AuditEnvelope class
One entry in an append-only audit log. Only eventId/recordedAt/action are
universal; every other field is populated by maintainers that track it.
prevHash/entryHash are present on hash-chained logs (see audit/verify) and
absent otherwise. Principal DIDs are plaintext and MAY be absent when a
right-to-be-forgotten redaction has nulled them after the fact.
Constructors
-
AuditEnvelope({required String eventId, required String recordedAt, required String action, String? outcome, String? actor, String? target, String? contextId, int? schemaVersion, DigestMultibase? prevHash, DigestMultibase? entryHash, Map<
String, dynamic> ? detail, Ext? ext}) -
const
-
AuditEnvelope.fromJson(Map<
String, dynamic> json) -
Read this payload from a decoded JSON object.
factory
Properties
- action → String
-
The operation this entry records — a maintainer-defined action name (e.g.
member.removed,policy.activated). The discriminator fordetail.final - actor → String?
-
DID of the principal that performed the action.
nullwhen a right-to-be-forgotten redaction has removed the plaintext; a maintainer that keeps a keyed hash of the actor for correlation carries it inext, not here.final - contextId → String?
-
Trust context the event occurred in, for a maintainer that partitions its log per
context.
final
-
detail
→ Map<
String, dynamic> ? -
Event-specific payload, keyed by
action. Opaque to the framework; a consumer that does not recognise the action treats it as an unstructured record.final - entryHash → String?
-
Hash-chain commitment over this entry's immutable content. The next entry's
prevHashpoints here. Multibase-encoded multihash over the RFC 8785 (JCS) canonicalization of that content; the canonicalization is what makes the commitment reproducible by a verifier that did not write the entry.final - eventId → String
-
Stable identifier for this event. Also the tie-breaker component of a cursor's
position key.
final
-
ext
→ Map<
String, dynamic> ? -
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- outcome → String?
-
How the operation resolved. Typically
successordenied; a maintainer MAY use others. Absent for events that have no pass/fail sense.final - prevHash → String?
-
Hash-chain link: the
entryHashof the immediately-preceding entry. Present only on chained logs; its integrity is what audit/verify checks. Multibase-encoded multihash over the RFC 8785 (JCS) canonicalization of the predecessor's immutable content — the same derivation asentryHash, so a verifier recomputes both the same way.final - recordedAt → String
-
Wall-clock time the entry was written. The primary ordering key.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- schemaVersion → int?
-
Envelope-shape version at the maintainer, for consumers that need to reason about
wire-shape evolution.
final
- target → String?
-
DID of the principal the action acted upon, when the event has one.
null/absent for events whose target is the maintainer itself. Same redaction semantics asactor.final
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, dynamic> - Serialize to a JSON-encodable map, omitting absent members.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited