Table of Contents

Class CanonicalPayloadBuilder

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Builds deterministic, provider-neutral signing payloads for AsiBackbone governance artifacts.

public static class CanonicalPayloadBuilder
Inheritance
CanonicalPayloadBuilder
Inherited Members

Methods

ForAuditLedgerRecord(AuditLedgerRecord, CanonicalPayloadOptions?)

Builds a canonical payload for a persistence-ready audit ledger record.

public static CanonicalPayload ForAuditLedgerRecord(AuditLedgerRecord record, CanonicalPayloadOptions? options = null)

Parameters

record AuditLedgerRecord
options CanonicalPayloadOptions

Returns

CanonicalPayload

ForCapabilityGrant(CapabilityGrant, CanonicalPayloadOptions?)

Builds a canonical payload for a capability grant grant.

public static CanonicalPayload ForCapabilityGrant(CapabilityGrant grant, CanonicalPayloadOptions? options = null)

Parameters

grant CapabilityGrant

The capability grant grant to canonicalize.

options CanonicalPayloadOptions

Canonicalization options, including the metadata allow-list.

Returns

CanonicalPayload

A deterministic canonical payload for the grant.

Remarks

Every field the grant carries is included, so the resulting hash binds the whole grant rather than a subset of it. A payload that omits a field leaves that field outside the proof while CapabilityGrantValidator still enforces it, which lets a modified value pass validation against a signature computed before the change. Scopes are normalized to a sorted, de-duplicated, ordinal set, so two grants that differ only in scope ordering produce the same hash.

Metadata is the one exception, and deliberately so: it is filtered through AllowsMetadataKey(string), whose allow-list is empty by default. With default options no grant metadata reaches the proof at all, which keeps unbounded and potentially sensitive host data out of hashed payloads. A host that puts security-relevant data in grant metadata has no binding for it until that key is added to the allow-list.

ForDecisionReceipt(IDecisionReceipt, CanonicalPayloadOptions?)

Builds a canonical payload for decision receipt.

public static CanonicalPayload ForDecisionReceipt(IDecisionReceipt receipt, CanonicalPayloadOptions? options = null)

Parameters

receipt IDecisionReceipt
options CanonicalPayloadOptions

Returns

CanonicalPayload

ForDecisionReceiptLifecycleEvent(DecisionReceiptLifecycleEvent, CanonicalPayloadOptions?)

Builds a canonical payload for an decision receipt lifecycle event.

public static CanonicalPayload ForDecisionReceiptLifecycleEvent(DecisionReceiptLifecycleEvent lifecycleEvent, CanonicalPayloadOptions? options = null)

Parameters

lifecycleEvent DecisionReceiptLifecycleEvent
options CanonicalPayloadOptions

Returns

CanonicalPayload

ForGovernanceEmissionEnvelope(GovernanceEmissionEnvelope, CanonicalPayloadOptions?)

Builds a canonical payload for a governance emission envelope.

public static CanonicalPayload ForGovernanceEmissionEnvelope(GovernanceEmissionEnvelope envelope, CanonicalPayloadOptions? options = null)

Parameters

envelope GovernanceEmissionEnvelope
options CanonicalPayloadOptions

Returns

CanonicalPayload

ForGovernanceOutboxEntry(GovernanceOutboxEntry, CanonicalPayloadOptions?)

Builds a canonical payload for a durable outbox entry.

public static CanonicalPayload ForGovernanceOutboxEntry(GovernanceOutboxEntry entry, CanonicalPayloadOptions? options = null)

Parameters

entry GovernanceOutboxEntry
options CanonicalPayloadOptions

Returns

CanonicalPayload