DeviceBinding class

DeviceBinding

Constructors

DeviceBinding({required String deviceId, required String consumerDid, required ConsumerKind? consumerKind, required String displayName, String? platform, DeviceAttestation? attestation, bool? pushCapable, KeyCustody? keyCustody, List<Capability>? capabilities, required String registeredAt, String? lastSeenAt, String? disabledAt, String? wipedAt, Ext? ext})
const
DeviceBinding.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

attestation → DeviceAttestation?
final
capabilities → List<Capability>?
Capability bitset granted to this device (mirrors the ACL-side scope). Returned for inspection; mutated only via acl/change-role or device/disable.
final
consumerDid → String
The long-term VTA-derived key (DID) the device authenticates with. Established via the ACL-swap pattern at registration.
final
consumerKind → DeviceAttestation?
final
deviceId → String
Maintainer-assigned opaque id for this device. Stable across the device's lifetime — never re-used after disable or wipe.
final
disabledAt → String?
Present when the device has been disabled (device/disable). Disabled devices cannot authenticate but their record is retained for audit.
final
displayName → String
Human-readable name (e.g. "Glenn's MacBook — Chrome", "iPhone 17").
final
ext → Ext?
final
hashCode → int
The hash code for this object.
no setterinherited
keyCustody → KeyCustody?
How the device custodies its private key material (tier + algorithms). Maintainer policy input, mirroring attestation — a maintainer MAY apply stricter policy to software-tier devices. See docs/design-notes/mobile-key-custody-profile.md.
final
lastSeenAt → String?
Updated on every device/heartbeat and on any successful auth.
final
platform → String?
Free-form platform descriptor (e.g. "macOS 16 / Chrome 142", "iOS 19.1", "Android 16", "Linux/x86_64"). Producer-supplied at registration; consumer-supplied updates are accepted on heartbeat.
final
pushCapable → bool?
Whether this device has a usable push channel — i.e. it has registered a push token with a push gateway and conveyed the resulting opaque WakeHandle to its VTA via device/set-wake (https://trusttasks.org/binding/push/0.1). Informational visibility for device/list only. The raw platform push token is held ONLY by the gateway; the maintainer/VTA holds the opaque WakeHandle and the VTA-owned trigger allowlist, never the token. Set from the presence of a current WakeHandle for this device.
final
registeredAt → String
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
wipedAt → String?
Present when a wipe has been issued (device/wipe). Distinct from disabledAt — a wiped device is also disabled, but wipe additionally communicates a wipe-cache instruction that the device may or may not have executed (see device/wipe).
final

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited