nativeprotocol

package
v1.48.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: GPL-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package nativeprotocol validates the versioned native helper replies. It has no process, permission, notification, or legacy presentation effects.

Index

Constants

View Source
const MaxEnvelopeBytes = 16 * 1024

Variables

View Source
var ErrInvalidEnvelope = errors.New("invalid native protocol envelope")

ErrInvalidEnvelope deliberately contains no caller text or native output.

Functions

func EncodeRequest

func EncodeRequest(r Request) ([]byte, error)

EncodeRequest validates decoded byte limits before JSON serialization. UTF-8 is preserved exactly; json.Marshal's safe escaping is representation only.

func ValidDesktopThreadTarget added in v1.47.0

func ValidDesktopThreadTarget(threadID, applicationPath, teamID string) bool

ValidDesktopThreadTarget checks target syntax only, without probing an app or chat. Policy eligibility and action/envelope identity are separate checks.

func ValidText

func ValidText(s string, limit int, multiline bool) bool

Types

type Capabilities

type Capabilities struct {
	SchemaVersion                   int      `json:"schemaVersion"`
	ProtocolVersions                []int    `json:"protocolVersions"`
	ActionKinds                     []string `json:"actionKinds"`
	ReceiptSupport                  bool     `json:"receiptSupport"`
	Backend                         string   `json:"backend"`
	ExplicitFeatureEnabledByDefault bool     `json:"explicitFeatureEnabledByDefault"`
}

func DecodeCapabilities

func DecodeCapabilities(data []byte) (Capabilities, error)

DecodeCapabilities is only a codec. A trusted managed artifact fingerprint must be verified before a caller launches a capabilities probe.

func (Capabilities) Supports

func (c Capabilities) Supports(version int, action string) bool

type DesktopThreadAction

type DesktopThreadAction struct {
	Type            string `json:"type"`
	SchemaVersion   int    `json:"schemaVersion"`
	ThreadID        string `json:"threadID"`
	RouteKind       string `json:"routeKind"`
	BundleID        string `json:"bundleID"`
	TeamID          string `json:"teamID"`
	ApplicationPath string `json:"applicationPath"`
	CorrelationID   string `json:"correlationID"`
}

DesktopThreadAction matches the native lane's shared action fixture. This type has no arbitrary command, URL or fallback application field.

type Permission

type Permission struct {
	SchemaVersion int    `json:"schemaVersion"`
	CorrelationID string `json:"correlationID"`
	Nonce         string `json:"nonce"`
	Backend       string `json:"backend"`
	Permission    string `json:"permission"`
}

func DecodePermission

func DecodePermission(data []byte, correlation, nonce string) (Permission, error)

type Receipt

type Receipt struct {
	SchemaVersion  int    `json:"schemaVersion"`
	CorrelationID  string `json:"correlationID"`
	Nonce          string `json:"nonce"`
	NotificationID string `json:"notificationID"`
	Status         string `json:"status"`
	Reason         string `json:"reason"`
	RetrySafe      bool   `json:"retrySafe"`
}

func DecodeReceipt

func DecodeReceipt(data []byte, correlationID, nonce string) (Receipt, error)

DecodeReceipt requires the exact pending attempt's identity. Neither a process exit code nor an uncorrelated receipt proves OS acceptance.

type Request

type Request struct {
	SchemaVersion int     `json:"schemaVersion"`
	CorrelationID string  `json:"correlationID"`
	Nonce         string  `json:"nonce"`
	BootID        string  `json:"bootID"`
	NotAfter      float64 `json:"notAfter"`
	Title         string  `json:"title"`
	Body          string  `json:"body"`
	Subtitle      string  `json:"subtitle,omitempty"`
	Category      string  `json:"category"`
	// Nil encodes the native string "none"; a nonnil pointer encodes only the
	// fixed typed object. No raw JSON escapes the trusted producer.
	Action *DesktopThreadAction `json:"-"`
	Silent bool                 `json:"silent"`
}

type SetupCapabilities

type SetupCapabilities struct {
	SchemaVersion             int    `json:"schemaVersion"`
	PermissionRequestVersions []int  `json:"permissionRequestVersions"`
	Backend                   string `json:"backend"`
}

SetupCapabilities is separate from notification actions and send versions. Callers must verify managed artifact identity and known base capabilities before probing with exactly --capabilities-json --setup. No launcher lives here.

func DecodeSetupCapabilities

func DecodeSetupCapabilities(data []byte) (SetupCapabilities, error)

DecodeSetupCapabilities fails closed unless the exact supported v1 contract is advertised. Permission outcomes use DecodePermission, never DecodeReceipt.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL