Documentation
¶
Overview ¶
Package leaf rebuilds Access Transparency transparency-log leaf entries from events exactly as the Compliance API activity feed serves them.
A leaf entry is SchemaVersion followed by RFC 8785 (JCS) canonical JSON over field set v1 — eleven keys projected from the served event. Its RFC 6962 leaf hash is SHA-256(0x00 || entry). The projection rules are the public transparency-log specification's § Leaf canonicalization: values are copied byte for byte, a key the served event omits enters as null, keys outside the set are ignored, and actor.email_address and resource_details.parent are always null under schema version 0x01.
Index ¶
Constants ¶
const IndexKey = "transparency_log_leaf_index"
IndexKey is the served key carrying an event's position in its organization's log; null when the event has no leaf.
const SchemaVersion byte = 0x01
SchemaVersion is the leaf-entry version byte for field set v1.
Variables ¶
var ErrUnknownType = errors.New("event type is outside leaf schema version 0x01's type list; a newer axt-verify is required")
ErrUnknownType means the served event's type is outside Types.
Functions ¶
func ClaimsOurType ¶
ClaimsOurType reports whether a type value is one of ours, or is near enough to be claiming to be. Only a type that shares no beginning with one of ours is passed over as another product's row; everything else goes to Parse and is refused there, because relabelling an event is the cheapest way to make it disappear from a verification pass.
func TypeOf ¶
TypeOf reads an activity's "type" through the same strict decode Parse uses. A caller deciding whether a row is this tool's to check must not be told one thing by a lenient parser and another by the canonicalizer: every ambiguity Parse refuses — a repeated member, a member differing only in case from a projected name, trailing content — is an error here too, and an error means the row is ours to fail, never to pass over.
Types ¶
type Event ¶
type Event struct {
// ID is the served activity id ("" when the record carries none).
ID string
// OrganizationUUID is the served organization_uuid ("" when absent).
OrganizationUUID string
// Index is the event's leaf index; nil when the event has no leaf
// (recorded while the organization had no active log).
Index *uint64
// Entry is the leaf entry: SchemaVersion || canonical JSON.
Entry []byte
}
Event is what a verifier needs from one served event.
func Parse ¶
Parse projects one served event — a JSON object as it appears in the activity feed's data array or a SIEM export of it — onto field set v1. Served bytes that are ambiguous about a projected value are refused, not resolved: a repeated member name, a name differing from a projected one only in case, or a string the JSON decoder would repair. Resolving one would stamp several distinct served forms as the single leaf the log committed, and only the form this verifier happened to read would be the verified one.