domain

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Index

Constants

View Source
const (
	QuarantineAuditActionSecretGuard = "secret_guard"
	QuarantineAuditResultBlocked     = "blocked"
)

Variables

View Source
var (
	ErrSessionNotFound       = errors.New("securesession: session not found")
	ErrDuplicateSessionID    = errors.New("securesession: duplicate session id")
	ErrDuplicateFingerprint  = errors.New("securesession: duplicate resume fingerprint")
	ErrInvalidResumeToken    = errors.New("securesession: invalid resume token")
	ErrOwnerMismatch         = errors.New("securesession: owner mismatch")
	ErrResumeExpired         = errors.New("securesession: resume window expired")
	ErrWorkspaceDenied       = errors.New("securesession: workspace denied")
	ErrPolicyUnavailable     = errors.New("securesession: policy unavailable")
	ErrStorageUnavailable    = errors.New("securesession: storage unavailable")
	ErrMandatoryAuditFailure = errors.New("securesession: mandatory audit failure")
	ErrMissingPrincipal      = errors.New("securesession: missing principal")
	ErrTranscriptDisabled    = errors.New("securesession: transcript capture disabled for session")
	// ErrWorkspaceUnresolved is returned when workspace resolution failed under fail-closed policy
	// (Req 11.6: do not fail open into an ambiguous empty workspace for secure-session turns).
	ErrWorkspaceUnresolved = errors.New("securesession: workspace could not be resolved")
	// ErrSessionQuarantined is returned when a quarantined session is reused (resume or pre-dispatch).
	// Clients must start a new session; the mapped denial is protocol-safe and secret-free.
	ErrSessionQuarantined = errors.New("securesession: session quarantined")
	// ErrInvalidQuarantineInput is returned when a quarantine transition request is incomplete or invalid.
	ErrInvalidQuarantineInput = errors.New("securesession: invalid quarantine input")
	// ErrQuarantineUnimplemented is a Phase-1 compile stub sentinel returned by stores that have
	// not yet implemented Store.Quarantine (Phase 5). Production paths must not convert this to allow.
	ErrQuarantineUnimplemented = errors.New("securesession: Quarantine not implemented")
)

Domain errors for secure-session policy and storage. The composition root sets runtime.Executor.SessionDenialMapper (e.g. lipapidenial.MapToSessionDenial) to translate these to lipapi session denials for clients; domain and app return these sentinels unchanged.

Functions

func PrincipalIDPresent

func PrincipalIDPresent(p PrincipalRef) bool

PrincipalIDPresent reports whether a principal id is bound (non-empty after trim).

Types

type ActivitySource

type ActivitySource string

ActivitySource classifies what updated last activity.

const (
	ActivityClientRequest ActivitySource = "client_request"
	ActivityRemoteEvent   ActivitySource = "remote_event"
	ActivitySystem        ActivitySource = "system"
)

type AttemptAccounting

type AttemptAccounting struct {
	BLegID                   string
	InputTokens              int64
	OutputTokens             int64
	CacheReadTokens          int64
	CacheWriteTokens         int64
	NonCachedInputTokens     int64
	ReasoningTokens          int64
	NonReasoningOutputTokens int64
	TotalTokens              int64
	CostNanoUnits            int64
	CostMinorUnits           int64
	Currency                 string
	CostSource               string
	RawUsageJSON             string
	BillingUnavailable       bool

	RequestStartedAt         time.Time
	FirstRemoteEventAt       time.Time
	FirstMeaningfulTokenAt   time.Time
	RemoteCompletedAt        time.Time
	ProxyCompletedAt         time.Time
	TTFTMillis               int64
	RemoteDurationMillis     int64
	CompletionDurationMillis int64
	// CompletionTPSMilli stores tokens-per-second with milliprecision: 5000 means 5.000 TPS.
	CompletionTPSMilli int64
}

AttemptAccounting attaches usage/cost signals to a B-leg attempt.

func MergeAttemptAccounting

func MergeAttemptAccounting(base, delta AttemptAccounting) AttemptAccounting

MergeAttemptAccounting overlays a usage/timing delta onto an existing attempt accounting row. Numeric token and cost counters accumulate; optional timing and descriptive fields keep the latest non-zero/non-empty value. A delta for a different B-leg replaces the base.

type AttemptEvidence

type AttemptEvidence struct {
	Trace      AttemptTrace
	Outcome    AttemptOutcome
	Accounting AttemptAccounting
}

AttemptEvidence joins trace, terminal outcome, and usage for operator diagnostics (Req 14.8).

type AttemptOutcome

type AttemptOutcome struct {
	SessionID      SessionID
	TurnID         TurnID
	BLegID         string
	Success        bool
	SurfaceState   SurfaceState
	HTTPStatus     int
	ProviderStatus string
	ErrorCode      string
	TimeoutClass   string
	DebugReason    string
	EndedAt        time.Time
}

AttemptOutcome captures terminal state for a B-leg attempt.

type AttemptSettings

type AttemptSettings struct {
	Temperature          *float64
	MaxTokens            *int
	Timeout              time.Duration
	ReasoningEffort      string
	Verbosity            string
	Streaming            bool
	ToolSummary          []string
	BackendOptionsDigest string
}

AttemptSettings snapshots execution-affecting parameters for an attempt.

type AttemptTrace

type AttemptTrace struct {
	SessionID       SessionID
	TurnID          TurnID
	ALegID          string
	BLegID          string
	AttemptSeq      int
	RequestedModel  string
	RequestedAlias  string
	ResolvedBackend string
	ResolvedModel   string
	RouteSource     string
	RouteReason     string
	Settings        AttemptSettings
	StartedAt       time.Time
}

AttemptTrace captures routing and backend binding at B-leg open.

type AuditItem

type AuditItem struct {
	SessionID SessionID
	TurnID    TurnID
	Seq       int64
	Action    string
	Result    string
	CreatedAt time.Time
}

AuditItem is one ordered audit log entry.

type ClientHints

type ClientHints struct {
	ClientSessionID     string
	AgentIdentityDigest string
}

ClientHints are non-authoritative correlation inputs from the client.

type CreateRecord

type CreateRecord struct {
	SessionID         SessionID
	ResumeFingerprint TokenFingerprint
	Owner             PrincipalRef
	Workspace         WorkspaceRef
	ClientHints       ClientHints
	Policy            PolicyMetadata
	ALegID            string
	ResumeEligible    bool
	CreatedAt         time.Time
}

CreateRecord is input for initial session persistence.

type PolicyMetadata

type PolicyMetadata struct {
	PolicyVersion            string
	TranscriptEnabled        bool
	EffectiveTreatment       string
	StricterPolicyResolution string
	RouteHint                string
	RedactionProfile         string
	AuditMode                string
}

PolicyMetadata captures stored treatment and recording policy flags.

type PrincipalRef

type PrincipalRef struct {
	ID     string
	Issuer string
	Tenant string
}

PrincipalRef binds a session to an authenticated identity.

type QuarantineInput

type QuarantineInput struct {
	SessionID  SessionID
	TurnID     TurnID
	ReasonCode string
	EventID    string
	At         time.Time
}

QuarantineInput is the safe, idempotent transition request for Store.Quarantine. It must never carry secret values, prompt excerpts, or resume tokens.

func (QuarantineInput) Validate

func (in QuarantineInput) Validate() error

Validate reports whether in contains the minimum safe fields for quarantine.

type QuarantinePlan

type QuarantinePlan struct {
	Apply          bool
	Status         SessionStatus
	ResumeEligible bool
	QuarantinedAt  time.Time
	ReasonCode     string
	EventID        string
	AuditAction    string
	AuditResult    string
}

QuarantinePlan captures the pure transition outcome for Store.Quarantine.

func PlanQuarantine

func PlanQuarantine(current Record, in QuarantineInput) (QuarantinePlan, error)

PlanQuarantine derives the terminal quarantine transition from the current record and input. It never mutates the record; adapters own locking, persistence, and audit writes.

type ReadOptions

type ReadOptions struct {
	Limit    int
	AfterSeq int64
}

ReadOptions bounds transcript/audit reads.

