leaf

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 31, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package leaf rebuilds Access Transparency transparency-log leaf entries from events exactly as the Compliance API activity feed serves them.

A leaf entry is SchemaVersion followed by RFC 8785 (JCS) canonical JSON over field set v1 — eleven keys projected from the served event. Its RFC 6962 leaf hash is SHA-256(0x00 || entry). The projection rules are the public transparency-log specification's § Leaf canonicalization: values are copied byte for byte, a key the served event omits enters as null, keys outside the set are ignored, and actor.email_address and resource_details.parent are always null under schema version 0x01.

Index

Constants

View Source
const IndexKey = "transparency_log_leaf_index"

IndexKey is the served key carrying an event's position in its organization's log; null when the event has no leaf.

View Source
const SchemaVersion byte = 0x01

SchemaVersion is the leaf-entry version byte for field set v1.

Variables

View Source
var ErrUnknownType = errors.New("event type is outside leaf schema version 0x01's type list; a newer axt-verify is required")

ErrUnknownType means the served event's type is outside Types.

Functions

func ClaimsOurType

func ClaimsOurType(typ string) bool

ClaimsOurType reports whether a type value is one of ours, or is near enough to be claiming to be. Only a type that shares no beginning with one of ours is passed over as another product's row; everything else goes to Parse and is refused there, because relabelling an event is the cheapest way to make it disappear from a verification pass.

func TypeOf

func TypeOf(served []byte) (string, error)

TypeOf reads an activity's "type" through the same strict decode Parse uses. A caller deciding whether a row is this tool's to check must not be told one thing by a lenient parser and another by the canonicalizer: every ambiguity Parse refuses — a repeated member, a member differing only in case from a projected name, trailing content — is an error here too, and an error means the row is ours to fail, never to pass over.

func Types

func Types() []string

Types returns schema version 0x01's closed event-type list. An event of any other type cannot be a 0x01 leaf: new types ship under a new version byte and need a newer verifier.

Types

type Event

type Event struct {
	// ID is the served activity id ("" when the record carries none).
	ID string
	// OrganizationUUID is the served organization_uuid ("" when absent).
	OrganizationUUID string
	// Index is the event's leaf index; nil when the event has no leaf
	// (recorded while the organization had no active log).
	Index *uint64
	// Entry is the leaf entry: SchemaVersion || canonical JSON.
	Entry []byte
}

Event is what a verifier needs from one served event.

func Parse

func Parse(served []byte) (Event, error)

Parse projects one served event — a JSON object as it appears in the activity feed's data array or a SIEM export of it — onto field set v1. Served bytes that are ambiguous about a projected value are refused, not resolved: a repeated member name, a name differing from a projected one only in case, or a string the JSON decoder would repair. Resolving one would stamp several distinct served forms as the single leaf the log committed, and only the form this verifier happened to read would be the verified one.

func (Event) Hash

func (e Event) Hash() []byte

Hash returns the RFC 6962 leaf hash of the entry.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL