Download codex-rs/app-server-protocol/src/protocol/v2/user_verification.rs from SaylorTwift/codex: direct link, hf CLI and curl.
- Browser
- Download file 6.65 kB
-
https://huggingface.co/SaylorTwift/codex/resolve/main/codex-rs/app-server-protocol/src/protocol/v2/user_verification.rs
- Command line
-
hf download hf://SaylorTwift/codex/codex-rs/app-server-protocol/src/protocol/v2/user_verification.rs
-
curl -L -o user_verification.rs https://huggingface.co/SaylorTwift/codex/resolve/main/codex-rs/app-server-protocol/src/protocol/v2/user_verification.rs
6.65 kB
| //! Experimental user-verification APIs for trusted UI clients. | |
| //! Native implementation and registration transport are independent of these contracts. | |
| use crate::JsonSchema; | |
| use crate::RequestId; | |
| use crate::TS; | |
| use serde::Deserialize; | |
| use serde::Serialize; | |
| /// A signature over the exact decoded challenge. The verifier validates and consumes it. | |
| pub struct UserVerificationProof { | |
| pub credential_id: String, | |
| /// Unpadded base64url DER ECDSA signature using P-256 and SHA-256. | |
| pub signature: String, | |
| } | |
| impl std::fmt::Debug for UserVerificationProof { | |
| fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result { | |
| formatter | |
| .debug_struct("UserVerificationProof") | |
| .finish_non_exhaustive() | |
| } | |
| } | |
| pub enum UserVerificationUnavailableReason { | |
| CredentialMissing, | |
| BiometricsUnavailable, | |
| ProviderUnavailable, | |
| } | |
| pub enum UserVerificationCancellationReason { | |
| UserCancelled, | |
| Interrupted, | |
| } | |
| pub enum UserVerificationFailureReason { | |
| AuthenticationFailed, | |
| Timeout, | |
| ProviderError, | |
| ServiceError, | |
| } | |
| pub enum UserVerificationInvalidRequestReason { | |
| InvalidParams, | |
| } | |
| /// Closed error categories; native diagnostic payloads must not cross this boundary. | |
| pub enum UserVerificationErrorDetails { | |
| InvalidRequest { | |
| reason: UserVerificationInvalidRequestReason, | |
| }, | |
| Unavailable { | |
| reason: UserVerificationUnavailableReason, | |
| }, | |
| Cancelled { | |
| reason: UserVerificationCancellationReason, | |
| }, | |
| Failed { | |
| reason: UserVerificationFailureReason, | |
| }, | |
| } | |
| /// The error object inside the normal JSON-RPC envelope. | |
| pub struct UserVerificationRpcError { | |
| pub code: i64, | |
| pub message: String, | |
| pub data: UserVerificationErrorDetails, | |
| } | |
| pub struct UserVerificationStatusParams {} | |
| /// Local readiness only; this neither prompts nor queries server registration. | |
| pub struct UserVerificationStatusResponse { | |
| pub credential_id: Option<String>, | |
| pub unavailable_reason: Option<UserVerificationUnavailableReason>, | |
| pub unavailable_message: Option<String>, | |
| } | |
| pub struct UserVerificationEnrollParams {} | |
| /// Public metadata for a created or reused local credential. The caller completes | |
| /// backend registration; this response does not establish server enrollment. | |
| /// Older app-servers omit the metadata fields; callers must check both before registration. | |
| pub struct UserVerificationEnrollResponse { | |
| pub credential_id: String, | |
| // TODO: Make both metadata fields required after the experimental/alpha rollout | |
| // guarantees them on the oldest supported app-server version. | |
| pub algorithm: Option<String>, | |
| /// Unpadded base64url of the SubjectPublicKeyInfo DER encoding. | |
| pub public_key: Option<String>, | |
| } | |
| pub struct UserVerificationDeleteParams {} | |
| pub struct UserVerificationDeleteResponse {} | |
| /// Local signing primitive, independent of any pending elicitation. | |
| pub struct UserVerificationVerifyParams { | |
| /// Unpadded base64url encoding of 1–4096 challenge bytes. | |
| pub challenge: String, | |
| /// Display context already approved by the UI; 1–256 UTF-8 bytes. | |
| pub title: String, | |
| /// Additional display context; at most 4096 UTF-8 bytes. | |
| pub description: String, | |
| } | |
| pub struct UserVerificationVerifyResponse { | |
| pub proof: UserVerificationProof, | |
| } | |
| /// Cancels a native verification RPC issued on this connection, not an elicitation. | |
| /// Use a fresh request ID for each operation and a distinct ID for this cancellation RPC. | |
| pub struct UserVerificationCancelParams { | |
| pub request_id: RequestId, | |
| } | |
| /// Acknowledges the cancellation signal; native work may still be finishing. | |
| /// Unknown or finished requests are a no-op, and completed effects are not rolled back. | |
| pub struct UserVerificationCancelResponse {} | |
| mod tests; | |