跳转到内容

ak.profile.push_gateway.v1

← Profiles

ak.profile.push_gateway.v1

role

"gateway"

description

"Push gateway delivery profile. Provides notify, not Account device registration. Registration and unregistration belong to the Account Station role. All implementations claiming this profile MUST also implement ak.profile.push_gateway.blind_wakeup.v1 and read an authoritative durable registration within the supported deployment boundary. A shared-authority deployment may read that state directly; an independent public Gateway must separately advertise ak.operation_bundle.push_gateway.registration_handoff.v1 and satisfy the source-Station tenant isolation and signed durable receipt contract in zh/discovery/push-notifications.md sections 3.3-3.4. Visible notification remains an explicit opt-in profile."

enforcement_phases

[
  "conformance",
  "startup_claim_guard"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.edge.push.command.notify.v1",
    "binding_kind": "http_json"
  }
]

depends_on

[
  "ak.profile.push_gateway.blind_wakeup.v1"
]

required_profiles

[
  "ak.profile.push_gateway.blind_wakeup.v1"
]

required_event_kinds

[]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.notification.v1"
]

required_fixtures

[
  "privacy-security-fixture.json"
]

optional_extensions

[
  "notification_summary"
]

feature_discovery

{
  "required": [
    "payload_max_bytes",
    "plaintext_visibility_classes"
  ],
  "unsupported_optional": "strip unsupported plaintext fields"
}

additional_requirements

{
  "registration_authority_must": "A Gateway MUST resolve notify only from an exact durable registration. It MUST NOT provide Account self-service registration or infer registration from notify selectors.",
  "public_handoff_bundle_must": "An independent public Gateway MUST advertise ak.operation_bundle.push_gateway.registration_handoff.v1 in addition to the notify bundle before a Station may select it. Shared-authority deployments omit that handoff bundle when no wire transfer is needed.",
  "station_tenant_isolation_must": "Public handoff storage, encryption keys, logs, access, workers, caches, backups and deletion MUST be partitioned by authenticated Source-Service-ID. Raw provider tokens MUST NOT enter logs, metrics, traces, receipts or cross-Station indexes.",
  "handoff_recovery_must": "The handoff is immutable per (authenticated source Station, registration_id): exact replay returns the original signed durable receipt, different content conflicts, revoked is terminal, and installing an exact successor atomically tombstones its predecessor."
}

Source