Class CanonicalPayloadBuilder
Builds deterministic, provider-neutral signing payloads for AsiBackbone governance artifacts.
public static class CanonicalPayloadBuilder
- Inheritance
-
CanonicalPayloadBuilder
- Inherited Members
Methods
ForAuditLedgerRecord(AuditLedgerRecord, CanonicalPayloadOptions?)
Builds a canonical payload for a persistence-ready audit ledger record.
public static CanonicalPayload ForAuditLedgerRecord(AuditLedgerRecord record, CanonicalPayloadOptions? options = null)
Parameters
recordAuditLedgerRecordoptionsCanonicalPayloadOptions
Returns
ForCapabilityGrant(CapabilityGrant, CanonicalPayloadOptions?)
Builds a canonical payload for a capability grant grant.
public static CanonicalPayload ForCapabilityGrant(CapabilityGrant grant, CanonicalPayloadOptions? options = null)
Parameters
grantCapabilityGrantThe capability grant grant to canonicalize.
optionsCanonicalPayloadOptionsCanonicalization options, including the metadata allow-list.
Returns
- CanonicalPayload
A deterministic canonical payload for the grant.
Remarks
Every field the grant carries is included, so the resulting hash binds the whole grant rather than a subset of it. A payload that omits a field leaves that field outside the proof while CapabilityGrantValidator still enforces it, which lets a modified value pass validation against a signature computed before the change. Scopes are normalized to a sorted, de-duplicated, ordinal set, so two grants that differ only in scope ordering produce the same hash.
Metadata is the one exception, and deliberately so: it is filtered through AllowsMetadataKey(string), whose allow-list is empty by default. With default options no grant metadata reaches the proof at all, which keeps unbounded and potentially sensitive host data out of hashed payloads. A host that puts security-relevant data in grant metadata has no binding for it until that key is added to the allow-list.
ForDecisionReceipt(IDecisionReceipt, CanonicalPayloadOptions?)
Builds a canonical payload for decision receipt.
public static CanonicalPayload ForDecisionReceipt(IDecisionReceipt receipt, CanonicalPayloadOptions? options = null)
Parameters
receiptIDecisionReceiptoptionsCanonicalPayloadOptions
Returns
ForDecisionReceiptLifecycleEvent(DecisionReceiptLifecycleEvent, CanonicalPayloadOptions?)
Builds a canonical payload for an decision receipt lifecycle event.
public static CanonicalPayload ForDecisionReceiptLifecycleEvent(DecisionReceiptLifecycleEvent lifecycleEvent, CanonicalPayloadOptions? options = null)
Parameters
lifecycleEventDecisionReceiptLifecycleEventoptionsCanonicalPayloadOptions
Returns
ForGovernanceEmissionEnvelope(GovernanceEmissionEnvelope, CanonicalPayloadOptions?)
Builds a canonical payload for a governance emission envelope.
public static CanonicalPayload ForGovernanceEmissionEnvelope(GovernanceEmissionEnvelope envelope, CanonicalPayloadOptions? options = null)
Parameters
envelopeGovernanceEmissionEnvelopeoptionsCanonicalPayloadOptions
Returns
ForGovernanceOutboxEntry(GovernanceOutboxEntry, CanonicalPayloadOptions?)
Builds a canonical payload for a durable outbox entry.
public static CanonicalPayload ForGovernanceOutboxEntry(GovernanceOutboxEntry entry, CanonicalPayloadOptions? options = null)
Parameters
entryGovernanceOutboxEntryoptionsCanonicalPayloadOptions