pub enum AckProvenance {
ThirdParty,
IssuerAsserted,
NoAcknowledgement,
Unrecognized(String),
}Expand description
How the acknowledgement recorded in adapter.ackDigest was obtained.
§Why this member exists
Under a write-only adapter posture there is no read path, so ackDigest
alone cannot tell a reader whether an independent operations layer
acknowledged the write-in or the Issuer authored a minimal acknowledgement
object itself when nothing structured came back. The digest proves a digest
was computed over something. It does not prove who produced the thing. This
member makes the distinction a property of the record instead of a property
of the Issuer’s unpublished manifest.
Classification belongs to the profile. What a deployment then does about an Issuer-asserted acknowledgement – refuse, warn, or record and carry on – is a matter of that deployment’s risk appetite and is deliberately not specified here.
§Why an unrecognised value is preserved rather than rejected
Self::Unrecognized carries the exact string that was on the wire. Two
rules sit next to each other and they are separate requirements:
- The three named values remain distinguishable from each other.
- An unrecognised value is surfaced as unrecognised. It is not read as
Self::ThirdPartyand it is not normalised toSelf::NoAcknowledgement.
The second rule is the one that is easy to get wrong, because the obvious instinct is to fail closed on anything unrecognised. That instinct is correct for an enumeration feeding a pre-action gate and wrong here, and the difference is the cost function underneath it. At a gate, refusing costs availability and the action simply does not happen. This member is a descriptive property of a record that gets read afterwards, often by somebody reconstructing an event months later. Refusing there means refusing the record, and refusing the record destroys the reconstruction the record exists to serve. Once the engagement has already happened, refusal is not the conservative choice.
Normalising to Self::NoAcknowledgement is the same collapse pointing the
other way: it manufactures a positive claim that the operations layer
returned nothing, which is a substantive statement about what happened at the
site and may be false.
So the profile is closed on the producing side and tolerant on the consuming side. A conforming producer MUST emit one of the three named values; a verifier MUST NOT refuse a receipt solely because this member carries something else, and MUST surface it as unrecognised.
§Serialization
Serialize and Deserialize are written by hand rather than derived.
#[serde(other)] would discard the unrecognised string, which fails rule 2:
the value has to stay available to the reader, not merely be distinguishable
as “not one of ours”. Round-tripping is byte-exact, which matters because the
payload is signed over its JCS serialization – a variant that re-serialised
to anything other than the original bytes would invalidate the signature.
Variants§
ThirdParty
An independent operations layer produced the acknowledgement. Wire value
THIRD_PARTY.
Under a write-only posture this remains the Issuer’s claim about a third
party rather than an independently verified fact. The profile does not
name this state CONFIRMED for exactly that reason.
IssuerAsserted
The Issuer authored the acknowledgement object itself. Wire value
ISSUER_ASSERTED.
NoAcknowledgement
No acknowledgement was obtained. Wire value NONE.
Named NoAcknowledgement in Rust rather than None, which would shadow
Option::None at every use site and produce compiler messages that
read as if the option type were involved. The wire string is pinned by
hand and is unaffected.
Unrecognized(String)
A value outside the closed set, preserved exactly as it appeared.
A receipt carrying this is not conforming. It still parses, still validates, and still presents this member to the reader, for the reasons in the type-level documentation.
Implementations§
Source§impl AckProvenance
impl AckProvenance
Sourcepub fn as_wire_str(&self) -> &str
pub fn as_wire_str(&self) -> &str
Returns the wire string for this value.
Sourcepub const fn is_unrecognized(&self) -> bool
pub const fn is_unrecognized(&self) -> bool
Returns true when the value is outside the closed set the profile names.
A verifier that surfaces the acknowledgement-provenance state to a reader uses this rather than comparing against the named variants, so that an unrecognised value cannot be silently folded into one of them.