pub struct SessionLivenessStatement {
pub type_: String,
pub session_ref: String,
pub participant_ref: String,
pub joining_agent: String,
pub nonce_digest: String,
pub challenge_issued_at: String,
pub response_signed_at: String,
}Expand description
Host-signed evidence that a specific join answered a specific challenge, with both endpoints of the window it took.
Fields§
§type_: String§session_ref: Stringsession_id the join belongs to. Must equal the participant
statement’s session_ref; a verifier checks this rather than
trusting the link.
participant_ref: StringArtifact id of the participant envelope this attests. The link that makes the evidence portable: given a participant receipt, a verifier can find the liveness statement, and given this, they can find what it describes.
joining_agent: StringJoining agent’s Ed25519 public key, base64url-no-pad. Duplicated from the participant statement deliberately: it is bound into these signed bytes, so this attestation cannot be re-pointed at a different join by editing the reference alone.
nonce_digest: Stringsha256:<hex> of the nonce, never the nonce itself. The nonce is
single-use liveness material; publishing it in a durable artifact
would hand a replayer the exact string the host was expecting.
A digest still lets the host’s own records be reconciled against this.
challenge_issued_at: StringRFC 3339. When the host minted the nonce.
response_signed_at: StringRFC 3339. The signed_at the joining agent bound into its challenge
response — the agent’s own claim about when it answered.
Implementations§
Source§impl SessionLivenessStatement
impl SessionLivenessStatement
pub fn new( session_ref: impl Into<String>, participant_ref: impl Into<String>, joining_agent: impl Into<String>, nonce: &str, challenge_issued_at: impl Into<String>, response_signed_at: impl Into<String>, ) -> Self
Sourcepub fn interval_seconds(&self) -> Option<i64>
pub fn interval_seconds(&self) -> Option<i64>
The challenge window in seconds: issue to answer.
None when either timestamp will not parse, or when the answer
predates the challenge. A negative interval is not a small window —
it means at least one clock is wrong or one timestamp was fabricated,
and reporting it as a number would launder that into a reassuring
value. The caller must handle None as “cannot be evaluated”.
Sourcepub fn canonical_for_signing(&self) -> String
pub fn canonical_for_signing(&self) -> String
Canonical signing bytes. Same pipe-delimited shape as the other session statements, every field positional so none can be omitted.
Sourcepub fn sign_as_host(
&self,
host_signer: &dyn Signer,
) -> Result<String, SignerError>
pub fn sign_as_host( &self, host_signer: &dyn Signer, ) -> Result<String, SignerError>
Signed by the host, not the joining agent. The host is the party that issued the challenge and observed the answer; the agent cannot attest to when it was asked.
Trait Implementations§
Source§impl Clone for SessionLivenessStatement
impl Clone for SessionLivenessStatement
Source§fn clone(&self) -> SessionLivenessStatement
fn clone(&self) -> SessionLivenessStatement
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SessionLivenessStatement
impl Debug for SessionLivenessStatement
Source§impl<'de> Deserialize<'de> for SessionLivenessStatement
impl<'de> Deserialize<'de> for SessionLivenessStatement
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for SessionLivenessStatement
Source§impl PartialEq for SessionLivenessStatement
impl PartialEq for SessionLivenessStatement
Source§impl Serialize for SessionLivenessStatement
impl Serialize for SessionLivenessStatement
impl StructuralPartialEq for SessionLivenessStatement
Auto Trait Implementations§
impl Freeze for SessionLivenessStatement
impl RefUnwindSafe for SessionLivenessStatement
impl Send for SessionLivenessStatement
impl Sync for SessionLivenessStatement
impl Unpin for SessionLivenessStatement
impl UnsafeUnpin for SessionLivenessStatement
impl UnwindSafe for SessionLivenessStatement
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.