跳转到内容

ak.schema.realm_read_operations.v1

← Schemas

Arkret Realm Read Operation DTOs
ak.schema.realm_read_operations.v1 · file: schemas/realm-read-operations.schema.json

Closed response DTOs for the self-surface Realm read operations (ak.self.realm.*). Realm read returns the lifecycle projection, stream enumeration returns the visible authority streams of one Realm, and export returns a full event-log + operation dump. See spec/v1/zh/models/realm-and-space.md.

* $ · anyOf[3]
Closed response DTOs for the self-surface Realm read operations (ak.self.realm.*). Realm read returns the lifecycle projection, stream enumeration returns the visible authority streams of one Realm, and export returns a full event-log + operation dump. See spec/v1/zh/models/realm-and-space.md.
anyOf · anyOf[0] · object · $ref #/$defs/realm_lifecycle_view
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* owner_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* member_ids · array<$ref ./common-ids.schema.json#/$defs/actor_id>
items · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* deleted · boolean
archived · boolean
example: false
frozen · boolean
example: false
terminal_state · string (enum)
enum: "tombstoned" "destroyed"
successor_realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
anyOf · anyOf[1] · object · $ref #/$defs/realm_stream_list
ACL-filtered, paginated enumeration of one Realm's authority streams (ak.self.realm.read.streams.v1). It is the discovery surface that positional scan cannot be: scan requires a stream_ref the caller already knows, so without this list a stream outside the bounded subscribe window would be undiscoverable. Pagination is a fixed snapshot: the page sequence is taken against one server-side generation, so a stream that appears after the first page is NOT inserted into the earlier pages and is therefore never skipped; it is discovered by a later enumeration or by the visible discovery delta. Permissions are re-checked on every page, so a page MAY be narrower than its predecessor, and a stream the caller has stopped being permitted to know about MUST disappear rather than be served from the frozen generation.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* streams · array<$ref #/$defs/realm_stream_row>
Rows sorted by unsigned bytes of RFC 8785 JCS(stream_ref), the same order the subscribe frame truncates in, so enumeration and delivery agree on which streams a bounded window kept. The Realm stream is a row like any other.
items · object · $ref #/$defs/realm_stream_row
One authority stream of the Realm that this caller is permitted to know exists and whose Commit chain is already established. Progress uses the same {head_commit_ref, next_position} shape as zh/sync/service-surface.md section 4.6, and readable_floor is the same anchor the scan surface returns, so a client can enumerate, bind its permitted prefix and continue the tail without a second vocabulary.
* stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* head_commit_ref · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* next_position · integer
Next stream_position this stream expects, i.e. head stream_position + 1. Positions are never compared across streams.
readable_floor · object · $ref ./authority-commit-operations.schema.json#/$defs/readable_floor
Verifiable bottom of one caller's readable range on one stream. The anchor lets a member whose history is trimmed verify that its permitted prefix is complete without ever holding position 0: it proves where the accepted chain that caller may read begins, and it proves nothing about whether the Station holds further history below it or further updates above it.
* oldest_position · integer
Smallest stream_position this caller is permitted to read. Positions below it are unreadable, not missing: their absence MUST NOT be treated as a gap and MUST NOT be used to infer activity, membership or existence below the floor.
* floor_commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* floor_reason · string (enum)
Why the range starts here. stream_start means the floor is the physical start of the stream and oldest_position is 0; the other two are trimmed ranges and MUST NOT be reported as stream_start. Retention never moves a floor: v1 never deletes an accepted RealmCommit and expired Events are returned through the withheld CommittedEventView branch.
enum: "stream_start" "membership_join" "history_access_policy"
next_cursor · string · $ref #/$defs/cursor
Opaque continuation of this enumeration. Absent means the current page is the last one.
pattern: ^ak:cursor:[A-Za-z0-9_-]+$
* has_more · boolean
The only field a client may use to decide whether to keep paging (zh/sync/api-conventions.md section 7.1).
anyOf · anyOf[2] · object · $ref #/$defs/realm_export
* schema · const "ak.export.realm.v1"
enum: "ak.export.realm.v1"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* generated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* operations · array<object>
Operation dump rows {operation_id, realm_id, object_kind, operation_type, payload, created_at}.
items · object
* events · array<object>
Event-log dump rows {event_id, realm_id, event_kind, operation_type, operation_id, sender, payload, created_at}.
items · object

Source