Fires when a scheduled item's availableAt time passes — i.e. an
item written with availableAt in the future has just become
visible on the wire. Carries the item's owner + id so the
listener can refetch it via AtCollection.getOrNull.
Fires leadTime before an item's expiresAt. Useful for
reminder / alarm UIs that need to nudge the user before a record
disappears (the atServer expires items hard at expiresAt, so
once that moment arrives the record is already gone).
Fires when a remote atSign posts a receipt for an item we can
observe. owner + id identify the PARENT item being read (the
thing the receipt is about — not the receipt sub-item itself), so
they match the owner + id of the corresponding CItem.
from is the reader; readAt is the moment the notification was
received (not the moment the reader wrote it).
Event emitted on AtClient.dataEvents whenever a keystore
mutation passes through LocalSecondary's chokepoint methods
(_update / _delete). Subscribers see every change driven by
this client — local app writes AND sync-applied remote changes —
in a single uniform stream.
A keystore record was created or updated. Carries the metadata
constructed from the UpdateVerbBuilder that drove the write so
listeners (e.g. an event-driven expiry timer) can read expiresAt
without re-fetching the record.
This atSign's enrollments, managed through a client that authenticates as
one holding __manage: the roster, the decisions on it, and the passcodes
a new request has to quote.
Represents a local key
Local key are confined to the client(device)/server it is created.
The key does not sync between the local-secondary and the cloud-secondary.
Contains methods to execute verb on local secondary storage using executeVerb
Set AtClientPreference.isLocalStoreRequired to true and other preferences that your app needs.
Delete and Update commands will be synced to the server
Model class representing a namespace permission.
The string representation of the permission is namespace: {ns1: rw, ns2: r}
where read is r and write is w and ns1/ns2 are the namespaces.
The atSign's user-owned root of trust — an ML-DSA-65 signer published at
public:pq_signing_root@<atSign> that anchors the chain vouching for
enrollment signing keys.
Root of the typed-predicate AST. Mint with the operator methods on
PathField (e.g. field.eq(value)); compose with and / or /
not. Pass to Query.wherePath to apply.
Immutable description of one level in a sub-collection tree. Used
with Query.watchWithTree to declare a parent → children → ...
shape that the library will live-orchestrate.
One node in the snapshot returned by Query.watchWithTree. Carries
the parentCItem<T> and the per-sub-collection branches —
each branch keyed by its SubSpec.subName and holding the current
list of children at that level (which are themselves TreeNodes,
recursing all the way down).
One row in the snapshot returned by Query.watchWithSub — a
parent CItem<P> alongside the current list of its children
CItem<C> from a single named sub-collection.
An interface that defines methods for AtKeys that can be written.
It can be implemented by classes that write AtKeys to different sources,
such as file system or keychain.
Comparison operator carried by a CmpPredicate. Stored as a value
(rather than encoded in the subclass) so switch over op stays
exhaustive at evaluation time and indexed-executor pushdown can
pattern-match on it.
Identifies the origin of a SyncRequest. Every sync request is
idempotent — "what to push" is owned by LocalSecondary's
AtSyncQueue, so requests are just "please drain" triggers that
can be coalesced wholesale at end-of-round.
An nskey generation's decapsulation key: the expanded form pqOpen
opens conveyances with — derived from an NskeySeed, held in memory,
never filed and never conveyed.
An nskey generation's seed: the compact form the whole keypair
re-derives from — the ONLY form that may be filed durably or conveyed
to another enrollment.
Adds waitUntilCaughtUp to every SyncService without forcing
existing implementers to add a method to satisfy a new abstract
member. Implemented as an extension (not a method on SyncService
or a mixin) so:
What error says about the connection, or null when it says nothing:
a key that was not found, a value that failed to parse, a privilege the
enrollment lacks all mean the atServer answered, and the classification
for those is AtConnectionState.online, while an error about the caller's
own arguments says nothing at all.
Clears the process-global factory registry so tests can start from
a known empty state. The registry is a static cache on
AtCollection used by registerFactory / setUpFromAtSign; tests
call this in setUp/tearDown to avoid cross-test pollution.
Builds a CmpPredicate with the given parts, bypassing the
PathField operator path. Tests use this to exercise reserved
PredicateOp values that don't yet have a corresponding operator.
Constructs an AtCollection<T> on the EventSource.both path
with both source streams injected: tests drive each path
independently and assert un-deduplicated dual emission.
Constructs an AtCollection<T> with an injected notification
stream — required so tests drive notification events without an
active server connection. Callers supply notifications (typically
a StreamController.broadcast() they own); the produced collection
subscribes to it as if it were the live monitor stream.
The id of an nskey generation — a SHA-256 prefix of its public half, so it
is derivable by anyone holding the key and identical for every party that
uses it.
Opens spec on parentItem using parentColl's context. Test-only
because the production call-site is hidden behind
AtCollection.subCollection — the spec object isn't directly
constructed by app code.
Constructs a sub-collection of parent with an injected
notification stream. Same semantics as
collectionWithInjectedNotifications but for nested collections.
Builds the connection a client uses to reach an atServer: what an
application hands the entry points so that every connection the client
opens - its own, its sync's, its monitor's - travels the way the
application chose.
open was refused, and this device holds nothing for the principal, so
there is no client to hand back: the first open of a principal on a device
must be online.
open was asked to open a keyfile that holds nothing but an enrollment
awaiting approval, so there is no credential to authenticate with yet.
Atsign.resumeEnrollment is the way to pick it up.
An approval whose server-side approve succeeded but whose conveyance
refused the advertised key package (KeyPackageStatus.rejected) — the
enrollment is live and will be unable to decrypt anything, and the
approver can revoke it.
Thrown by work whose owner has stopped: an operation of an AtClient
that has been stopped, or any call on an at_lookup connection its owner
has closed.