TokenScope
Defined in: src/http/token.ts:32
Everything the AEAD associated data of a state or call token is bound to.
Passed as one object rather than four positional strings because every field is a string and a transposition would still compile – and a token bound to the wrong scope fails open in the only direction that matters: it opens.
Properties
Section titled “Properties”domain?
Section titled “domain?”optional domain?: string | null;Defined in: src/http/token.ts:52
Authentication domain of the issuing principal.
evidenceBinding?
Section titled “evidenceBinding?”optional evidenceBinding?: string;Defined in: src/http/token.ts:50
Digest of the resolved transport-peer evidence, when there is any. Its presence selects the bound AAD prefix.
principal
Section titled “principal”principal: string | null | undefined;Defined in: src/http/token.ts:47
The issuing principal; null for an anonymous caller. An authenticator
that deliberately uses an empty principal is still authenticated, and the
empty string and null produce different AAD.
protocol
Section titled “protocol”protocol: string;Defined in: src/http/token.ts:43
Wire name of the protocol that owns the stream, or SERVER_SCOPE.
Bound into the AAD rather than carried in the plaintext so a cross-protocol continuation fails the AEAD tag check – rejected exactly as an invalid token, with no comparison code to get wrong and nothing to forget on the call-state cache-hit path, where the call token is never opened at all. The cursor is always opened first, so binding it here covers both paths.
