跳转到内容

ak.schema.moderation_queue_item.v1

← Schemas

Arkret Moderation Queue Item
ak.schema.moderation_queue_item.v1 · file: schemas/moderation-queue-item.schema.json
* $ · object
* id · string
The accepted ak.self.moderation.report Event id retyped to moderation_queue_item; services MUST NOT allocate an independent identifier. See governance/content-moderation.md section 3.3.
pattern: ^ak:moderation_queue_item:[A-Za-z0-9_-]{44}$
* report · object · $ref ./event-payload.schema.json#/$defs/moderation_report_payload
Immutable payload projection from the accepted ak.self.moderation.report Event; never the service-operation request wrapper.
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
effective_scope · $ref #/$defs/effective_scope · $ref #/$defs/effective_scope
Governance boundary for the report. Defaults to the Realm scope when absent; Circle-scoped targets MUST resolve to the target Circle and route only to scoped moderators/admins.
* target_ref · $ref #/$defs/object_ref · $ref #/$defs/object_ref
* report_reason_code · string (enum)
enum: "spam" "harassment" "hate_speech" "nsfw" "illegal" "misinformation" "other"
description · string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_text
NFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern: ^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$
* reporter_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
provenance · string (enum)
Delivery provenance. Absent or "self" is a native self-authored report. "mimi_facade" is a service-attested report authored by the authorized receiving facade service after authenticating the source Provider and the reporter's claim and current authority. The facade never writes the reporter Actor as Event actor; source_provider_id is required only for mimi_facade.
enum: "self" "mimi_facade"
source_provider_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
Origin MIMI provider's service DID for a facade-mapped report. Required exactly when provenance is "mimi_facade"; forbidden otherwise.
evidence_refs · array<$ref #/$defs/object_ref>
items · $ref #/$defs/object_ref · $ref #/$defs/object_ref
evidence_package · object · $ref ./moderation-evidence.schema.json#/$defs/evidence_package
Canonical encrypted moderation evidence-package descriptor. target_refs names exactly the report target at admission; recipient_public_key_ref and encrypted_to MUST be byte-identical and resolve to an authorized moderator key for the report's exact effective scope. reporter_signature covers the descriptor and referenced ciphertext. The encrypted material MUST contain only reporter-visible evidence for target_refs and MUST NOT contain MLS epoch/exporter private material or unrelated plaintext.
* target_refs · array<$ref #/$defs/object_ref>
items · $ref #/$defs/object_ref · $ref #/$defs/object_ref
* encryption · string
* recipient_public_key_ref · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* encrypted_to_kid · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* ciphertext · string
Base64url without padding.
pattern: ^[A-Za-z0-9_-]+$
* ciphertext_digest · $ref #/$defs/digest · $ref #/$defs/digest
plaintext_digest · $ref #/$defs/digest · $ref #/$defs/digest
* reporter_signature · string
franking_proof · object · $ref ./moderation-evidence.schema.json#/$defs/franking_proof
Canonical receiving-service receipt used both inside a moderation report and as the complete payload of an ak.moderation.franking_proof durable Event. The local signature uses domain ak.franking_proof.signature.v1 and covers every member except signature. event_id names the encrypted Event whose receipt is proven; the enclosing proof Event has its own distinct Event.event_id.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* event_id · string · $ref ./common-ids.schema.json#/$defs/event_id
Complete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* received_by · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* verification_method · string · $ref ./common-ids.schema.json#/$defs/did_url
Arkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern: ^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$
* received_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* replay_nonce · string
Opaque anti-replay nonce generated by the receiving service and covered by the proof signature.
pattern: ^[A-Za-z0-9_-]{16,256}$
* signature · string
Receiving service signature over the canonical franking-proof transcript.
* status · string (enum)
Authoritative moderation queue-item lifecycle. v1 is intentionally minimal: 'submitted' = report accepted and awaiting handling; 'resolved' = handling complete (terminal). The disposition (action taken vs no violation) lives on the separate ak.moderation.decision event. Additional intermediate states MAY be introduced in a later revision if a workflow phase needs them. See governance/content-moderation.md §3.3.
enum: "submitted" "resolved"
priority · string (enum)
Local administrator workflow only: never carried in an Event payload, never part of the decision fold, never replicated across Stations, and never a capability. Omit when unassigned. See governance/content-moderation.md section 3.3.
enum: "low" "normal" "high" "urgent"
* visibility · string (enum)
Read-side derivation over the accepted report and the target scope, in the order given in governance/content-moderation.md section 3.3: plaintext scope -> plaintext_evidence; evidence_package present -> encrypted_evidence; franking_proof only -> franking_proof_only; otherwise metadata_only. When evidence is withheld or trimmed for an unauthorized caller, this member MUST be downgraded to the evidence shape that caller can actually receive, and MUST NOT reveal whether the trimmed evidence exists. Never written by the reporter and never hard-filled with one default.
enum: "metadata_only" "encrypted_evidence" "plaintext_evidence" "franking_proof_only"
assigned_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Local administrator workflow only; entries MUST already hold the matching moderation capability in this scope. Omit when unassigned. See governance/content-moderation.md section 3.3.
items · string · $ref ./common-ids.schema.json#/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
evidence_policy · object
Derived handling policy; omit when there is no material source. plaintext_allowed mirrors the plaintext-scope branch of visibility, franking_proof_verification_required mirrors whether the report payload carries a franking_proof. retention_expires_at and legal_hold are local retention policy and MUST NOT change the canonical decision. See governance/content-moderation.md section 3.3.
* plaintext_allowed · boolean
* franking_proof_verification_required · boolean
retention_expires_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
legal_hold · boolean
audit_refs · array<string>
Local administrator workflow only; entries MUST be Events the caller is already authorized to read. See governance/content-moderation.md section 3.3.
items · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
* created_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$

Source