跳转到内容

ak.schema.holder_quarantine.v1

← Schemas

Arkret Holder Quarantine
ak.schema.holder_quarantine.v1 · file: schemas/holder-quarantine.schema.json

Closed plaintext account-data typed current result value of ak.account.holder_quarantine. The recipient Station is the sole CAS writer; the typed current result is a pending-review pointer inbox and grants no membership, contact, or consent authority. surface_kind is the closed discriminator: invite_delivery entries reference an accepted invite Event and its introduction evidence, consent_request entries reference no Event at all. Contact delivery is not a branch here: a Contact request has its own pending_incoming state and MUST NOT get a second parallel review carrier.

* $ · object
Closed plaintext account-data typed current result value of ak.account.holder_quarantine. The recipient Station is the sole CAS writer; the typed current result is a pending-review pointer inbox and grants no membership, contact, or consent authority. surface_kind is the closed discriminator: invite_delivery entries reference an accepted invite Event and its introduction evidence, consent_request entries reference no Event at all. Contact delivery is not a branch here: a Contact request has its own pending_incoming state and MUST NOT get a second parallel review carrier.
* schema · const "ak.schema.holder_quarantine.v1"
enum: "ak.schema.holder_quarantine.v1"
* updated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* quarantine_entries · array<$ref #/$defs/quarantine_entry>
Bounded pending-review entries, oldest first. Expired entries are purged before a write and overflow evicts the oldest entries.
items · object · $ref #/$defs/quarantine_entry
One pending-review quarantined admission. Membership in quarantine_entries is the only state this typed current result expresses: an entry is pending review until the holder reviews it or its TTL discards it, so no status member is carried. The two surface_kind branches are closed and mutually exclusive; a member declared by the other branch is a schema violation.
allOf · allOf[0] · ?
* entry_digest · string · $ref #/$defs/digest
Recipient-service-local stable deduplication digest for this quarantined delivery.
pattern: ^sha256:[0-9a-f]{64}$
* account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* source_peer_principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* source_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* surface_kind · string (enum) · $ref #/$defs/surface_kind
Closed discriminator for the admission surface that produced this entry. An unregistered value fails closed.
enum: "invite_delivery" "consent_request"
* consent_scope · string (enum)
Requested consent scope. The invite_delivery branch pins it to invite; the consent_request branch admits every other registered scope. The enum mirrors zh/identity/consent-model.md section 4.
enum: "invite" "voice_call" "video_call" "presence" "any"
introduction_kind · string (enum) · $ref #/$defs/introduction_kind
Introduction evidence kind presented by the requester. invite_delivery branch only; a consent request has no introduction evidence, so any value there would be fabricated.
enum: "locator_ref" "consent_grant" "shared_realm" "handle_claim" "same_station" "explicit_address"
effective_kind · string (enum) · $ref #/$defs/introduction_kind
Evidence kind after verification downgrade.
enum: "locator_ref" "consent_grant" "shared_realm" "handle_claim" "same_station" "explicit_address"
trust_tier · string (enum)
enum: "high" "discovery" "low"
invite_event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
request_digest · string · $ref #/$defs/digest
Replay deduplication digest of the invite delivery request. invite_delivery branch only: ak.self.consent.command.request.v1 declares idempotency_mechanism none and carries no nonce, so its branch deduplicates by live-entry uniqueness instead.
pattern: ^sha256:[0-9a-f]{64}$
idempotency_key_digest · string · $ref #/$defs/digest
Digest of the invite delivery Idempotency-Key. invite_delivery branch only, for the same reason as request_digest.
pattern: ^sha256:[0-9a-f]{64}$
* received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* expires_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
last_invalidation · object · $ref #/$defs/consent_revoke_invalidation
Optional diagnostic for the latest accepted consent-revoke invalidation. It is holder-private and never disclosed to the requester.
* reason · const "consent_revoke"
enum: "consent_revoke"
* peer_principal_id · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* consent_scope · string (enum)
enum: "invite" "any"
* revoked_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* removed_entries · integer

Source