Documentation
¶
Overview ¶
Package steps implements the seven audit-chain step types as typed proto handlers. All handler functions satisfy sdk.TypedStepHandler and are wired into sdk.TypedStepFactory instances in internal/plugin.go.
Zero map[string]any: every handler receives a typed *auditv1.* input and returns a typed *auditv1.* output via sdk.TypedStepResult.
Index ¶
- func AnchorHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.AnchorResponse], error)
- func AppendHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.AppendResponse], error)
- func ApplyRedactions(payload []byte, redactFields []string) ([]byte, map[string]string, error)
- func MerkleRootHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.MerkleRootResponse], error)
- func PollAnchorConfirmationHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.PollAnchorConfirmationResponse], error)
- func ProofHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.ProofResponse], error)
- func PublicReceiptHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.PublicReceiptResponse], error)
- func VerifyHandler(ctx context.Context, ...) (*sdk.TypedStepResult[*auditv1.VerifyResponse], error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AnchorHandler ¶
func AnchorHandler( ctx context.Context, req sdk.TypedStepRequest[*emptypb.Empty, *auditv1.AnchorRequest], ) (*sdk.TypedStepResult[*auditv1.AnchorResponse], error)
AnchorHandler is the TypedStepHandler for step.audit.anchor. It computes the Merkle root over the requested sequence range, submits it to each configured anchor provider, and records the pending anchors in audit_anchors.
func AppendHandler ¶
func AppendHandler( ctx context.Context, req sdk.TypedStepRequest[*emptypb.Empty, *auditv1.AppendRequest], ) (*sdk.TypedStepResult[*auditv1.AppendResponse], error)
AppendHandler is the TypedStepHandler for step.audit.append. It appends one hash-chained entry to the named ledger and returns the assigned sequence number, entry hash, and server-side timestamp.
func ApplyRedactions ¶
ApplyRedactions replaces the listed top-level JSON keys in payload with stable per-receipt pseudonyms of the form "contributor_N", where N increments once per unique original value within this receipt's scope (duplicate original values receive the same pseudonym). The field is REPLACED (not deleted) so the payload structure is preserved. Returns the modified payload bytes, a field→pseudonym mapping, and any error. Exported so it can be tested independently.
func MerkleRootHandler ¶
func MerkleRootHandler( ctx context.Context, req sdk.TypedStepRequest[*emptypb.Empty, *auditv1.MerkleRootRequest], ) (*sdk.TypedStepResult[*auditv1.MerkleRootResponse], error)
MerkleRootHandler is the TypedStepHandler for step.audit.merkle_root. It reads the entry hashes for the requested sequence range, builds a binary Merkle tree using RFC 6962 leaf/node hashing, and returns the root.
func PollAnchorConfirmationHandler ¶
func PollAnchorConfirmationHandler( ctx context.Context, req sdk.TypedStepRequest[*auditv1.PollAnchorConfirmationConfig, *auditv1.PollAnchorConfirmationRequest], ) (*sdk.TypedStepResult[*auditv1.PollAnchorConfirmationResponse], error)
PollAnchorConfirmationHandler is the TypedStepHandler for step.audit.poll_anchor_confirmation.
Swallow-transient-errors contract (§ 3.5c):
- Transient errors (network, 5xx, calendar unreachable) → successful response with swallowed = true, error_message set, confirmation unchanged.
- Hard errors (invalid proof, 4xx semantic rejection) → gRPC error (returned as a non-nil error from this handler).
BMW-style YAML pipelines supply all parameters via the step's `config:` block, so the handler reads from req.Config first and falls back to req.Input for direct (integration-test) gRPC dispatch.
func ProofHandler ¶
func ProofHandler( ctx context.Context, req sdk.TypedStepRequest[*emptypb.Empty, *auditv1.ProofRequest], ) (*sdk.TypedStepResult[*auditv1.ProofResponse], error)
ProofHandler is the TypedStepHandler for step.audit.proof. It fetches the entry at the requested sequence, finds all anchors covering that sequence, and builds a Merkle inclusion proof for the first covering anchor range.
func PublicReceiptHandler ¶
func PublicReceiptHandler( ctx context.Context, req sdk.TypedStepRequest[*auditv1.PublicReceiptConfig, *auditv1.PublicReceiptRequest], ) (*sdk.TypedStepResult[*auditv1.PublicReceiptResponse], error)
PublicReceiptHandler is the TypedStepHandler for step.audit.public_receipt. It builds a self-contained verifiable receipt JSON that includes the audit entry, its Merkle inclusion proof, all covering anchor records, and an optional pseudonymisation map for redacted payload fields.
BMW-style YAML pipelines supply all parameters via the step's `config:` block, so the handler reads from req.Config first and falls back to req.Input for direct (integration-test) gRPC dispatch.
func VerifyHandler ¶
func VerifyHandler( ctx context.Context, req sdk.TypedStepRequest[*emptypb.Empty, *auditv1.VerifyRequest], ) (*sdk.TypedStepResult[*auditv1.VerifyResponse], error)
VerifyHandler is the TypedStepHandler for step.audit.verify. It scans the audit_log table in the requested sequence range and re-derives each entry hash, checking both hash integrity and chain linkage.
Types ¶
This section is empty.