specs/device/wipe/v0_2/payload
library
Classes
-
Payload
-
The maintainer issues a wipe to a Companion or Service. The target is expected to
destroy its local cache and (depending on scope) its device-local key material. The
action is best-effort — a compromised device may silently drop the wipe — so the
maintainer additionally revokes ACL access and rotates the device's cache-key
derivation root, so that defence in depth means a non-compliant device is still
neutralised.
-
Response
-
Acknowledgement from the target device. Sent only when the target executes the
wipe; absent if the target was offline or compromised. The maintainer treats the
absence of a response as 'not confirmed' but considers the device neutralised
because of the server-side defence-in-depth.
-
ResponseDiagnostics
-
ResponseDiagnostics, generated from its schema.
Extension Types
-
PayloadScope
-
How aggressively the target should wipe: -
cache — discard the encrypted vault
cache; consumer can re-sync with valid creds. - cacheAndKeys — discard cache +
device-local key material; consumer must re-onboard. - full — cacheAndKeys +
clear all extension/app storage + revoke OS credential-provider registration where
APIs permit.
-
ResponseScope
-
ResponseScope is a closed set of string values defined by this specification's
schema.
Typedefs
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.