Skip to content

Commit d8aaeed

Browse files
committed
Revert "Rust SDK: Add authenticated cross-session input producer"
This reverts commit dc77d92.
1 parent 403b5c7 commit d8aaeed

3 files changed

Lines changed: 6 additions & 557 deletions

File tree

‎rust/src/session.rs‎

Lines changed: 0 additions & 38 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,6 @@ use crate::session_fs::SessionFsProvider;
3737
use crate::trace_context::inject_trace_context;
3838
use crate::transforms::SystemMessageTransform;
3939
use crate::types::{
40-
AdmitAuthenticatedCrossSessionInputParams, AdmitAuthenticatedCrossSessionInputRequest,
4140
AutoTier, AutoTierPreference, CommandContext, CommandDefinition, CommandHandler,
4241
CreateSessionResult, ElicitationRequest, ElicitationResult, ExitPlanModeData,
4342
GetMessagesResponse, MessageOptions, PermissionRequestData, RequestId, ResumeSessionConfig,
@@ -746,43 +745,6 @@ impl Session {
746745
}
747746
}
748747

749-
/// Admit an authenticated cross-session input into this session.
750-
///
751-
/// Wraps the runtime's private, direct-host-only
752-
/// `session.lifecycle.admitAuthenticatedCrossSessionInput` method. The
753-
/// runtime rejects the call unless it arrives on the local direct
754-
/// connection, so this is only usable by a host embedding the SDK
755-
/// in-process (or over the direct local transport), not by a remote peer.
756-
///
757-
/// The caller supplies only the variable fields of
758-
/// [`CrossSessionInput`](crate::types::CrossSessionInput). The wire
759-
/// payload's `version`, `kind`, `origin`, and `integrity` discriminators
760-
/// are stamped by the SDK, so a caller cannot assert a different
761-
/// provenance or integrity class for the admitted content.
762-
///
763-
/// The runtime's response carries no payload this SDK surfaces; errors
764-
/// from the runtime are returned unchanged.
765-
///
766-
/// # Cancel safety
767-
///
768-
/// **Cancel-safe.** Single RPC dispatched through the writer-actor (see
769-
/// [`Client::call`](crate::Client::call)). If the caller's future is
770-
/// dropped after the frame is enqueued, the admission still lands and
771-
/// the runtime processes it normally.
772-
pub async fn admit_authenticated_cross_session_input(
773-
&self,
774-
request: AdmitAuthenticatedCrossSessionInputRequest,
775-
) -> Result<(), Error> {
776-
let params = AdmitAuthenticatedCrossSessionInputParams::new(self.id.clone(), request);
777-
self.client
778-
.call(
779-
"session.lifecycle.admitAuthenticatedCrossSessionInput",
780-
Some(serde_json::to_value(params)?),
781-
)
782-
.await?;
783-
Ok(())
784-
}
785-
786748
/// Retrieve the session's timeline events.
787749
pub async fn get_events(&self) -> Result<Vec<SessionEvent>, Error> {
788750
let result = self

‎rust/src/types.rs‎

Lines changed: 0 additions & 301 deletions
Original file line numberDiff line numberDiff line change
@@ -5605,307 +5605,6 @@ impl From<&String> for MessageOptions {
56055605
}
56065606
}
56075607

5608-
/// Wire `version` stamped on every authenticated cross-session admission
5609-
/// request. The runtime rejects any other value.
5610-
const CROSS_SESSION_INPUT_VERSION: u32 = 1;
5611-
5612-
/// Wire `kind` discriminator stamped on every authenticated cross-session
5613-
/// admission request.
5614-
const CROSS_SESSION_INPUT_KIND: &str = "authenticated-cross-session";
5615-
5616-
/// Wire `origin` provenance class stamped on every authenticated
5617-
/// cross-session admission request. Cross-session input is never human
5618-
/// input, so the SDK — not the caller — asserts the non-human origin.
5619-
const CROSS_SESSION_INPUT_ORIGIN: &str = "authenticated-cross-session";
5620-
5621-
/// Wire `integrity` class stamped on every authenticated cross-session
5622-
/// admission request. Cross-session content is untrusted even when the
5623-
/// host authenticated its sender, so the SDK — not the caller — asserts it.
5624-
const CROSS_SESSION_INPUT_INTEGRITY: &str = "untrusted";
5625-
5626-
/// Optional private presentation metadata describing the sending session,
5627-
/// carried alongside a [`CrossSessionInput`].
5628-
///
5629-
/// Every field is optional and is omitted from the wire payload when `None`.
5630-
/// The runtime rejects explicit `null` for any of these fields.
5631-
#[derive(Debug, Clone, Default, PartialEq, Eq)]
5632-
#[non_exhaustive]
5633-
pub struct CrossSessionPresentation {
5634-
/// Identifier of the sending project session.
5635-
pub project_session_id: Option<String>,
5636-
/// Human-readable name of the sending project session.
5637-
pub project_session_name: Option<String>,
5638-
/// Display name shown for the sender.
5639-
pub display_name: Option<String>,
5640-
/// Branch the sending project session is working on.
5641-
pub project_session_branch: Option<String>,
5642-
/// Repository the sending project session is working in.
5643-
pub repository: Option<String>,
5644-
}
5645-
5646-
impl CrossSessionPresentation {
5647-
/// Build an empty presentation block. Every field is omitted until set.
5648-
pub fn new() -> Self {
5649-
Self::default()
5650-
}
5651-
5652-
/// Set the sending project session's identifier.
5653-
pub fn with_project_session_id(mut self, project_session_id: impl Into<String>) -> Self {
5654-
self.project_session_id = Some(project_session_id.into());
5655-
self
5656-
}
5657-
5658-
/// Set the sending project session's name.
5659-
pub fn with_project_session_name(mut self, project_session_name: impl Into<String>) -> Self {
5660-
self.project_session_name = Some(project_session_name.into());
5661-
self
5662-
}
5663-
5664-
/// Set the display name shown for the sender.
5665-
pub fn with_display_name(mut self, display_name: impl Into<String>) -> Self {
5666-
self.display_name = Some(display_name.into());
5667-
self
5668-
}
5669-
5670-
/// Set the sending project session's branch.
5671-
pub fn with_project_session_branch(mut self, branch: impl Into<String>) -> Self {
5672-
self.project_session_branch = Some(branch.into());
5673-
self
5674-
}
5675-
5676-
/// Set the sending project session's repository.
5677-
pub fn with_repository(mut self, repository: impl Into<String>) -> Self {
5678-
self.repository = Some(repository.into());
5679-
self
5680-
}
5681-
}
5682-
5683-
/// The caller-supplied half of an authenticated cross-session input.
5684-
///
5685-
/// This type deliberately carries only the fields a host may vary. The
5686-
/// wire payload's `version`, `kind`, `origin`, and `integrity`
5687-
/// discriminators are stamped by the SDK during request conversion and are
5688-
/// not reachable from this type, so a caller cannot claim a different
5689-
/// provenance or integrity class.
5690-
#[derive(Debug, Clone, PartialEq, Eq)]
5691-
#[non_exhaustive]
5692-
pub struct CrossSessionInput {
5693-
/// Stable identifier assigned by the sending host for this message.
5694-
pub message_id: String,
5695-
/// Authenticated same-user principal supplied by the sending host.
5696-
pub sender_principal: String,
5697-
/// Session identifier of the sender.
5698-
pub sender_session_id: String,
5699-
/// Host-stamped immediate sender identity used to check that a reply
5700-
/// stays on the established edge.
5701-
pub reply_target: String,
5702-
/// Raw natural-language message content.
5703-
pub content: String,
5704-
/// Optional recipient behavior request, distinct from
5705-
/// [`delivery_mode`](Self::delivery_mode). Omitted when `None`.
5706-
pub requested_mode: Option<String>,
5707-
/// Optional private presentation metadata. Omitted when `None`.
5708-
pub presentation: Option<CrossSessionPresentation>,
5709-
/// Optional scheduling selection. Omitted when `None`, which preserves
5710-
/// the recipient session's current default.
5711-
pub delivery_mode: Option<DeliveryMode>,
5712-
}
5713-
5714-
impl CrossSessionInput {
5715-
/// Build a cross-session input from its required fields.
5716-
pub fn new(
5717-
message_id: impl Into<String>,
5718-
sender_principal: impl Into<String>,
5719-
sender_session_id: impl Into<String>,
5720-
reply_target: impl Into<String>,
5721-
content: impl Into<String>,
5722-
) -> Self {
5723-
Self {
5724-
message_id: message_id.into(),
5725-
sender_principal: sender_principal.into(),
5726-
sender_session_id: sender_session_id.into(),
5727-
reply_target: reply_target.into(),
5728-
content: content.into(),
5729-
requested_mode: None,
5730-
presentation: None,
5731-
delivery_mode: None,
5732-
}
5733-
}
5734-
5735-
/// Set the optional recipient behavior request.
5736-
pub fn with_requested_mode(mut self, requested_mode: impl Into<String>) -> Self {
5737-
self.requested_mode = Some(requested_mode.into());
5738-
self
5739-
}
5740-
5741-
/// Attach optional private presentation metadata.
5742-
pub fn with_presentation(mut self, presentation: CrossSessionPresentation) -> Self {
5743-
self.presentation = Some(presentation);
5744-
self
5745-
}
5746-
5747-
/// Set the optional delivery mode for this admission.
5748-
pub fn with_delivery_mode(mut self, delivery_mode: DeliveryMode) -> Self {
5749-
self.delivery_mode = Some(delivery_mode);
5750-
self
5751-
}
5752-
}
5753-
5754-
/// Recipient-side per-turn continuation context supplied by the local host.
5755-
///
5756-
/// This is never transmitted between sessions and is never populated from a
5757-
/// remote sender's payload.
5758-
#[derive(Debug, Clone, Default, PartialEq, Eq)]
5759-
#[non_exhaustive]
5760-
pub struct CrossSessionRecipientContext {
5761-
/// Session identifiers this turn is authorized to continue with.
5762-
pub authorized_continuation_targets: Vec<String>,
5763-
}
5764-
5765-
impl CrossSessionRecipientContext {
5766-
/// Build a recipient context from a set of authorized continuation targets.
5767-
pub fn new(targets: impl IntoIterator<Item = impl Into<String>>) -> Self {
5768-
Self {
5769-
authorized_continuation_targets: targets.into_iter().map(Into::into).collect(),
5770-
}
5771-
}
5772-
}
5773-
5774-
/// Request for
5775-
/// [`Session::admit_authenticated_cross_session_input`](crate::session::Session::admit_authenticated_cross_session_input).
5776-
#[derive(Debug, Clone, PartialEq, Eq)]
5777-
#[non_exhaustive]
5778-
pub struct AdmitAuthenticatedCrossSessionInputRequest {
5779-
/// The authenticated cross-session input to admit.
5780-
pub input: CrossSessionInput,
5781-
/// Optional recipient-side continuation context. Omitted when `None`.
5782-
pub recipient_context: Option<CrossSessionRecipientContext>,
5783-
}
5784-
5785-
impl AdmitAuthenticatedCrossSessionInputRequest {
5786-
/// Build a request that admits `input` with no extra recipient context.
5787-
pub fn new(input: CrossSessionInput) -> Self {
5788-
Self {
5789-
input,
5790-
recipient_context: None,
5791-
}
5792-
}
5793-
5794-
/// Attach recipient-side continuation context.
5795-
pub fn with_recipient_context(mut self, context: CrossSessionRecipientContext) -> Self {
5796-
self.recipient_context = Some(context);
5797-
self
5798-
}
5799-
}
5800-
5801-
/// Wire params for `session.lifecycle.admitAuthenticatedCrossSessionInput`.
5802-
#[derive(Debug, Serialize)]
5803-
#[serde(rename_all = "camelCase")]
5804-
pub(crate) struct AdmitAuthenticatedCrossSessionInputParams {
5805-
session_id: SessionId,
5806-
input: CrossSessionInputWire,
5807-
#[serde(skip_serializing_if = "Option::is_none")]
5808-
recipient_context: Option<CrossSessionRecipientContextWire>,
5809-
}
5810-
5811-
impl AdmitAuthenticatedCrossSessionInputParams {
5812-
pub(crate) fn new(
5813-
session_id: SessionId,
5814-
request: AdmitAuthenticatedCrossSessionInputRequest,
5815-
) -> Self {
5816-
Self {
5817-
session_id,
5818-
input: CrossSessionInputWire::from(request.input),
5819-
recipient_context: request.recipient_context.map(Into::into),
5820-
}
5821-
}
5822-
}
5823-
5824-
/// Wire form of [`CrossSessionInput`]. The provenance and integrity
5825-
/// discriminators are private and stamped here, so no caller-provided value
5826-
/// can reach them.
5827-
#[derive(Debug, Serialize)]
5828-
#[serde(rename_all = "camelCase")]
5829-
struct CrossSessionInputWire {
5830-
version: u32,
5831-
kind: &'static str,
5832-
origin: &'static str,
5833-
integrity: &'static str,
5834-
message_id: String,
5835-
sender_principal: String,
5836-
sender_session_id: String,
5837-
reply_target: String,
5838-
content: String,
5839-
#[serde(skip_serializing_if = "Option::is_none")]
5840-
requested_mode: Option<String>,
5841-
#[serde(skip_serializing_if = "Option::is_none")]
5842-
presentation: Option<CrossSessionPresentationWire>,
5843-
#[serde(skip_serializing_if = "Option::is_none")]
5844-
delivery_mode: Option<DeliveryMode>,
5845-
}
5846-
5847-
impl From<CrossSessionInput> for CrossSessionInputWire {
5848-
fn from(input: CrossSessionInput) -> Self {
5849-
Self {
5850-
version: CROSS_SESSION_INPUT_VERSION,
5851-
kind: CROSS_SESSION_INPUT_KIND,
5852-
origin: CROSS_SESSION_INPUT_ORIGIN,
5853-
integrity: CROSS_SESSION_INPUT_INTEGRITY,
5854-
message_id: input.message_id,
5855-
sender_principal: input.sender_principal,
5856-
sender_session_id: input.sender_session_id,
5857-
reply_target: input.reply_target,
5858-
content: input.content,
5859-
requested_mode: input.requested_mode,
5860-
presentation: input.presentation.map(Into::into),
5861-
delivery_mode: input.delivery_mode,
5862-
}
5863-
}
5864-
}
5865-
5866-
/// Wire form of [`CrossSessionPresentation`].
5867-
#[derive(Debug, Serialize)]
5868-
#[serde(rename_all = "camelCase")]
5869-
struct CrossSessionPresentationWire {
5870-
#[serde(skip_serializing_if = "Option::is_none")]
5871-
project_session_id: Option<String>,
5872-
#[serde(skip_serializing_if = "Option::is_none")]
5873-
project_session_name: Option<String>,
5874-
#[serde(skip_serializing_if = "Option::is_none")]
5875-
display_name: Option<String>,
5876-
#[serde(skip_serializing_if = "Option::is_none")]
5877-
project_session_branch: Option<String>,
5878-
#[serde(skip_serializing_if = "Option::is_none")]
5879-
repository: Option<String>,
5880-
}
5881-
5882-
impl From<CrossSessionPresentation> for CrossSessionPresentationWire {
5883-
fn from(presentation: CrossSessionPresentation) -> Self {
5884-
Self {
5885-
project_session_id: presentation.project_session_id,
5886-
project_session_name: presentation.project_session_name,
5887-
display_name: presentation.display_name,
5888-
project_session_branch: presentation.project_session_branch,
5889-
repository: presentation.repository,
5890-
}
5891-
}
5892-
}
5893-
5894-
/// Wire form of [`CrossSessionRecipientContext`].
5895-
#[derive(Debug, Serialize)]
5896-
#[serde(rename_all = "camelCase")]
5897-
struct CrossSessionRecipientContextWire {
5898-
authorized_continuation_targets: Vec<String>,
5899-
}
5900-
5901-
impl From<CrossSessionRecipientContext> for CrossSessionRecipientContextWire {
5902-
fn from(context: CrossSessionRecipientContext) -> Self {
5903-
Self {
5904-
authorized_continuation_targets: context.authorized_continuation_targets,
5905-
}
5906-
}
5907-
}
5908-
59095608
/// Response from [`Client::get_status`](crate::Client::get_status).
59105609
#[derive(Debug, Clone, Serialize, Deserialize)]
59115610
#[serde(rename_all = "camelCase")]

0 commit comments

Comments
 (0)