Public declaration syntax from forge-swift/Sources/ForgeAuth/Capability.swift Original source SHA-256: 11fa455cdb39630cec545788c50e004aade3029d998b58fa4daec2e61e8ddcb1 Function bodies and constant values are omitted. This is not the complete implementation. Source line 23 public struct ToolPattern: Codable, Sendable, Equatable, Hashable Source line 25 public let pattern: String /// Creates a new tool pattern. /// /// - Parameter pattern: The pattern string. Use `*` for wildcard matching. public init(_ pattern: String) Source line 30 public init(_ pattern: String) Source line 43 public func matches(_ toolName: String) -> Bool Source line 54 public init(from decoder: Decoder) throws Source line 59 public func encode(to encoder: Encoder) throws Source line 73 public struct Capability: Codable, Sendable, Equatable Source line 75 public let toolPattern: ToolPattern /// An optional human-readable label for this capability. public let label: String? /// Optional scope string in `service:resource:action` format. /// /// When present, this is the canonical scope string used for ACT scope /// matching. When absent, the scope is derived from the tool pattern /// as `forge:tool.:execute`. public let scope: String? /// Creates a new capability. /// /// - Parameters: /// - toolPattern: The tool name pattern. /// - label: An optional human-readable label. /// - scope: An optional scope string in `service:resource:action` format. public init(toolPattern: ToolPattern, label: String?; Source line 78 public let label: String? /// Optional scope string in `service:resource:action` format. /// /// When present, this is the canonical scope string used for ACT scope /// matching. When absent, the scope is derived from the tool pattern /// as `forge:tool.:execute`. public let scope: String? /// Creates a new capability. /// /// - Parameters: /// - toolPattern: The tool name pattern. /// - label: An optional human-readable label. /// - scope: An optional scope string in `service:resource:action` format. public init(toolPattern: ToolPattern, label: String?; Source line 85 public let scope: String? /// Creates a new capability. /// /// - Parameters: /// - toolPattern: The tool name pattern. /// - label: An optional human-readable label. /// - scope: An optional scope string in `service:resource:action` format. public init(toolPattern: ToolPattern, label: String?; Source line 93 public init(toolPattern: ToolPattern, label: String?; Source line 103 public static func tool(_ toolName: String) -> Capability Source line 113 public static func wildcard() -> Capability Source line 129 public struct ArsenalACT: Codable, Sendable, Equatable Source line 131 public let id: String /// The OAS DID of the agent this token is issued to. public let agentDid: String /// The issuer identifier. public let issuer: String /// The audience identifier. public let audience: String /// The capabilities granted by this token. public let capabilities: [Capability] /// The scope strings granted by this token (in `service:resource:action` format). /// /// These are the canonical scopes used for scope matching. If a capability has /// an explicit scope, it is included here. Otherwise, the scope is derived from /// the tool pattern. public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp Source line 134 public let agentDid: String /// The issuer identifier. public let issuer: String /// The audience identifier. public let audience: String /// The capabilities granted by this token. public let capabilities: [Capability] /// The scope strings granted by this token (in `service:resource:action` format). /// /// These are the canonical scopes used for scope matching. If a capability has /// an explicit scope, it is included here. Otherwise, the scope is derived from /// the tool pattern. public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? Source line 137 public let issuer: String /// The audience identifier. public let audience: String /// The capabilities granted by this token. public let capabilities: [Capability] /// The scope strings granted by this token (in `service:resource:action` format). /// /// These are the canonical scopes used for scope matching. If a capability has /// an explicit scope, it is included here. Otherwise, the scope is derived from /// the tool pattern. public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? Source line 140 public let audience: String /// The capabilities granted by this token. public let capabilities: [Capability] /// The scope strings granted by this token (in `service:resource:action` format). /// /// These are the canonical scopes used for scope matching. If a capability has /// an explicit scope, it is included here. Otherwise, the scope is derived from /// the tool pattern. public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool Source line 143 public let capabilities: [Capability] /// The scope strings granted by this token (in `service:resource:action` format). /// /// These are the canonical scopes used for scope matching. If a capability has /// an explicit scope, it is included here. Otherwise, the scope is derived from /// the tool pattern. public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 Source line 150 public let scopes: [String] /// When the token was issued. public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: Source line 153 public let issuedAt: Timestamp /// When the token becomes valid (not-before). public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. Source line 156 public let notBefore: Timestamp /// When the token expires, or `nil` for non-expiring tokens. public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. Source line 159 public let expiresAt: Timestamp? /// The parent token ID if this token was delegated. public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. /// - issuedAt: When the token was issued. /// - notBefore: When the token becomes valid. /// - expiresAt: When the token expires, or nil. Source line 162 public let parentTokenId: String? /// Whether delegation is allowed from this token. public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. /// - issuedAt: When the token was issued. /// - notBefore: When the token becomes valid. /// - expiresAt: When the token expires, or nil. /// - parentTokenId: The parent token ID for delegated tokens. /// - allowDelegation: Whether delegation is allowed. /// - maxDelegationDepth: Maximum delegation depth. Source line 165 public let allowDelegation: Bool /// Maximum delegation depth permitted from this token. public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. /// - issuedAt: When the token was issued. /// - notBefore: When the token becomes valid. /// - expiresAt: When the token expires, or nil. /// - parentTokenId: The parent token ID for delegated tokens. /// - allowDelegation: Whether delegation is allowed. /// - maxDelegationDepth: Maximum delegation depth. /// - minTtlReduction: Minimum TTL reduction for delegation (seconds). public init( id: String, Source line 168 public let maxDelegationDepth: UInt32 /// Minimum TTL reduction (in seconds) when delegating to child tokens. public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. /// - issuedAt: When the token was issued. /// - notBefore: When the token becomes valid. /// - expiresAt: When the token expires, or nil. /// - parentTokenId: The parent token ID for delegated tokens. /// - allowDelegation: Whether delegation is allowed. /// - maxDelegationDepth: Maximum delegation depth. /// - minTtlReduction: Minimum TTL reduction for delegation (seconds). public init( id: String, agentDid: String, issuer: String, audience: String, Source line 171 public let minTtlReduction: Int64 /// Creates a new Arsenal ACT. /// /// - Parameters: /// - id: Unique token identifier. /// - agentDid: The agent's OAS DID. /// - issuer: The issuer identifier. /// - audience: The audience identifier. /// - capabilities: The capabilities granted. /// - scopes: The scope strings granted. /// - issuedAt: When the token was issued. /// - notBefore: When the token becomes valid. /// - expiresAt: When the token expires, or nil. /// - parentTokenId: The parent token ID for delegated tokens. /// - allowDelegation: Whether delegation is allowed. /// - maxDelegationDepth: Maximum delegation depth. /// - minTtlReduction: Minimum TTL reduction for delegation (seconds). public init( id: String, agentDid: String, issuer: String, audience: String, capabilities: [Capability], scopes: [String], issuedAt: Timestamp; Source line 189 public init( id: String, agentDid: String, issuer: String, audience: String, capabilities: [Capability], scopes: [String], issuedAt: Timestamp; Source line 220 public var isExpired: Bool Source line 226 public var remainingTtlSeconds: Int64? Source line 252 public func verifyACT(_ act: ArsenalACT) throws Source line 298 public func extractScopes(_ act: ArsenalACT) -> [String] Source line 329 public func actAllowsScope(_ act: ArsenalACT, scope: String) throws -> Bool