specs/policy/evaluate/v0_3/payload
library
Classes
-
Payload
-
Dry-run a policy decision against a synthetic PolicyInput. Returns the policy
decision plus a trace of which policy modules matched and which rules fired. Used
by the policy-editor UI to verify changes before save and by admins to diagnose
unexpected outcomes. 0.3 evaluates against the generalised PolicyInput (any Trust
Task, carrying typeUri + side-effect/exposure classes) and can return the
requireConsent decision.
-
PolicyDecision
-
PolicyDecision
-
PolicyDecisionRequireConsent
-
When decision == "requireConsent", the approver constraint the enforcement point
MUST satisfy — a signed consent decision from the named set, bound to the request's
payloadDigest — before executing.
-
PolicyDecisionStepUp
-
When decision == "requireStepUp", which method to demand.
-
PolicyInput
-
The structured input fed to a policy evaluator before dispatching a task.
Generalised in 0.3 from the vault-flow triad to any Trust Task:
request.typeUri
identifies the task and request.sideEffects / request.exposure carry the
authoritative SPEC §7.3 classifications the evaluator derives from the compiled
handler.
-
PolicyInputConsumer
-
PolicyInputConsumer, generated from its schema.
-
PolicyInputRequest
-
PolicyInputRequest, generated from its schema.
-
PolicyInputRequestExposure
-
Authoritative exposure class (SPEC §7.3 item 14), likewise derived from the
compiled handler.
discloses is the sensitivity of returned data; actsAsSubject
is whether the subject's authority is exercised.
-
Response
-
Policy Evaluate — response payload
Extension Types
-
PolicyDecisionDecision
-
PolicyDecisionDecision is a closed set of string values defined by this
specification's schema.
-
PolicyDecisionMode
-
Vault-flow-specific. When decision == "allow" for a proxy-login/release request,
whether the maintainer should proxy-login or release-for-fill. Default: proxy.
Ignored for other task kinds.
-
PolicyDecisionStepUpMethod
-
PolicyDecisionStepUpMethod is a closed set of string values defined by this
specification's schema.
-
PolicyInputConsumerNetworkClass
-
PolicyInputConsumerNetworkClass is a closed set of string values defined by this
specification's schema.
-
PolicyInputRequestExposureDiscloses
-
PolicyInputRequestExposureDiscloses is a closed set of string values defined by
this specification's schema.
-
PolicyInputRequestSideEffects
-
Authoritative integrity class (SPEC §7.3 item 13). The evaluator MUST derive this
from the compiled handler it is about to invoke, not from the wire — the registry's
declared value is advisory only.
Typedefs
-
ConsumerKind
= Object?
-
Discriminator: is this consumer a user-driven Companion or a headless Service?
-
DigestMultibase
= String
-
A cryptographic digest as a multibase-encoded multihash — the encoding the W3C
Verifiable Credentials Data Model 2.0 defines for
digestMultibase, and the one
did:webvh uses for its SCID and entry hashes. Multihash carries the hash
algorithm in-band, so the value is self-describing and the wire format survives an
algorithm change without a schema revision; multibase does the same for the base
encoding, so a verifier never infers base58 from base64url by context. A bare hex
string or a sha-256:-style prefix hard-codes one algorithm into the wire contract
and is non-conforming here. This definition constrains the encoding only. What
the digest is computed over is stated by each referencing field, because it differs
legitimately: a digest over a JSON document is taken over its RFC 8785 (JCS)
canonicalization, while a digest over an opaque artifact is taken over its bytes. A
field whose input is a JSON document and which does not name a canonicalization is
not reproducible. Restricted to the two multibase headers W3C Controlled
Identifiers 1.0 §2.4 normatively requires — z (base58btc) and u
(base64url-no-pad). CID permits others but states that "interoperability is not
guaranteed between implementations using such values", and a registry whose purpose
is interoperability should not mint digests a conforming verifier may be unable to
read. The alphabets are enforced rather than assumed: base58btc excludes 0, O, I
and l, and an earlier permissive pattern let three published examples carry digests
that were not valid base58 at all. base58btc is RECOMMENDED, for consistency with
did:key and did:webvh.
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.
-
SiteTarget
= Object?
-
A single binding target for a vault entry. Tagged union over the discriminator
kind. A VaultEntry's targets array MAY mix any number of these.