type Record

type Record struct {
	SessionID               SessionID
	ResumeFingerprint       TokenFingerprint
	Owner                   PrincipalRef
	Workspace               WorkspaceRef
	ClientHints             ClientHints
	Policy                  PolicyMetadata
	ALegID                  string
	Status                  SessionStatus
	QuarantinedAt           time.Time
	QuarantineReasonCode    string
	QuarantineEventID       string
	ResumeEligible          bool
	LastActivityAt          time.Time
	LastActivitySource      ActivitySource
	CreatedAt               time.Time
	LatestAttemptTrace      AttemptTrace
	LatestAttemptOutcome    AttemptOutcome
	LatestAttemptAccounting AttemptAccounting
}

Record is persisted secure-session state (no raw resume token).

type ResumeToken

type ResumeToken string

ResumeToken is a bearer resume proof (never persist in store records; use TokenFingerprint).

type SessionID

type SessionID string

SessionID is a proxy-owned opaque session identifier.

type SessionStatus

type SessionStatus string

SessionStatus is the lifecycle status of a secure session.

const (
	SessionStatusActive      SessionStatus = "active"
	SessionStatusQuarantined SessionStatus = "quarantined"
)

func (SessionStatus) IsActive

func (s SessionStatus) IsActive() bool

IsActive reports whether s is active. Empty status is treated as active for pre-migration rows until Phase 5 writes an explicit active value.

func (SessionStatus) IsQuarantined

func (s SessionStatus) IsQuarantined() bool

IsQuarantined reports whether s is the terminal quarantined status.

type Summary

type Summary struct {
	SessionID      SessionID
	OwnerID        string
	WorkspaceID    string
	LastActivityAt time.Time
	TurnCount      int
	AttemptCount   int

	Status            SessionStatus
	ResumeEligible    bool
	ALegID            string
	PolicyVersion     string
	TranscriptEnabled bool
	RedactionProfile  string
	AuditMode         string
	UsageInputTokens  int64
	UsageOutputTokens int64
}

Summary is a roll-up row for operator views.

type SummaryQuery

type SummaryQuery struct {
	OwnerID     string
	WorkspaceID string
	Limit       int
}

SummaryQuery filters session summaries for operators.

type SurfaceState

type SurfaceState string

SurfaceState describes how a backend attempt was exposed to the client.

const (
	SurfaceSurfaced  SurfaceState = "surfaced"
	SurfaceSwallowed SurfaceState = "swallowed"
	SurfaceFailed    SurfaceState = "failed"
	SurfaceTimeout   SurfaceState = "timeout"
)

type TokenFingerprint

type TokenFingerprint [32]byte

TokenFingerprint is the stored HMAC-SHA-256 digest of a resume token.

func (TokenFingerprint) Equal

Equal reports whether a and b are the same fingerprint in constant time.

type TranscriptItem

type TranscriptItem struct {
	SessionID  SessionID
	TurnID     TurnID
	Seq        int64
	EventKind  string
	PayloadRef string
	CreatedAt  time.Time
}

TranscriptItem is one ordered transcript entry.

type TurnID

type TurnID string

TurnID identifies a user turn within a session.

type UsageDelta

type UsageDelta struct {
	SessionID SessionID
	TurnID    TurnID
	BLegID    string

	InputTokens  int64
	OutputTokens int64

	CacheReadTokens          int64
	CacheWriteTokens         int64
	NonCachedInputTokens     int64
	ReasoningTokens          int64
	NonReasoningOutputTokens int64
	TotalTokens              int64
	CostNanoUnits            int64
	CostMinorUnits           int64
	Currency                 string
	CostSource               string
	RawUsageJSON             string
	BillingUnavailable       bool

	RequestStartedAt         time.Time
	FirstRemoteEventAt       time.Time
	FirstMeaningfulTokenAt   time.Time
	RemoteCompletedAt        time.Time
	ProxyCompletedAt         time.Time
	TTFTMillis               int64
	RemoteDurationMillis     int64
	CompletionDurationMillis int64
	// CompletionTPSMilli stores tokens-per-second with milliprecision: 5000 means 5.000 TPS.
	CompletionTPSMilli int64
}

UsageDelta increments per-session usage and optional per-attempt accounting fields.

type UsageTotals

type UsageTotals struct {
	SessionID    SessionID
	InputTokens  int64
	OutputTokens int64
	Attempts     int
}

UsageTotals aggregates usage for summaries and diagnostics.

type WorkspaceRef

type WorkspaceRef struct {
	ID string
}

WorkspaceRef is an optional workspace scope for policy and isolation.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL