String>,
pub body_field: Option<String>,
pub other: Vec<(String, String)>,
}Expand description
A staged message, shaped the way a person reads one.
OutboxKind::Publish’s lesson generalises: a message’s reviewable
object is the message, not the JSON carrying it. A review surface that
prints {"body_markdown": "Dear Dirk,\n\nThank you…"} asks the reviewer to
decode escape sequences to find out what would be said in their name — and
“approve without reading” is the exact failure the outbox exists to
prevent, so a draft that is hard to read is a security cost rather than a
cosmetic one. It is also what an editor should open: editing prose inside a
JSON string literal is where a real newline becomes \n, a stray quote
becomes a parse error, and the whole edit is refused for a reason that has
nothing to do with what the person meant to say.
Keyed on well-known argument names, like [headline] and for the same
reason: the store stays tool-agnostic, so a tool nobody anticipated is
still reviewable — its fields land in other rather than vanishing.
Nothing is dropped. Every key of the arguments appears in exactly one
of headers, body or other, and there is a test on that, because a
field the reviewer cannot see is a field they approved without reading.
That is the whole difference between reshaping a draft and summarising it.
Fields§
§headers: Vec<(String, String)>Addressing and the other short scalars, in reading order.
body: Option<String>The prose, with its real newlines.
body_field: Option<String>Which argument the prose came from, so an edit writes it back to the same key rather than guessing a second time.
other: Vec<(String, String)>Everything else, unshaped — shown after the body, never hidden.