pub struct RefusalPayload<'a> {
pub kind: &'a str,
pub reason: &'a str,
pub reason_detail: &'a str,
pub merchant_host: &'a str,
pub requested_base_units: &'a str,
pub permitted_base_units: &'a str,
pub tool_call_id: &'a str,
pub subject: &'a str,
pub timestamp: &'a str,
}Expand description
The payment_refusal field set refusal_payload signs, named at the call site.
Mirrors ReceiptPayload’s reasoning (#2090, INV-W5): a positional
argument list of same-typed &strs invites a silent field swap at the
call site, so every field is named here instead.
Unlike a receipt, a refusal has exactly one schema version — this event kind ships new, with no prior persisted history to keep verifying, so there is no v1/v2 split to carry.
Fields§
§kind: &'a strThe event kind the payload is stored under (always
polyc_proto::kinds::PAYMENT_REFUSAL). Signed so a payload cannot be
re-filed under a different kind, mirroring ReceiptPayload::kind.
reason: &'a strThe stable, machine-readable reason tag (e.g. "over_spend_cap") —
one of the tags crate’s callers mint via an exhaustive match over
polyc_payments::proxy::RejectReason, or "unknown" for a reason
this build has no tag for. Never the free-text Display rendering.
reason_detail: &'a strA non-secret diagnostic detail for the reason — the wrapped error’s
own Display text (e.g. the SSRF-guard host, the mandate failure).
Never signer-key or credential material.
merchant_host: &'a strThe destination host the fetch would have paid, when the reject site had a host to name (empty otherwise).
requested_base_units: &'a strThe base-unit amount the call requested, as a decimal string, for a
reason that carries one (over_spend_cap, over_budget); empty for
every other reason.
permitted_base_units: &'a strThe base-unit amount the cap/budget actually permitted, as a decimal string, for a reason that carries one; empty for every other reason.
tool_call_id: &'a strThe paid_fetch tool-call id the refused attempt answered.
subject: &'a strOpaque principal the refused attempt is attributed to — the same
status ReceiptPayload::subject carries.
timestamp: &'a strDecimal string of the unix-seconds clock value at the moment the
reject site recorded the refusal — the payments sibling field to
ReceiptPayload::timestamp, but unix-seconds rather than RFC3339:
the recording seam already carries the turn’s dispatch-time
now_unix (no fresh wall-clock read needed), so this reuses that
value verbatim rather than reformatting it. Without this, a blocked
row has no time field at all and cannot be placed on a ledger
alongside settled receipts.
Trait Implementations§
Source§impl<'a> Clone for RefusalPayload<'a>
impl<'a> Clone for RefusalPayload<'a>
Source§fn clone(&self) -> RefusalPayload<'a>
fn clone(&self) -> RefusalPayload<'a>
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreimpl<'a> Copy for RefusalPayload<'a>
Auto Trait Implementations§
impl<'a> Freeze for RefusalPayload<'a>
impl<'a> RefUnwindSafe for RefusalPayload<'a>
impl<'a> Send for RefusalPayload<'a>
impl<'a> Sync for RefusalPayload<'a>
impl<'a> Unpin for RefusalPayload<'a>
impl<'a> UnsafeUnpin for RefusalPayload<'a>
impl<'a> UnwindSafe for RefusalPayload<'a>
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more