Payload class

The executor asks an enrolled approver device to authorize one pending privileged task, presenting the effects it computed by dry-running the real handler against its own prior state. The executor signs this document; the approver renders only what it verifies under that signature.

Constructors

Payload({required String challenge, required String taskType, required DigestMultibase payloadDigest, required PayloadSideEffects sideEffects, required Exposure exposure, required List<Effect> effects, List<String>? consequences, String? subject, required String requester, String? requesterDeviceId, String? origin, String? note, StatePin? statePin, required String approverSet, required int minApprovals, required bool excludeRequester, required String expiresAt, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

approverSet → String
Name of the approver set the policy's requireConsent named.
final
challenge → String
Per-request nonce (≥128 bits entropy) echoed and signed by the matching task-consent/decision. It is also the salt in payloadDigest, so a party that holds this request can re-derive the digest and a party that does not cannot invert it.
final
consequences → List<String>?
Static, human-facing second-order effects declared in the task's specification (SPEC §7.3 item 13). A fallback for handlers with no dry-run — per-task, not per-request, so it can say 'any document change rotates the update keys' but not which keys. Prefer effects.
final
effects → List<Effect>
What executing this task will actually do, computed by dry-running the real handler against the executor's prior state. MAY be empty when the executor has no dry-run for this handler — in which case consequences carries the specification's static fallback text. When BOTH are empty the surface MUST tell the approver the consequences could not be determined, and MUST NOT present the task as though it had none.
final
excludeRequester → bool
When true, requester may not count toward the threshold — so a single compromised device cannot both propose and approve. A surface MUST NOT offer to approve a request whose requester is its own subject when this is set.
final
expiresAt → String
After this instant the pending request lapses and no decision is accepted for it.
final
exposure → Exposure
final
ext → Ext?
final
hashCode → int
The hash code for this object.
no setterinherited
minApprovals → int
Distinct approvals from the set required before the task may execute.
final
note → String?
OPTIONAL requester-authored display text — the one member of this payload whose prose the executor did NOT author, carried verbatim for context ('why I am asking'). EXPLICITLY UNTRUSTED: it is written by the least trusted party in the system and MUST NOT be treated as a statement of the task's effects. A surface that renders it MUST attribute it to requester, MUST present it visually distinct from effects, and MUST NOT let it substitute for, reorder, or obscure them. The executor's signature on this document attests only that the requester supplied this text, never that it is true.
final
origin → String?
OPTIONAL web origin that proposed the task, when it arrived via a relying party. This MUST be the origin the consumer's own runtime attested (e.g. the browser-supplied sender origin) — never a value the proposing page supplied, and never one the relying party could author.
final
payloadDigest → String
The binding between what the approver sees and what executes. Multibase-encoded multihash over the RFC 8785 (JCS) canonicalization of the payload, the task type, and the challenge as salt. The decision echoes it; the executor re-derives it from the payload it is about to run and refuses on mismatch. Salted because an unsalted digest over a low-entropy payload is a confirmation oracle for anyone who observes it in transit.
final
requester → String
DID that submitted the pending task. Shown to the approver, and compared against the approver when excludeRequester is set.
final
requesterDeviceId → String?
OPTIONAL enrolled device the task was submitted from.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sideEffects → PayloadSideEffects
Authoritative SPEC §7.3 item 13 side-effect class of the pending task, derived by the executor from the compiled handler it is about to invoke. NEVER taken from the registry: a registry that decided this would be a consent kill-switch, downgradeable by publishing a new version with a weaker class.
final
statePin → StatePin?
final
subject → String?
OPTIONAL identifier the task acts on — the value at the specification's subjectPath, usually a DID. Absent for subjectless tasks.
final
taskType → String
Type URI of the task awaiting approval. It is bound into payloadDigest: without that binding, two tasks whose payloads canonicalize identically would share a digest, and an approval for a benign task would authorize a destructive one.
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited