Skip to main content

RoomMessageBody

Enum RoomMessageBody 

Source
pub enum RoomMessageBody {
    Public {
        content_type: u32,
        content_version: u32,
        data: Vec<u8>,
    },
    Private {
        content_type: u32,
        content_version: u32,
        ciphertext: Vec<u8>,
        nonce: [u8; 12],
        secret_version: SecretVersion,
    },
}
Expand description

Message body that can be either public or private (encrypted).

Content is opaque to the contract - interpretation happens client-side. This design enables adding new content types without contract redeployment.

§Content Types

  • content_type = 1: Text message (TextContentV1)
  • content_type = 2: Action on another message (ActionContentV1)
  • content_type = 3: Reply to another message (ReplyContentV1)
  • content_type = 4: Room event like join/leave (EventContentV1)
    • Allowed as Public even in private rooms (contains no sensitive content)
    • Old clients display as “[Unsupported message type 4.1 - please upgrade]”
  • Future types can be added without contract changes

§Extensibility

  • New content types: Just use a new content_type number
  • New action types: Just use a new action_type number within ActionContentV1
  • New fields: Add to content structs (old clients ignore unknown fields)
  • Breaking changes: Bump content_version

§Do NOT apply serde_bytes to data / ciphertext

Both are bare Vec<u8>, so like ActionContentV1::payload before freenet/river#443 they serialize as a CBOR array of integers (~2 bytes per byte). That looks like the same easy win, and it is NOT: these fields live inside MessageV1, which verify_struct RE-SERIALIZES to check the signature (AuthorizedMessageV1::verify). Changing their encoding would invalidate the signature of every existing message in every room — unlike ActionContentV1, which is pre-encoded into these opaque bytes and is therefore outside the signed representation.

The #443 fix was safe precisely because it stopped at that boundary. If the on-wire size of message bodies ever needs to shrink, it requires a versioned migration, not a serde attribute.

Variants§

§

Public

Public (unencrypted) message

Fields

§content_type: u32

Content type identifier (see content module for constants)

§content_version: u32

Version of the content format

§data: Vec<u8>

CBOR-encoded content bytes.

Do NOT add serde(with = "serde_bytes") — see the type-level note.

§

Private

Private (encrypted) message

Fields

§content_type: u32

Content type identifier (see content module for constants)

§content_version: u32

Version of the content format

§ciphertext: Vec<u8>

Encrypted CBOR-encoded content.

Do NOT add serde(with = "serde_bytes") — see the type-level note.

§nonce: [u8; 12]

Nonce used for encryption

§secret_version: SecretVersion

Version of the room secret used for encryption

Implementations§

Source§

impl RoomMessageBody

Source

pub fn public(text: String) -> Self

Create a new public text message

Source

pub fn join_event() -> Self

Create a join event message

Source

pub fn public_raw( content_type: u32, content_version: u32, data: Vec<u8>, ) -> Self

Create a new public message with raw content

Source

pub fn private( content_type: u32, content_version: u32, ciphertext: Vec<u8>, nonce: [u8; 12], secret_version: SecretVersion, ) -> Self

Create a new private message

Source

pub fn private_text( ciphertext: Vec<u8>, nonce: [u8; 12], secret_version: SecretVersion, ) -> Self

Create a private text message (convenience method)

Source

pub fn edit(target: MessageId, new_text: String) -> Self

Create an edit action (public)

Source

pub fn delete(target: MessageId) -> Self

Create a delete action (public)

Source

pub fn reaction(target: MessageId, emoji: String) -> Self

Create a reaction action (public)

Source

pub fn remove_reaction(target: MessageId, emoji: String) -> Self

Create a remove reaction action (public)

Source

pub fn reply( text: String, target_message_id: MessageId, target_author_name: String, target_content_preview: String, ) -> Self

Create a public reply message

Source

pub fn private_action( ciphertext: Vec<u8>, nonce: [u8; 12], secret_version: SecretVersion, ) -> Self

Create a private action message (encrypted)

Use this for any action (edit, delete, reaction, remove_reaction) in a private room. The caller should:

  1. Create the ActionContentV1 (e.g., ActionContentV1::edit(target, new_text))
  2. Encode it: action.encode()
  3. Encrypt the bytes with the room secret
  4. Pass the ciphertext here
Source

pub fn is_public(&self) -> bool

Check if this is a public message

Source

pub fn is_private(&self) -> bool

Check if this is a private message

Source

pub fn content_type(&self) -> u32

Get the content type

Source

pub fn content_version(&self) -> u32

Get the content version

Source

pub fn is_action(&self) -> bool

Check if this is an action message (content_type = ACTION)

Source

pub fn is_event(&self) -> bool

Check if this is an event message (content_type = EVENT)

Source

pub fn decode_content(&self) -> Option<DecodedContent>

Decode the content (for public messages only) Returns None for private messages - decrypt first

Source

pub fn target_id(&self) -> Option<MessageId>

Get the target message ID if this is an action

Source

pub fn content_len(&self) -> usize

Get the content length for validation (contract uses this for size limits)

Source

pub fn measure_text(text: &str, encrypted: bool) -> usize

Exact Self::content_len of the body Self::public builds for text — or, with encrypted, of the private body the senders build by AES-256-GCM-sealing the encoded TextContentV1.

Send gates and byte counters MUST use the measure_* functions, not text.len(): the contract validates encoded content bytes (CBOR framing, plus the AEAD tag in private rooms), so a raw-text gate passes messages the contract then silently prunes (freenet/river#430, the “message was lost” reports).

Source

pub fn measure_reply( text: &str, target_message_id: MessageId, target_author_name: &str, target_content_preview: &str, encrypted: bool, ) -> usize

Exact Self::content_len of the body Self::reply builds — or, with encrypted, of the private reply body (encrypted encoded ReplyContentV1). Reply bodies embed the quoted author name and content preview, so their overhead is much larger than plain text.

Source

pub fn measure_edit(target: MessageId, new_text: &str, encrypted: bool) -> usize

Exact Self::content_len of the body Self::edit builds — or, with encrypted, of the private edit body (encrypted encoded ActionContentV1).

Source

pub fn secret_version(&self) -> Option<SecretVersion>

Get the secret version (if private)

Source

pub fn to_string_lossy(&self) -> String

Get a string representation for display purposes

Source

pub fn as_public_string(&self) -> Option<String>

Try to get the public plaintext, returns None if private or not a text message

Trait Implementations§

Source§

impl Clone for RoomMessageBody

Source§

fn clone(&self) -> RoomMessageBody

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for RoomMessageBody

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for RoomMessageBody

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Display for RoomMessageBody

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl PartialEq for RoomMessageBody

Source§

fn eq(&self, other: &RoomMessageBody) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for RoomMessageBody

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for RoomMessageBody

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T> ToString for T
where T: Display + ?Sized,

Source§

fn to_string(&self) -> String

Converts the given value to a String. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.