Documentation
¶
Overview ¶
Package nativeprotocol validates the versioned native helper replies. It has no process, permission, notification, or legacy presentation effects.
Index ¶
- Constants
- Variables
- func EncodeRequest(r Request) ([]byte, error)
- func ValidDesktopThreadTarget(threadID, applicationPath, teamID string) bool
- func ValidText(s string, limit int, multiline bool) bool
- type Capabilities
- type DesktopThreadAction
- type Permission
- type Receipt
- type Request
- type SetupCapabilities
Constants ¶
const MaxEnvelopeBytes = 16 * 1024
Variables ¶
var ErrInvalidEnvelope = errors.New("invalid native protocol envelope")
ErrInvalidEnvelope deliberately contains no caller text or native output.
Functions ¶
func EncodeRequest ¶
EncodeRequest validates decoded byte limits before JSON serialization. UTF-8 is preserved exactly; json.Marshal's safe escaping is representation only.
func ValidDesktopThreadTarget ¶ added in v1.47.0
ValidDesktopThreadTarget checks target syntax only, without probing an app or chat. Policy eligibility and action/envelope identity are separate checks.
Types ¶
type Capabilities ¶
type Capabilities struct {
SchemaVersion int `json:"schemaVersion"`
ProtocolVersions []int `json:"protocolVersions"`
ActionKinds []string `json:"actionKinds"`
ReceiptSupport bool `json:"receiptSupport"`
Backend string `json:"backend"`
ExplicitFeatureEnabledByDefault bool `json:"explicitFeatureEnabledByDefault"`
}
func DecodeCapabilities ¶
func DecodeCapabilities(data []byte) (Capabilities, error)
DecodeCapabilities is only a codec. A trusted managed artifact fingerprint must be verified before a caller launches a capabilities probe.
type DesktopThreadAction ¶
type DesktopThreadAction struct {
Type string `json:"type"`
SchemaVersion int `json:"schemaVersion"`
ThreadID string `json:"threadID"`
RouteKind string `json:"routeKind"`
BundleID string `json:"bundleID"`
TeamID string `json:"teamID"`
ApplicationPath string `json:"applicationPath"`
CorrelationID string `json:"correlationID"`
}
DesktopThreadAction matches the native lane's shared action fixture. This type has no arbitrary command, URL or fallback application field.
type Permission ¶
type Permission struct {
SchemaVersion int `json:"schemaVersion"`
CorrelationID string `json:"correlationID"`
Nonce string `json:"nonce"`
Backend string `json:"backend"`
Permission string `json:"permission"`
}
func DecodePermission ¶
func DecodePermission(data []byte, correlation, nonce string) (Permission, error)
type Receipt ¶
type Request ¶
type Request struct {
SchemaVersion int `json:"schemaVersion"`
CorrelationID string `json:"correlationID"`
Nonce string `json:"nonce"`
BootID string `json:"bootID"`
NotAfter float64 `json:"notAfter"`
Title string `json:"title"`
Body string `json:"body"`
Subtitle string `json:"subtitle,omitempty"`
Category string `json:"category"`
// Nil encodes the native string "none"; a nonnil pointer encodes only the
// fixed typed object. No raw JSON escapes the trusted producer.
Action *DesktopThreadAction `json:"-"`
Silent bool `json:"silent"`
}
type SetupCapabilities ¶
type SetupCapabilities struct {
SchemaVersion int `json:"schemaVersion"`
PermissionRequestVersions []int `json:"permissionRequestVersions"`
Backend string `json:"backend"`
}
SetupCapabilities is separate from notification actions and send versions. Callers must verify managed artifact identity and known base capabilities before probing with exactly --capabilities-json --setup. No launcher lives here.
func DecodeSetupCapabilities ¶
func DecodeSetupCapabilities(data []byte) (SetupCapabilities, error)
DecodeSetupCapabilities fails closed unless the exact supported v1 contract is advertised. Permission outcomes use DecodePermission, never DecodeReceipt.