跳转到内容

ak.profile.applet_service.v1

← Profiles

ak.profile.applet_service.v1

enforcement_phases

[
  "conformance",
  "startup_claim_guard"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.edge.applet.read.describe.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.edge.applet.read.ping.v1",
    "binding_kind": "http_json"
  },
  {
    "direction": "provide",
    "operation_id": "ak.edge.applet.command.transaction.v1",
    "binding_kind": "http_json"
  }
]

required_event_kinds

[
  "ak.applet.registration"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.event.v1",
  "ak.schema.event_payload.v1",
  "ak.schema.applet_package.v1",
  "ak.schema.applet_registration_epoch_transcript.v1"
]

required_fixtures

[
  "applet-registration-epoch-fixture.json"
]

optional_extensions

[]

feature_discovery

{
  "required": [
    "claimed_profiles",
    "supported_protocols",
    "namespace",
    "service_id",
    "transaction_delivery_authentication_record",
    "transaction_replay_binding"
  ],
  "unsupported_optional": "return unsupported_feature"
}

additional_requirements

{
  "transaction_push_per_delivery_signature_must": "ak.edge.applet.command.transaction.v1 MUST require a per-delivery RFC 9421 HTTP Message Signature in both node->Applet and app/bridge->arkret inbound directions; pure bearer-only transaction push MUST be rejected with http_signature_required.",
  "transaction_push_covered_components_must": {
    "signature_scenario_id": "ak.http_signature.scenario.applet_transaction.v1",
    "covered_components": [
      "@authority",
      "@method",
      "@target-uri",
      "arkret-operation",
      "content-digest",
      "destination-service-id",
      "idempotency-key",
      "source-service-id"
    ],
    "freshness_profile_id": "ak.http_signature.freshness.v1",
    "statement": "Signature-Input MUST cover every component listed here. The list is a projection of http_signature_contract_registry in contract-registry.json and is compared to it by gate; it is a minimum, not a closed set. created/expires MUST satisfy the shared window in zh/sync/service-http-binding.md section 8.3. A request whose Arkret-Operation header is present but not signed MUST be rejected with http_signature_invalid."
  },
  "transaction_push_delivery_authentication_record_must": "Receivers MUST derive and persist the closed delivery_authentication_record from verified inputs, including operation/direction, source/destination, signature label, verification method/key digest/algorithm, registration epoch, idempotency key, content digest, ordered covered components, created and expires. They MUST recompute delivery_authentication_record_digest with domain ak.applet.delivery_authentication_record.v1; neither value is caller supplied.",
  "transaction_push_replay_binding_must": "The idempotency identity MUST include operation_id, direction, Source-Service-ID, Destination-Service-ID and Idempotency-Key; the cached record MUST bind canonical body digest, delivery_authentication_record and its receiver-recomputed digest. A replay with a different body digest or authentication-record digest MUST fail closed.",
  "transaction_push_inbound_registration_must": "For app/bridge->arkret inbound push, Source-Service-ID MUST match an active effective Applet install and Signature-Input keyid MUST equal the current registration webhook_auth.key_ref; missing install or key mismatch MUST fail closed with applet_registration_unauthorized or http_signature_invalid.",
  "transaction_push_actor_binding_must": "The source service signature authenticates only the Applet service. Each durable Event in the transaction MUST still verify event proofs, applet_id, authorization_ref, actor_id namespace and capability grants; namespace or actor-source confusion MUST fail closed.",
  "managed_authority_contract_must": "Service-only install, 0..N independent Bot/Ghost; exact role creation actions, ordinary Service parent to terminal child and Device content supply follow registry/applet-managed-authority-registry.json and zh/authz/managed-governance.md."
}

non_event_grant_authority_rules

[
  {
    "issuer_action": "ak.realm.admin",
    "issuer_owner_authority_allowed": true,
    "grantable_action": "ak.applet.bot.provision",
    "required_registration_event_kind": "ak.applet.registration",
    "required_claimed_profile": "ak.profile.applet_service.v1",
    "required_constraint_kind": "authority_control",
    "required_constraint_subkind": "applet_authority",
    "subject_binding": "registration.service_id",
    "scope_binding": "grant.resource_exact_registration_scope",
    "epoch_binding": "constraint.registration_epoch_exact_registration",
    "requested_action_binding": "grant.action_in_registration.requested_scopes"
  }
]

Source