Payload class
The executor asks an enrolled approver device to authorize one pending privileged task, presenting the effects it computed by dry-running the real handler against its own prior state. The executor signs this document; the approver renders only what it verifies under that signature.
Constructors
-
Payload({required String challenge, required String taskType, required DigestMultibase payloadDigest, required PayloadSideEffects sideEffects, required Exposure exposure, required List<
Effect> effects, List<String> ? consequences, String? subject, required String requester, String? requesterDeviceId, String? origin, String? note, StatePin? statePin, required String approverSet, required int minApprovals, required bool excludeRequester, required String expiresAt, Ext? ext}) -
const
-
Payload.fromJson(Map<
String, dynamic> json) -
Read this payload from a decoded JSON object.
factory
Properties
- approverSet → String
-
Name of the approver set the policy's
requireConsentnamed.final - challenge → String
-
Per-request nonce (≥128 bits entropy) echoed and signed by the matching
task-consent/decision. It is also the salt in
payloadDigest, so a party that holds this request can re-derive the digest and a party that does not cannot invert it.final -
consequences
→ List<
String> ? -
Static, human-facing second-order effects declared in the task's specification
(SPEC §7.3 item 13). A fallback for handlers with no dry-run — per-task, not
per-request, so it can say 'any document change rotates the update keys' but not
which keys. Prefer
effects.final -
effects
→ List<
Effect> -
What executing this task will actually do, computed by dry-running the real handler
against the executor's prior state. MAY be empty when the executor has no dry-run
for this handler — in which case
consequencescarries the specification's static fallback text. When BOTH are empty the surface MUST tell the approver the consequences could not be determined, and MUST NOT present the task as though it had none.final - excludeRequester → bool
-
When true,
requestermay not count toward the threshold — so a single compromised device cannot both propose and approve. A surface MUST NOT offer to approve a request whoserequesteris its own subject when this is set.final - expiresAt → String
-
After this instant the pending request lapses and no decision is accepted for it.
final
- exposure → Exposure
-
final
- ext → Ext?
-
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- minApprovals → int
-
Distinct approvals from the set required before the task may execute.
final
- note → String?
-
OPTIONAL requester-authored display text — the one member of this payload whose
prose the executor did NOT author, carried verbatim for context ('why I am
asking'). EXPLICITLY UNTRUSTED: it is written by the least trusted party in the
system and MUST NOT be treated as a statement of the task's effects. A surface that
renders it MUST attribute it to
requester, MUST present it visually distinct fromeffects, and MUST NOT let it substitute for, reorder, or obscure them. The executor's signature on this document attests only that the requester supplied this text, never that it is true.final - origin → String?
-
OPTIONAL web origin that proposed the task, when it arrived via a relying party.
This MUST be the origin the consumer's own runtime attested (e.g. the
browser-supplied sender origin) — never a value the proposing page supplied, and
never one the relying party could author.
final
- payloadDigest → String
-
The binding between what the approver sees and what executes. Multibase-encoded
multihash over the RFC 8785 (JCS) canonicalization of the payload, the task type,
and the
challengeas salt. The decision echoes it; the executor re-derives it from the payload it is about to run and refuses on mismatch. Salted because an unsalted digest over a low-entropy payload is a confirmation oracle for anyone who observes it in transit.final - requester → String
-
DID that submitted the pending task. Shown to the approver, and compared against
the approver when
excludeRequesteris set.final - requesterDeviceId → String?
-
OPTIONAL enrolled device the task was submitted from.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- sideEffects → PayloadSideEffects
-
Authoritative SPEC §7.3 item 13 side-effect class of the pending task, derived by
the executor from the compiled handler it is about to invoke. NEVER taken from the
registry: a registry that decided this would be a consent kill-switch,
downgradeable by publishing a new version with a weaker class.
final
- statePin → StatePin?
-
final
- subject → String?
-
OPTIONAL identifier the task acts on — the value at the specification's
subjectPath, usually a DID. Absent for subjectless tasks.final - taskType → String
-
Type URI of the task awaiting approval. It is bound into
payloadDigest: without that binding, two tasks whose payloads canonicalize identically would share a digest, and an approval for a benign task would authorize a destructive one.final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited