跳转到内容

ak.profile.push_gateway.visible_notification.v1

← Profiles

ak.profile.push_gateway.visible_notification.v1

role

"gateway"

description

"Opt-in push gateway profile for deployments that require visible notification fields (e.g. titles, sender labels) in provider payloads. Claiming this profile is permitted ONLY when (1) Realm policy explicitly lists the gateway in plaintext_visible_services AND declares visible_notification allowance, (2) per-device opt-in is recorded in ak.device authorization state, and (3) the client UI clearly surfaces that visible-notification mode is active. Even when claimed, payloads MUST stay minimised: no message body, no DID URL, no cross-Realm stable correlation key, no IP / geolocation, no free-form text outside the profile-declared field set. See zh/discovery/push-notifications.md §5.1."

enforcement_phases

[
  "conformance",
  "startup_claim_guard"
]

operation_requirements

[
  {
    "direction": "provide",
    "operation_id": "ak.edge.push.command.notify.v1",
    "binding_kind": "http_json"
  }
]

depends_on

[
  "ak.profile.push_gateway.v1"
]

required_profiles

[
  "ak.profile.push_gateway.v1",
  "ak.profile.push_gateway.blind_wakeup.v1"
]

inherits

[
  "ak.profile.push_gateway.v1"
]

required_event_kinds

[
  "ak.device.authorize"
]

rejected_event_kinds

[]

required_schemas

[
  "ak.schema.notification.v1"
]

required_fixtures

[
  "privacy-security-fixture.json"
]

optional_extensions

[
  "notification_summary"
]

feature_discovery

{
  "required": [
    "visible_notification_policy_ref",
    "device_opt_in_state",
    "ui_disclosure"
  ],
  "unsupported_optional": "omit profile claim; deployments that cannot guarantee Realm policy + device opt-in + UI disclosure MUST NOT claim this profile"
}

additional_requirements

{
  "policy_gate_must": "Realm policy MUST list the gateway service DID in plaintext_visible_services with visible_notification explicitly allowed.",
  "device_opt_in_must": "Each receiving device MUST record an opt-in flag in its authorization state; absent opt-in, sender / Realm service MUST fall back to blind wakeup.",
  "ui_disclosure_must": "Client UI MUST clearly indicate visible notification is active to the user.",
  "payload_minimisation_must": "Even when claimed, payload MUST NOT carry message body, DID URLs, cross-Realm stable correlation keys, IP / geolocation, or untyped free-form text."
}

Source