steps

package
v0.2.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 24, 2026 License: MIT Imports: 14 Imported by: 0

Documentation

Overview

Package steps implements the seven audit-chain step types as typed proto handlers. All handler functions satisfy sdk.TypedStepHandler and are wired into sdk.TypedStepFactory instances in internal/plugin.go.

Zero map[string]any: every handler receives a typed *auditv1.* input and returns a typed *auditv1.* output via sdk.TypedStepResult.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AnchorHandler

AnchorHandler is the TypedStepHandler for step.audit.anchor. It computes the Merkle root over the requested sequence range, submits it to each configured anchor provider, and records the pending anchors in audit_anchors.

func AppendHandler

AppendHandler is the TypedStepHandler for step.audit.append. It appends one hash-chained entry to the named ledger and returns the assigned sequence number, entry hash, and server-side timestamp.

func ApplyRedactions

func ApplyRedactions(payload []byte, redactFields []string) ([]byte, map[string]string, error)

ApplyRedactions replaces the listed top-level JSON keys in payload with stable per-receipt pseudonyms of the form "contributor_N", where N increments once per unique original value within this receipt's scope (duplicate original values receive the same pseudonym). The field is REPLACED (not deleted) so the payload structure is preserved. Returns the modified payload bytes, a field→pseudonym mapping, and any error. Exported so it can be tested independently.

func MerkleRootHandler

MerkleRootHandler is the TypedStepHandler for step.audit.merkle_root. It reads the entry hashes for the requested sequence range, builds a binary Merkle tree using RFC 6962 leaf/node hashing, and returns the root.

func PollAnchorConfirmationHandler

PollAnchorConfirmationHandler is the TypedStepHandler for step.audit.poll_anchor_confirmation.

Swallow-transient-errors contract (§ 3.5c):

  • Transient errors (network, 5xx, calendar unreachable) → successful response with swallowed = true, error_message set, confirmation unchanged.
  • Hard errors (invalid proof, 4xx semantic rejection) → gRPC error (returned as a non-nil error from this handler).

BMW-style YAML pipelines supply all parameters via the step's `config:` block, so the handler reads from req.Config first and falls back to req.Input for direct (integration-test) gRPC dispatch.

func ProofHandler

ProofHandler is the TypedStepHandler for step.audit.proof. It fetches the entry at the requested sequence, finds all anchors covering that sequence, and builds a Merkle inclusion proof for the first covering anchor range.

func PublicReceiptHandler

PublicReceiptHandler is the TypedStepHandler for step.audit.public_receipt. It builds a self-contained verifiable receipt JSON that includes the audit entry, its Merkle inclusion proof, all covering anchor records, and an optional pseudonymisation map for redacted payload fields.

BMW-style YAML pipelines supply all parameters via the step's `config:` block, so the handler reads from req.Config first and falls back to req.Input for direct (integration-test) gRPC dispatch.

func VerifyHandler

VerifyHandler is the TypedStepHandler for step.audit.verify. It scans the audit_log table in the requested sequence range and re-derives each entry hash, checking both hash integrity and chain linkage.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL