Payload class

An enrolled approver authorizes (or refuses) one pending privileged task, bound to the exact payload it was shown. The proof on this document — not the transport session that carried it — is the authorization, and it is always made by the approver's own DID. Additive over 0.1: an OPTIONAL evidence member carries an additional factor (a WebAuthn assertion, or a signed step-up approver statement) the executor verifies on top of the proof, and an OPTIONAL actionId links the decision to a Verifiable Trust Community action (vtc/admin/actions/list/0.1). The outer document members (id, type, issuer, recipient, issuedAt, expiresAt, proof) are owned by the framework — SPEC §6.3.

Constructors

Payload({required String challenge, required DigestMultibase payloadDigest, required Decision decision, String? reason, String? actionId, Evidence? evidence, Ext? ext})
const
Payload.fromJson(Map<String, dynamic> json)
Read this payload from a decoded JSON object.
factory

Properties

actionId → String?
OPTIONAL identifier of the Verifiable Trust Community action (vtc/admin/actions/_shared/0.1 ActionId) this decision answers. A locator only: the executor finds the pending request by payloadDigest and checks challenge against it exactly as without this member, and refuses a decision whose actionId names a different action than the one those resolve to.
final
challenge → String
Echoes the challenge of the pending request this decision answers — a task-consent/request's challenge, or the challenge on a VTC action the approver may decide — binding the decision to that one pending request and that one approver. An executor MUST consume the challenge at execution rather than on receipt of this decision: a decision authorizes exactly one execution, and consuming it earlier lets an executor's own retry legitimately replay it.
final
decision → Decision
final
evidence → Object?
final
ext → Map<String, dynamic>?
final
hashCode → int
The hash code for this object.
no setterinherited
payloadDigest → String
Echoes the challenge-salted digest of the task being authorized, in the encoding the pending request carried it. The executor re-derives it from the payload it is about to execute and refuses on mismatch — this is what makes the approved payload the executed payload, cryptographically rather than by convention.
final
reason → String?
OPTIONAL human-facing note, most useful on a deny.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toJson() → Map<String, dynamic>
Serialize to a JSON-encodable map, omitting absent members.
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited