From de2e83382154d1e0d666b0471af5534d90b4f12b Mon Sep 17 00:00:00 2001 From: Hong Minhee Date: Wed, 23 Sep 2026 01:54:25 +0900 Subject: [PATCH 1/2] Preserve signed child JSON when serializing Signing a Note with signObject(), assigning it to a typed Create and serializing the parent used to rebuild the child under the parent's JSON-LD context. The child kept its proofValue but lost its own document and proof contexts, so the extracted child no longer verified, while the outer proof stayed valid over the mangled child. Producing a FEP-ef61 compound document therefore meant assembling the JSON by hand. signObject() now captures the secured JSON document its proof covers and keeps it on the object it returns. The document is not re-derived from the vocabulary object: it is the value createProof() hashed, plus the serialized proof, checked against the message digest, the proof configuration digest and the proof value, so a captured document verifies by construction. Nested serialization emits a placeholder node reference for a child that carries one, and the outermost toJsonLd() frame puts the captured document back after compaction. Placeholders are used on both encoder paths, because an ancestor frame may still compact a value that an inner frame embedded. The captured document is a snapshot, independent of anything done to the returned object afterwards. clone() never carries it, since a clone may differ from the document the proof covers. Retention is skipped, and ordinary serialization applies, for an object parsed with fromJsonLd(), an object that already carried a proof, a document too large or too deep to validate, and a toJsonLd() context that could hide the placeholder. A placeholder that cannot be put back throws rather than reaching the wire. Two adjacent paths could still destroy a secured child: - Outgoing JSON-LD compatibility normalization rewrote nested documents. It now leaves a nested self-contained secured document untouched under an opt-in option that only the producer path passes, so verifyProof()'s inbound fallback is unchanged. - Fanout reparsed the activity and serialized it again. It now reuses the document the activity was already serialized into, and an explicit Ed25519 sender's activity is signed before that serialization rather than by the delivery worker, while the typed child still carries its snapshot. An activity that already has a proof keeps its own. Fixes https://github.com/fedify-dev/fedify/issues/1044 https://github.com/fedify-dev/fedify/issues/288 https://github.com/fedify-dev/fedify/pull/1041 Assisted-by: Claude Code:claude-opus-5 Assisted-by: OpenCode:deepseek-flash Assisted-by: Codex:gpt-6-astra Assisted-by: Claude Code:claude-fable-5-1 --- CHANGES.md | 32 + .../fedify/signed-child-representation.md | 31 + .../vocab/signed-child-representation.md | 12 + docs/manual/send.md | 92 +- .../fedify/src/compat/outgoing-jsonld.test.ts | 111 + packages/fedify/src/compat/outgoing-jsonld.ts | 27 +- packages/fedify/src/compat/public-audience.ts | 38 +- .../src/compat/secured-document.test.ts | 79 + .../fedify/src/compat/secured-document.ts | 63 + .../src/federation/compound-fanout.test.ts | 308 +++ packages/fedify/src/federation/middleware.ts | 50 +- .../fedify/src/sig/compound-proof.test.ts | 313 ++- packages/fedify/src/sig/proof.ts | 180 +- packages/vocab-runtime/deno.json | 1 + packages/vocab-runtime/package.json | 10 + .../src/internal/signed-representation.ts | 565 ++++ .../src/signed-representation.test.ts | 338 +++ packages/vocab-runtime/tsdown.config.ts | 1 + .../src/__snapshots__/class.test.ts.deno.snap | 2313 +++++++++++++---- .../src/__snapshots__/class.test.ts.node.snap | 2313 +++++++++++++---- .../src/__snapshots__/class.test.ts.snap | 2313 +++++++++++++---- packages/vocab-tools/src/class.ts | 6 + packages/vocab-tools/src/codec.ts | 16 +- packages/vocab-tools/src/constructor.ts | 7 + .../vocab/src/signed-representation.test.ts | 277 ++ 25 files changed, 7733 insertions(+), 1763 deletions(-) create mode 100644 changes.d/fedify/signed-child-representation.md create mode 100644 changes.d/vocab/signed-child-representation.md create mode 100644 packages/fedify/src/compat/secured-document.test.ts create mode 100644 packages/fedify/src/compat/secured-document.ts create mode 100644 packages/fedify/src/federation/compound-fanout.test.ts create mode 100644 packages/vocab-runtime/src/internal/signed-representation.ts create mode 100644 packages/vocab-runtime/src/signed-representation.test.ts create mode 100644 packages/vocab/src/signed-representation.test.ts diff --git a/CHANGES.md b/CHANGES.md index 635b66930..8e71ef9c4 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -29,6 +29,29 @@ To be released. the new *Clearing legacy cache entries* section of the [key–value store guide] to clear them proactively instead of waiting. + - Fixed `signObject()` so that a signed object keeps verifying after it is + assigned to a typed parent and the parent is serialized. `signObject()` + now captures the secured JSON document its proof covers, and nested + serialization embeds that document verbatim instead of rebuilding the + child under the parent's JSON-LD context. Producing a [FEP-ef61] compound + document with `signObject()` no longer requires assembling the JSON by + hand. [[#288], [#1041], [#1044], [#1051]] + + - The captured document is a snapshot: `clone()` does not carry it, and + mutating a signed object in place does not change it. Sign a clone + again when it has to be embedded as a secured child. + - An object parsed with `fromJsonLd()`, an object that already carried a + proof, and a `toJsonLd()` `context` option that could hide the + internal placeholder all fall back to the previous behavior. + - Outgoing JSON-LD compatibility normalization now leaves a nested + self-contained secured document untouched while signing and sending, + so it cannot rewrite bytes that the child's own proof covers. + Inbound verification is unaffected. + - Fanout delivery now reuses the document the activity was already + serialized into instead of reparsing and reserializing it, which + previously invalidated an embedded signed child and the outer proof + that covered it. + - Fixed `verifyProof()` so Ed25519 JCS proofs authenticate every received proof option except `proofValue`, including `expires`, `domain`, `challenge`, `nonce`, and extension options. It now rejects expired or @@ -166,6 +189,8 @@ To be released. [#1017]: https://github.com/fedify-dev/fedify/issues/1017 [#1027]: https://github.com/fedify-dev/fedify/pull/1027 [#1041]: https://github.com/fedify-dev/fedify/pull/1041 +[#1044]: https://github.com/fedify-dev/fedify/issues/1044 +[#1051]: https://github.com/fedify-dev/fedify/pull/1051 ### @fedify/adonisjs @@ -436,6 +461,13 @@ To be released. `Note`, and other object types, for per-language translation metadata without creating separate posts. + - Changed nested serialization so that an object carrying a signed JSON-LD + representation retained by `signObject()` is embedded with that exact + representation, including its own `@context`, rather than being rebuilt + under the parent's context. `clone()` never carries the retained + representation, because a clone may differ from the document the proof + covers. [[#288], [#1044], [#1051]] + [FEP-22cd]: https://w3id.org/fep/22cd [#810]: https://github.com/fedify-dev/fedify/issues/810 [#826]: https://github.com/fedify-dev/fedify/issues/826 diff --git a/changes.d/fedify/signed-child-representation.md b/changes.d/fedify/signed-child-representation.md new file mode 100644 index 000000000..3e1a532d3 --- /dev/null +++ b/changes.d/fedify/signed-child-representation.md @@ -0,0 +1,31 @@ +--- +links: + '#1041': https://github.com/fedify-dev/fedify/pull/1041 + '#1044': https://github.com/fedify-dev/fedify/issues/1044 + '#1051': https://github.com/fedify-dev/fedify/pull/1051 + '#288': https://github.com/fedify-dev/fedify/issues/288 +--- + - Fixed `signObject()` so that a signed object keeps verifying after it is + assigned to a typed parent and the parent is serialized. `signObject()` + now captures the secured JSON document its proof covers, and nested + serialization embeds that document verbatim instead of rebuilding the + child under the parent's JSON-LD context. Producing a [FEP-ef61] compound + document with `signObject()` no longer requires assembling the JSON by + hand. [[#288], [#1041], [#1044], [#1051]] + + - The captured document is a snapshot: `clone()` does not carry it, and + mutating a signed object in place does not change it. Sign a clone + again when it has to be embedded as a secured child. + - An object parsed with `fromJsonLd()`, an object that already carried a + proof, and a `toJsonLd()` `context` option that could hide the + internal placeholder all fall back to the previous behavior. + - Outgoing JSON-LD compatibility normalization now leaves a nested + self-contained secured document untouched while signing and sending, + so it cannot rewrite bytes that the child's own proof covers. + Inbound verification is unaffected. + - Fanout delivery now reuses the document the activity was already + serialized into instead of reparsing and reserializing it, which + previously invalidated an embedded signed child and the outer proof + that covered it. + +[FEP-ef61]: https://w3id.org/fep/ef61 diff --git a/changes.d/vocab/signed-child-representation.md b/changes.d/vocab/signed-child-representation.md new file mode 100644 index 000000000..3510c0c56 --- /dev/null +++ b/changes.d/vocab/signed-child-representation.md @@ -0,0 +1,12 @@ +--- +links: + '#1044': https://github.com/fedify-dev/fedify/issues/1044 + '#1051': https://github.com/fedify-dev/fedify/pull/1051 + '#288': https://github.com/fedify-dev/fedify/issues/288 +--- + - Changed nested serialization so that an object carrying a signed JSON-LD + representation retained by `signObject()` is embedded with that exact + representation, including its own `@context`, rather than being rebuilt + under the parent's context. `clone()` never carries the retained + representation, because a clone may differ from the document the proof + covers. [[#288], [#1044], [#1051]] diff --git a/docs/manual/send.md b/docs/manual/send.md index c6bc53465..5c2eec7e9 100644 --- a/docs/manual/send.md +++ b/docs/manual/send.md @@ -1170,19 +1170,87 @@ verified in isolation even if the parent's active context causes the embedded JSON-LD to expand differently. Proof success does not establish that the isolated and embedded expansions are equivalent. +#### Producing a compound document + +`signObject()` captures the secured JSON document that the proof it creates +covers, and keeps it on the object it returns. Assigning that object to a +typed parent and serializing the parent embeds the captured document verbatim, +so the child keeps its own `@context` and its own proof context even when they +differ from the parent's: + +~~~~ typescript twoslash +import { signObject } from "@fedify/fedify"; +import { Create, Note } from "@fedify/vocab"; +const noteId = new URL("ap://did:key:z6Mkabc/objects/1"); +const activityId = new URL("ap://did:key:z6Mkabc/activities/1"); +const actorId = new URL("ap://did:key:z6Mkabc/actor"); +const key = null as unknown as CryptoKey; +const keyId = new URL("did:key:z6Mkabc#z6Mkabc"); +const portableContext = [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + "https://w3id.org/fep/ef61", +]; +// ---cut-before--- +const note = await signObject( + new Note({ id: noteId, attribution: actorId, content: "Hello" }), + key, + keyId, + { context: portableContext }, +); +const create = await signObject( + new Create({ id: activityId, actor: actorId, object: note }), + key, + keyId, + { context: portableContext }, +); +const compound = await create.toJsonLd({ + format: "compact", + context: portableContext, +}); +~~~~ + +Extracting `compound`'s `object` gives back exactly the bytes `note`'s proof +covers, and the outer proof covers that same secured child. + +Serialize the parent with the same `context` it was signed with. A proof +covers one serialization, and a document emitted under a different context is +a document the proof was never computed over. This matters most when the +activity goes out through +[`sendActivity()`](#sending-an-activity), which +serializes with the type's default context: omit the `context` option on the +outer `signObject()` call in that case, so the proof covers the bytes Fedify +actually sends. The child keeps its own context either way, which is what +makes a mismatch on the parent easy to misread as a working document. + +The captured document is a snapshot. It is independent of anything done to +the returned object afterwards, and `clone()` never carries it, because a +clone may differ from the document the proof covers. Sign the clone again +when it has to be embedded as a secured child. + > [!WARNING] -> Typed vocabulary serialization can change the secured representation of a -> signed embedded object. Signing a typed child, assigning it to a typed -> parent, and serializing the parent can remove the child's document and proof -> contexts while retaining its `proofValue`. Do not serialize a signed typed -> child through a typed parent when producing a map-local compound document. -> The profile also accepts exactly one direct proof per map, while Fedify's -> ordinary activity signer creates one proof for each Ed25519 key. A sender -> producing a portable compound document must arrange for exactly one direct -> proof on each map. -> When forwarding an already signed payload, use -> [`forwardActivity()`](./outbox.md#federating-posted-activities) to avoid a -> vocabulary-object round trip. +> Several things take a signed child outside this supported path, and each +> one falls back to ordinary serialization, which rebuilds the child under the +> parent's context and leaves it unable to verify on its own: +> +> - An object parsed with `fromJsonLd()`. Parsing does not establish which +> representation was signed, so nothing is captured. When forwarding an +> already signed payload, use +> [`forwardActivity()`](./outbox.md#federating-posted-activities) to avoid +> a vocabulary-object round trip. +> - An object that already carried a proof. The profile accepts exactly one +> direct proof per map, while Fedify's ordinary activity signer creates one +> proof for each Ed25519 key, so a sender producing a portable compound +> document must arrange for exactly one direct proof on each map. +> - A `toJsonLd()` call whose `context` option could hide the marker Fedify +> uses to place the captured document, for example a context that aliases +> `@id` under a term other than `id`, declares `@nest`, uses an `@id` or +> `@type` container, or cannot be resolved from Fedify's preloaded +> contexts. +> - A mutation applied to the returned object in place, through a plural +> accessor's array or a `proofValue` byte. The snapshot still holds what +> was signed, so the embedded child keeps verifying while the typed object +> no longer matches it. > [!TIP] > HTTPS Signatures, Linked Data Signatures, and Object Integrity Proofs can diff --git a/packages/fedify/src/compat/outgoing-jsonld.test.ts b/packages/fedify/src/compat/outgoing-jsonld.test.ts index 453520564..4cb20fdcd 100644 --- a/packages/fedify/src/compat/outgoing-jsonld.test.ts +++ b/packages/fedify/src/compat/outgoing-jsonld.test.ts @@ -285,3 +285,114 @@ test("normalizeOutgoingActivityJsonLd() applies outgoing JSON-LD workarounds", a const normalizedObject = normalized.object as Record; assertEquals(Array.isArray(normalizedObject.attachment), true); }); + +const securedChild = { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + id: "ap://did:key:z6Mkabc/objects/1", + type: "Note", + content: "Hello", + to: "as:Public", + attachment: { + type: "Document", + mediaType: "image/png", + url: "https://example.com/image.png", + }, + proof: { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + type: "DataIntegrityProof", + cryptosuite: "eddsa-jcs-2022", + created: "2023-02-24T23:36:38Z", + verificationMethod: "did:key:z6Mkabc#z6Mkabc", + proofPurpose: "assertionMethod", + proofValue: "z3FXQ", + }, +}; + +function compoundWithSecuredChild(): Record { + return { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + id: "ap://did:key:z6Mkdef/activities/1", + type: "Create", + actor: "ap://did:key:z6Mkdef/actor", + to: "as:Public", + object: structuredClone(securedChild), + }; +} + +test("normalizeOutgoingActivityJsonLd() can preserve a nested secured child", async () => { + const input = compoundWithSecuredChild(); + const preserved = await normalizeOutgoingActivityJsonLd( + input, + mockDocumentLoader, + { preserveNestedSecuredDocuments: true }, + ) as Record; + + // The parent is still normalized … + assertEquals(preserved.to, PUBLIC_COLLECTION.href); + // … while every byte the child's own proof covers is left alone. + assertEquals(preserved.object, securedChild); +}); + +test("normalizeOutgoingActivityJsonLd() rewrites a nested secured child by default", async () => { + const input = compoundWithSecuredChild(); + const normalized = await normalizeOutgoingActivityJsonLd( + input, + mockDocumentLoader, + ) as Record; + const child = normalized.object as Record; + + assertEquals(normalized.to, PUBLIC_COLLECTION.href); + assertEquals(child.to, PUBLIC_COLLECTION.href); + assertEquals(child.attachment, [securedChild.attachment]); +}); + +test("normalizeOutgoingActivityJsonLd() only preserves a complete secured child", async () => { + const cases: Record) => void> = { + "no proof": (child) => delete child.proof, + "null proof": (child) => child.proof = null, + "proof set": (child) => child.proof = [securedChild.proof], + "proof without a verification method": (child) => + delete (child.proof as Record).verificationMethod, + "incomplete proof": (child) => + delete (child.proof as Record).cryptosuite, + "empty proof value": (child) => + (child.proof as Record).proofValue = "", + }; + for (const [name, mutate] of Object.entries(cases)) { + const input = compoundWithSecuredChild(); + mutate(input.object as Record); + const normalized = await normalizeOutgoingActivityJsonLd( + input, + mockDocumentLoader, + { preserveNestedSecuredDocuments: true }, + ) as Record; + const child = normalized.object as Record; + + assertEquals(child.to, PUBLIC_COLLECTION.href, name); + assertEquals(child.attachment, [securedChild.attachment], name); + } +}); + +test("normalizeOutgoingActivityJsonLd() still normalizes a top-level secured document", async () => { + const input = { + ...structuredClone(securedChild), + id: "ap://did:key:z6Mkabc/objects/top-level", + }; + const normalized = await normalizeOutgoingActivityJsonLd( + input, + mockDocumentLoader, + { preserveNestedSecuredDocuments: true }, + ) as Record; + + assertEquals(normalized.to, PUBLIC_COLLECTION.href); + assertEquals(normalized.attachment, [securedChild.attachment]); +}); diff --git a/packages/fedify/src/compat/outgoing-jsonld.ts b/packages/fedify/src/compat/outgoing-jsonld.ts index 69c43387c..b894c1f47 100644 --- a/packages/fedify/src/compat/outgoing-jsonld.ts +++ b/packages/fedify/src/compat/outgoing-jsonld.ts @@ -3,6 +3,10 @@ import jsonld from "@fedify/vocab-runtime/jsonld"; import { getLogger } from "@logtape/logtape"; import { preloadedOnlyDocumentLoader } from "./preloaded-context-loader.ts"; import { normalizePublicAudience } from "./public-audience.ts"; +import { + isSelfContainedSecuredDocument, + type OutgoingNormalizationOptions, +} from "./secured-document.ts"; const logger = getLogger(["fedify", "compat", "outgoing-jsonld"]); @@ -92,15 +96,23 @@ function getKnownSafeContextUrls(): ReadonlySet { */ function wrapScalarAttachments( jsonLd: unknown, + preserveSecured: boolean, depth: number = 0, ): unknown { if (depth >= MAX_TRAVERSAL_DEPTH) return jsonLd; + // A nested self-contained secured document is signed as it stands; its + // bytes belong to its own proof, not to this document's wire format. + if ( + preserveSecured && depth > 0 && isSelfContainedSecuredDocument(jsonLd) + ) { + return jsonLd; + } if (Array.isArray(jsonLd)) { let normalized: unknown[] | null = null; for (let i = 0; i < jsonLd.length; i++) { const item = jsonLd[i]; - const next = wrapScalarAttachments(item, depth + 1); + const next = wrapScalarAttachments(item, preserveSecured, depth + 1); if (normalized == null && next !== item) { normalized = jsonLd.slice(0, i); } @@ -122,7 +134,7 @@ function wrapScalarAttachments( const next = key === "@context" || (key === "@value" && isJsonLdValueObject(jsonLd)) ? value - : wrapScalarAttachments(value, depth + 1); + : wrapScalarAttachments(value, preserveSecured, depth + 1); const shouldWrap = ATTACHMENT_FIELDS.has(key) && next != null && !Array.isArray(next) && @@ -247,8 +259,12 @@ function getLogSafeJsonLdMetadata(jsonLd: unknown): Record { export async function normalizeAttachmentArrays( jsonLd: unknown, contextLoader?: DocumentLoader, + options: OutgoingNormalizationOptions = {}, ): Promise { - const normalized = wrapScalarAttachments(jsonLd); + const normalized = wrapScalarAttachments( + jsonLd, + options.preserveNestedSecuredDocuments ?? false, + ); if (normalized === jsonLd) return jsonLd; if (exceedsTraversalDepth(jsonLd)) { logger.debug( @@ -298,7 +314,8 @@ export async function normalizeAttachmentArrays( export async function normalizeOutgoingActivityJsonLd( jsonLd: unknown, contextLoader?: DocumentLoader, + options: OutgoingNormalizationOptions = {}, ): Promise { - jsonLd = await normalizePublicAudience(jsonLd, contextLoader); - return await normalizeAttachmentArrays(jsonLd, contextLoader); + jsonLd = await normalizePublicAudience(jsonLd, contextLoader, options); + return await normalizeAttachmentArrays(jsonLd, contextLoader, options); } diff --git a/packages/fedify/src/compat/public-audience.ts b/packages/fedify/src/compat/public-audience.ts index 5a1af59dc..b758b8991 100644 --- a/packages/fedify/src/compat/public-audience.ts +++ b/packages/fedify/src/compat/public-audience.ts @@ -3,6 +3,10 @@ import { type DocumentLoader, preloadedContexts } from "@fedify/vocab-runtime"; import jsonld from "@fedify/vocab-runtime/jsonld"; import { getLogger } from "@logtape/logtape"; import { preloadedOnlyDocumentLoader } from "./preloaded-context-loader.ts"; +import { + isSelfContainedSecuredDocument, + type OutgoingNormalizationOptions, +} from "./secured-document.ts"; const logger = getLogger(["fedify", "compat", "public-audience"]); @@ -35,6 +39,7 @@ const KNOWN_SAFE_CONTEXT_URLS: ReadonlySet = new Set( function hasPublicCurieInAddressing( value: unknown, + preserveSecured: boolean, parentKey?: string, depth: number = 0, ): boolean { @@ -49,10 +54,16 @@ function hasPublicCurieInAddressing( if (depth >= MAX_TRAVERSAL_DEPTH) return false; if (Array.isArray(value)) { return value.some((item) => - hasPublicCurieInAddressing(item, parentKey, depth + 1) + hasPublicCurieInAddressing(item, preserveSecured, parentKey, depth + 1) ); } if (typeof value !== "object" || value == null) return false; + // A nested self-contained secured document is signed as it stands; leaving + // it out of the scan keeps the rewrite from touching bytes its own proof + // covers. + if (preserveSecured && depth > 0 && isSelfContainedSecuredDocument(value)) { + return false; + } const record = value as Record; for (const key of Object.keys(record)) { // Some relay implementations compare a subscription's Follow.object as a @@ -68,13 +79,18 @@ function hasPublicCurieInAddressing( // `@context` holds term definitions, not addressing values; skip it so // we do not traverse potentially large inline context objects. if (key === "@context") continue; - if (hasPublicCurieInAddressing(record[key], key, depth + 1)) return true; + if ( + hasPublicCurieInAddressing(record[key], preserveSecured, key, depth + 1) + ) { + return true; + } } return false; } function rewritePublicAudience( value: unknown, + preserveSecured: boolean, parentKey?: string, depth: number = 0, ): unknown { @@ -94,13 +110,21 @@ function rewritePublicAudience( if (Array.isArray(value)) { let changed = false; const mapped = value.map((item) => { - const rewritten = rewritePublicAudience(item, parentKey, depth + 1); + const rewritten = rewritePublicAudience( + item, + preserveSecured, + parentKey, + depth + 1, + ); if (rewritten !== item) changed = true; return rewritten; }); return changed ? mapped : value; } if (typeof value !== "object" || value == null) return value; + if (preserveSecured && depth > 0 && isSelfContainedSecuredDocument(value)) { + return value; + } const record = value as Record; let changed = false; // Clone into a null-prototype object so that writing back a key called @@ -119,7 +143,7 @@ function rewritePublicAudience( key === "object" && (record[key] === "as:Public" || record[key] === "Public") ? PUBLIC_COLLECTION.href - : rewritePublicAudience(record[key], key, depth + 1); + : rewritePublicAudience(record[key], preserveSecured, key, depth + 1); if (rewritten !== record[key]) changed = true; normalized[key] = rewritten; } @@ -233,9 +257,11 @@ function hasKnownSafeContext(jsonLd: unknown): boolean { export async function normalizePublicAudience( jsonLd: unknown, contextLoader?: DocumentLoader, + options: OutgoingNormalizationOptions = {}, ): Promise { - if (!hasPublicCurieInAddressing(jsonLd)) return jsonLd; - const normalized = rewritePublicAudience(jsonLd); + const preserveSecured = options.preserveNestedSecuredDocuments ?? false; + if (!hasPublicCurieInAddressing(jsonLd, preserveSecured)) return jsonLd; + const normalized = rewritePublicAudience(jsonLd, preserveSecured); if (hasKnownSafeContext(jsonLd)) return normalized; const loader = contextLoader ?? preloadedOnlyDocumentLoader; try { diff --git a/packages/fedify/src/compat/secured-document.test.ts b/packages/fedify/src/compat/secured-document.test.ts new file mode 100644 index 000000000..ea8376be2 --- /dev/null +++ b/packages/fedify/src/compat/secured-document.test.ts @@ -0,0 +1,79 @@ +import { test } from "@fedify/fixture"; +import { assert } from "@std/assert/assert"; +import { isSelfContainedSecuredDocument } from "./secured-document.ts"; + +function securedDocument(): Record { + return { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + id: "ap://did:key:z6Mkabc/objects/1", + type: "Note", + content: "Hello", + proof: { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + type: "DataIntegrityProof", + cryptosuite: "eddsa-jcs-2022", + created: "2023-02-24T23:36:38Z", + verificationMethod: "did:key:z6Mkabc#z6Mkabc", + proofPurpose: "assertionMethod", + proofValue: "z3FXQ", + }, + }; +} + +test("isSelfContainedSecuredDocument() accepts a complete secured document", () => { + assert(isSelfContainedSecuredDocument(securedDocument())); + + const expandedType = securedDocument(); + (expandedType.proof as Record).type = + "https://w3id.org/security#DataIntegrityProof"; + assert(isSelfContainedSecuredDocument(expandedType)); + + const typeArray = securedDocument(); + (typeArray.proof as Record).type = ["DataIntegrityProof"]; + assert(isSelfContainedSecuredDocument(typeArray)); +}); + +test("isSelfContainedSecuredDocument() rejects anything less", () => { + assert(!isSelfContainedSecuredDocument(null)); + assert(!isSelfContainedSecuredDocument("string")); + assert(!isSelfContainedSecuredDocument([securedDocument()])); + + for ( + const mutate of [ + // Without its own context the map cannot be extracted and verified + // on its own, so it is not a self-contained secured document. + (d: Record) => delete d["@context"], + (d: Record) => d["@context"] = null, + (d: Record) => delete d.proof, + (d: Record) => d.proof = null, + // A proof set is outside the map-local compound-proof profile. + (d: Record) => d.proof = [d.proof], + // Anything short of a complete `eddsa-jcs-2022` proof could be an + // application's own unrelated `proof` term. + (d: Record) => + (d.proof as Record).type = "SomethingElse", + (d: Record) => + delete (d.proof as Record).cryptosuite, + (d: Record) => + delete (d.proof as Record).created, + (d: Record) => + delete (d.proof as Record).verificationMethod, + (d: Record) => + delete (d.proof as Record).proofPurpose, + (d: Record) => + (d.proof as Record).proofValue = "", + (d: Record) => + (d.proof as Record).proofValue = 42, + ] + ) { + const document = securedDocument(); + mutate(document); + assert(!isSelfContainedSecuredDocument(document)); + } +}); diff --git a/packages/fedify/src/compat/secured-document.ts b/packages/fedify/src/compat/secured-document.ts new file mode 100644 index 000000000..6bb0644ae --- /dev/null +++ b/packages/fedify/src/compat/secured-document.ts @@ -0,0 +1,63 @@ +/** + * Options shared by the outgoing JSON-LD compatibility normalizers. + * + * @internal + */ +export interface OutgoingNormalizationOptions { + /** + * Whether to leave a nested self-contained secured document untouched. + * + * A map that carries its own `@context` and one direct, well-formed + * `DataIntegrityProof` is an independently verifiable document under + * Fedify's map-local compound-proof profile. Rewriting anything inside it + * changes the bytes its proof covers, so the producer path leaves it alone. + * + * Off by default, so that `verifyProof()`'s inbound compatibility fallback + * keeps reproducing exactly the digests it reproduces today. + */ + readonly preserveNestedSecuredDocuments?: boolean; +} + +function isJsonMap(value: unknown): value is Record { + return typeof value === "object" && value != null && !Array.isArray(value); +} + +function isNonEmptyString(value: unknown): value is string { + return typeof value === "string" && value.length > 0; +} + +function hasDataIntegrityProofType(value: unknown): boolean { + const types = Array.isArray(value) ? value : [value]; + return types.some((type) => + type === "DataIntegrityProof" || + type === "https://w3id.org/security#DataIntegrityProof" + ); +} + +/** + * Checks whether a JSON value is a complete, self-contained secured document: + * a map with its own `@context` and exactly one direct, map-valued `proof` + * that carries every member `eddsa-jcs-2022` proof generation produces. + * + * This is deliberately stricter than {@link hasProofLike}, which exists to + * decide whether a document is worth verifying. Here a false positive would + * silently suppress a wire-compatibility fix on an ordinary document, so a + * partial or malformed proof does not qualify. + * + * @internal + */ +export function isSelfContainedSecuredDocument(value: unknown): boolean { + if (!isJsonMap(value)) return false; + if (!Object.hasOwn(value, "@context") || value["@context"] == null) { + return false; + } + if (!Object.hasOwn(value, "proof")) return false; + const proof = value.proof; + if (!isJsonMap(proof)) return false; + return hasDataIntegrityProofType(proof.type) && + isNonEmptyString(proof.cryptosuite) && + isNonEmptyString(proof.created) && + isNonEmptyString(proof.verificationMethod) && + isNonEmptyString(proof.proofPurpose) && + isNonEmptyString(proof.proofValue); +} diff --git a/packages/fedify/src/federation/compound-fanout.test.ts b/packages/fedify/src/federation/compound-fanout.test.ts new file mode 100644 index 000000000..73b02c7bb --- /dev/null +++ b/packages/fedify/src/federation/compound-fanout.test.ts @@ -0,0 +1,308 @@ +import { mockDocumentLoader, test } from "@fedify/fixture"; +import { Create, DataIntegrityProof, Note } from "@fedify/vocab"; +import { exportDidKey, parseIri } from "@fedify/vocab-runtime"; +import { assert, assertEquals } from "@std/assert"; +import fetchMock from "fetch-mock"; +import serialize from "json-canon"; +import { normalizeOutgoingActivityJsonLd } from "../compat/outgoing-jsonld.ts"; +import { + ed25519PrivateKey, + ed25519PublicKey, + rsaPrivateKey2, + rsaPublicKey2, +} from "../testing/keys.ts"; +import { signObject, verifyProof } from "../sig/proof.ts"; +import { exportJwk } from "../sig/key.ts"; +import { MemoryKvStore } from "./kv.ts"; +import { FederationImpl } from "./middleware.ts"; +import type { MessageQueue } from "./mq.ts"; +import type { FanoutMessage, Message } from "./queue.ts"; + +const options = { + contextLoader: mockDocumentLoader, + documentLoader: mockDocumentLoader, +}; +const context = [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", +]; +const childContext = [...context, { ex: "https://example.com/ns#" }]; + +async function parseProof( + document: Record, +): Promise { + const proof = document.proof as Record; + return await DataIntegrityProof.fromJsonLd( + { "@context": document["@context"], ...proof }, + options, + ); +} + +test("fanout delivery keeps an embedded signed child intact", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const childDid = await exportDidKey(ed25519PublicKey.publicKey); + const childKeyId = new URL( + `${childDid}#${childDid.substring("did:key:".length)}`, + ); + const child = await signObject( + new Note({ + id: parseIri(`ap+ef61://${childDid}/objects/fanned-out`), + attribution: parseIri(`ap+ef61://${childDid}/actor`), + content: "A portable note carried through the fanout queue", + }), + ed25519PrivateKey, + childKeyId, + { ...options, context: childContext, created }, + ); + const activity = await signObject( + new Create({ + id: new URL("https://example.com/activities/fanned-out"), + actor: new URL("https://example.com/person"), + object: child, + }), + ed25519PrivateKey, + childKeyId, + { ...options, context, created }, + ); + const compound = await normalizeOutgoingActivityJsonLd( + await activity.toJsonLd({ format: "compact", ...options, context }), + mockDocumentLoader, + { preserveNestedSecuredDocuments: true }, + ) as Record; + const securedChild = compound.object as Record; + assertEquals(securedChild["@context"], childContext); + + fetchMock.spyGlobal(); + try { + let delivered: Record | null = null; + fetchMock.post("https://example.com/inbox", async (cl) => { + delivered = await cl.request!.json(); + return new Response(null, { status: 202 }); + }); + + const federation = new FederationImpl({ + kv: new MemoryKvStore(), + contextLoaderFactory: () => mockDocumentLoader, + }); + federation.setInboxListeners("/users/{identifier}/inbox", "/inbox"); + const message: FanoutMessage = { + type: "fanout", + id: crypto.randomUUID(), + baseUrl: "https://example.com", + keys: [{ + keyId: rsaPublicKey2.id!.href, + privateKey: await exportJwk(rsaPrivateKey2), + }], + inboxes: { + "https://example.com/inbox": { + actorIds: ["https://example.com/recipient"], + sharedInbox: false, + }, + }, + // The fanout queue carries the compact document Fedify already + // produced; reparsing and reserializing it would rebuild the secured + // child under the parent's context. + activity: compound, + activityId: "https://example.com/activities/fanned-out", + activityType: "https://www.w3.org/ns/activitystreams#Create", + normalizeExistingProofs: true, + traceContext: {}, + }; + + await federation.processQueuedTask(undefined, message); + + assert(delivered != null); + const body = delivered as Record; + // The Linked Data Signature is a sibling of the Object Integrity Proof, + // so it does not belong to either proof's input. + delete body.signature; + assertEquals(serialize(body), serialize(compound)); + const embedded = body.object as Record; + assertEquals( + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + childKeyId, + ); + assertEquals( + (await verifyProof(body, await parseProof(body), options))?.id, + childKeyId, + ); + } finally { + fetchMock.hardReset(); + } +}); + +test("forced fanout signs before serializing so the child survives", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const childDid = await exportDidKey(ed25519PublicKey.publicKey); + const childKeyId = new URL( + `${childDid}#${childDid.substring("did:key:".length)}`, + ); + const child = await signObject( + new Note({ + id: parseIri(`ap+ef61://${childDid}/objects/forced-fanout`), + attribution: parseIri(`ap+ef61://${childDid}/actor`), + content: "A portable note sent through a forced fanout", + }), + ed25519PrivateKey, + childKeyId, + { ...options, context: childContext, created }, + ); + // The activity itself is left unsigned, so Fedify has to create the outer + // proof. It must do so while the typed child still carries its retained + // representation, not after the fanout worker has reparsed the activity. + const activity = new Create({ + id: new URL("https://example.com/activities/forced-fanout"), + actor: new URL("https://example.com/person"), + object: child, + }); + + fetchMock.spyGlobal(); + try { + let delivered: Record | null = null; + fetchMock.post("https://example.com/inbox", async (cl) => { + delivered = await cl.request!.json(); + return new Response(null, { status: 202 }); + }); + + const queued: Message[] = []; + const queue: MessageQueue = { + enqueue(message) { + queued.push(message as Message); + return Promise.resolve(); + }, + listen() { + return Promise.resolve(); + }, + }; + const federation = new FederationImpl({ + kv: new MemoryKvStore(), + queue, + manuallyStartQueue: true, + contextLoaderFactory: () => mockDocumentLoader, + }); + federation.setInboxListeners("/users/{identifier}/inbox", "/inbox"); + const context = federation.createContext(new URL("https://example.com/")); + await context.sendActivity( + { keyId: childKeyId, privateKey: ed25519PrivateKey }, + { + id: new URL("https://example.com/users/bob"), + inboxId: new URL("https://example.com/inbox"), + }, + activity, + { fanout: "force" }, + ); + + // The fanout worker hands the activity on to the outbox queue, so drain + // every message the run produces. + assertEquals(queued.length, 1); + for (let i = 0; i < queued.length; i++) { + await federation.processQueuedTask(undefined, queued[i]); + } + + assert(delivered != null); + const body = delivered as Record; + delete body.signature; + const embedded = body.object as Record; + assertEquals(embedded["@context"], childContext); + assertEquals( + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + childKeyId, + ); + assertEquals( + (await verifyProof(body, await parseProof(body), options))?.id, + childKeyId, + ); + } finally { + fetchMock.hardReset(); + } +}); + +test("an already signed activity keeps its single proof through fanout", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const childDid = await exportDidKey(ed25519PublicKey.publicKey); + const childKeyId = new URL( + `${childDid}#${childDid.substring("did:key:".length)}`, + ); + const child = await signObject( + new Note({ + id: parseIri(`ap+ef61://${childDid}/objects/pre-signed`), + attribution: parseIri(`ap+ef61://${childDid}/actor`), + content: "A portable note in a pre-signed activity", + }), + ed25519PrivateKey, + childKeyId, + { ...options, context: childContext, created }, + ); + // Signed with Fedify's default context, which is what `sendActivity()` + // serializes the activity with; a caller-supplied context here would make + // the outer proof cover bytes that are never sent. + const activity = await signObject( + new Create({ + id: new URL("https://example.com/activities/pre-signed"), + actor: new URL("https://example.com/person"), + object: child, + }), + ed25519PrivateKey, + childKeyId, + { ...options, created }, + ); + + fetchMock.spyGlobal(); + try { + let delivered: Record | null = null; + fetchMock.post("https://example.com/inbox", async (cl) => { + delivered = await cl.request!.json(); + return new Response(null, { status: 202 }); + }); + + const queued: Message[] = []; + const queue: MessageQueue = { + enqueue(message) { + queued.push(message as Message); + return Promise.resolve(); + }, + listen() { + return Promise.resolve(); + }, + }; + const federation = new FederationImpl({ + kv: new MemoryKvStore(), + queue, + manuallyStartQueue: true, + contextLoaderFactory: () => mockDocumentLoader, + }); + federation.setInboxListeners("/users/{identifier}/inbox", "/inbox"); + const context_ = federation.createContext(new URL("https://example.com/")); + await context_.sendActivity( + { keyId: childKeyId, privateKey: ed25519PrivateKey }, + { + id: new URL("https://example.com/users/bob"), + inboxId: new URL("https://example.com/inbox"), + }, + activity, + { fanout: "force" }, + ); + for (let i = 0; i < queued.length; i++) { + await federation.processQueuedTask(undefined, queued[i]); + } + + assert(delivered != null); + const body = delivered as Record; + delete body.signature; + // Exactly one direct proof: a proof set is outside the map-local + // compound-proof profile. + assert(!Array.isArray(body.proof)); + assertEquals( + (await verifyProof(body, await parseProof(body), options))?.id, + childKeyId, + ); + const embedded = body.object as Record; + assertEquals(embedded["@context"], childContext); + assertEquals( + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + childKeyId, + ); + } finally { + fetchMock.hardReset(); + } +}); diff --git a/packages/fedify/src/federation/middleware.ts b/packages/fedify/src/federation/middleware.ts index 62a4a7255..fbccf9dfb 100644 --- a/packages/fedify/src/federation/middleware.ts +++ b/packages/fedify/src/federation/middleware.ts @@ -1249,6 +1249,7 @@ export class FederationImpl collectionSync: message.collectionSync, orderingKey: message.orderingKey, normalizeExistingProofs: message.normalizeExistingProofs, + activityJsonLd: message.activity, context, }); } @@ -2365,16 +2366,20 @@ export class FederationImpl } } } - let jsonLd = await activity.toJsonLd({ - format: "compact", - contextLoader, - }); + let jsonLd = !proofCreated && options.activityJsonLd != null + ? options.activityJsonLd + : await activity.toJsonLd({ + format: "compact", + contextLoader, + }); // Existing proofs are preserved by default because they may have been // created over the compact JSON-LD bytes exactly as supplied. Fedify can // safely normalize unsigned activities, proofs it just created, or // locally pre-signed activities when callers opt in. if (proofCreated || !hasProof || options.normalizeExistingProofs) { - jsonLd = await normalizeOutgoingActivityJsonLd(jsonLd, contextLoader); + jsonLd = await normalizeOutgoingActivityJsonLd(jsonLd, contextLoader, { + preserveNestedSecuredDocuments: true, + }); } if (rsaKey == null) { logger.warn( @@ -3928,6 +3933,33 @@ export class ContextImpl implements Context { }); proofCreated = true; } + } else { + // Explicit sender keys carry no Multikey, so sign with the key ID the + // caller supplied, which is exactly what the delivery worker would do + // after reparsing the activity. Signing here instead keeps a signed + // child's retained representation intact: the reparsed activity no + // longer carries one, so a worker-side proof would cover a rebuilt + // child whose own proof no longer verifies. + const contextLoader = this.contextLoader; + // An activity the caller already signed keeps its own proof: appending + // another would turn a single-proof document into a proof set, which + // the map-local compound-proof profile does not accept. This mirrors + // the guard `FederationImpl.sendActivity()` applies before signing. + let hasProof = false; + for await (const _ of activity.getProofs({ contextLoader })) { + hasProof = true; + break; + } + if (!hasProof) { + for (const { keyId, privateKey } of keys) { + if (privateKey.algorithm.name !== "Ed25519") continue; + activity = await signObject(activity, privateKey, keyId, { + contextLoader, + tracerProvider: this.tracerProvider, + }); + proofCreated = true; + } + } } const inboxes = extractInboxes({ recipients: expandedRecipients, @@ -4916,6 +4948,14 @@ interface SendActivityInternalOptions { readonly collectionSync?: string; readonly orderingKey?: string; readonly normalizeExistingProofs?: boolean; + /** + * The compact JSON-LD document the activity was already serialized into, + * when the caller has one. Reusing it keeps a document that embeds a + * secured child intact: reparsing an activity and serializing it again + * rebuilds the child under the parent's context and invalidates both its + * own proof and the outer proof that covered it. + */ + readonly activityJsonLd?: unknown; readonly context: Context; } diff --git a/packages/fedify/src/sig/compound-proof.test.ts b/packages/fedify/src/sig/compound-proof.test.ts index 65d36b368..522517273 100644 --- a/packages/fedify/src/sig/compound-proof.test.ts +++ b/packages/fedify/src/sig/compound-proof.test.ts @@ -1,5 +1,11 @@ import { mockDocumentLoader, test } from "@fedify/fixture"; -import { Create, DataIntegrityProof, Note } from "@fedify/vocab"; +import { + Create, + DataIntegrityProof, + Note, + type Object, + Question, +} from "@fedify/vocab"; import { encodeMultibase, exportDidKey, parseIri } from "@fedify/vocab-runtime"; import jsonld from "@fedify/vocab-runtime/jsonld"; import { assert, assertEquals } from "@std/assert"; @@ -14,6 +20,10 @@ import conflictVector from "../../test-vectors/fep-8b32/map-local-context-confli import { normalizeOutgoingActivityJsonLd } from "../compat/outgoing-jsonld.ts"; import { preloadedOnlyDocumentLoader } from "../compat/preloaded-context-loader.ts"; import { ed25519PrivateKey, ed25519PublicKey } from "../testing/keys.ts"; +import { + type CompoundProofDiscoveryLimits, + verifyCompoundProofDocuments, +} from "./compound-proof.ts"; import { signObject, verifyProof } from "./proof.ts"; const outerPrivateKey = await crypto.subtle.importKey( @@ -70,6 +80,16 @@ const options = { contextLoader: mockDocumentLoader, documentLoader: mockDocumentLoader, }; +const inboundOptions = { + contextLoader: preloadedOnlyDocumentLoader, + documentLoader: preloadedOnlyDocumentLoader, +}; +const compoundLimits: CompoundProofDiscoveryLimits = { + maxDepth: 16, + maxMaps: 32, + maxProofs: 8, + maxBytes: 16_384, +}; async function parseProof( document: Record, @@ -311,10 +331,6 @@ test("the context-conflict vector records valid proofs and divergent semantics", proofValue: conflictVector.proofValues.inner, }); - const inboundOptions = { - contextLoader: preloadedOnlyDocumentLoader, - documentLoader: preloadedOnlyDocumentLoader, - }; const verifiedInner = await verifyProof( embedded, await parseProof(embedded), @@ -457,103 +473,243 @@ test("the raw same-context baseline verifies map-locally", async () => { ); }); -test("typed Create serialization bypasses a parsed child's JSON-LD cache", async () => { - const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); - const unsignedInner = new Note({ - id: parseIri(`ap+ef61://${innerDid}/objects/distinct-context`), - attribution: parseIri(`ap+ef61://${innerDid}/actor`), - content: "A portable note with its own context", - }); - const inner = await signObject( - unsignedInner, +async function signDistinctContextNote( + created: Temporal.Instant, + path: string, +): Promise { + return await signObject( + new Note({ + id: parseIri(`ap+ef61://${innerDid}/objects/${path}`), + attribution: parseIri(`ap+ef61://${innerDid}/actor`), + content: "A portable note with its own context", + }), ed25519PrivateKey, innerKeyId, { ...options, context: distinctInnerContext, created }, ); - const standaloneInner = await normalizeOutgoingActivityJsonLd( - await inner.toJsonLd({ +} + +async function serializeOutgoing( + object: Object, + context?: typeof distinctInnerContext, +): Promise> { + return await normalizeOutgoingActivityJsonLd( + await object.toJsonLd({ format: "compact", ...options, - context: distinctInnerContext, + context: context ?? options.context, }), mockDocumentLoader, + { preserveNestedSecuredDocuments: true }, ) as Record; - const outer = await signObject( +} + +async function signOuterCreate( + created: Temporal.Instant, + path: string, + child: Note, +): Promise { + return await signObject( new Create({ - id: parseIri(`ap+ef61://${outerDid}/activities/distinct-context`), + id: parseIri(`ap+ef61://${outerDid}/activities/${path}`), actor: parseIri(`ap+ef61://${outerDid}/actor`), - object: inner, + object: child, }), outerPrivateKey, outerKeyId, { ...options, created }, ); - const compound = await normalizeOutgoingActivityJsonLd( - await outer.toJsonLd({ format: "compact", ...options }), - mockDocumentLoader, - ) as Record; +} + +test("typed Create serialization embeds the signed child representation", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "distinct-context"); + assert(inner instanceof Note); + const standaloneInner = await serializeOutgoing(inner, distinctInnerContext); + const outer = await signOuterCreate(created, "distinct-context", inner); + assert(outer instanceof Create); + const compound = await serializeOutgoing(outer); const embedded = compound.object as Record; const embeddedProof = embedded.proof as Record; - const standaloneProof = await parseProof(standaloneInner); - assertEquals(standaloneInner["@context"], distinctInnerContext); + // The child keeps its own document and proof contexts, which differ from + // the parent's, and is byte-identical to its standalone secured form. + assertEquals(embedded["@context"], distinctInnerContext); + assertEquals(embeddedProof["@context"], distinctInnerContext); + assertEquals(compound["@context"], context); + assertEquals(serialize(embedded), serialize(standaloneInner)); + assertEquals(embedded.type, "Note"); + assertEquals( - (standaloneInner.proof as Record)["@context"], - distinctInnerContext, + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + innerKeyId, ); - assertEquals(embedded["@context"], undefined); - assertEquals(embeddedProof["@context"], undefined); assertEquals( - embeddedProof.proofValue, - (standaloneInner.proof as Record).proofValue, + (await verifyProof(compound, await parseProof(compound), options))?.id, + outerKeyId, ); - const compactedStandalone = structuredClone(standaloneInner); - const compactedStandaloneProof = compactedStandalone.proof as Record< - string, - unknown - >; - delete compactedStandalone["@context"]; - delete compactedStandaloneProof["@context"]; - assertEquals(embedded, compactedStandalone); + + // The bytes on the wire also pass the inbound map-local verifier, which + // has no outgoing-normalization fallback to fall back on. + const mapLocal = await verifyCompoundProofDocuments( + compound, + compoundLimits, + inboundOptions, + ); + assertEquals(mapLocal.status, "ok"); + assert(mapLocal.status === "ok"); + assert(mapLocal.verified); assertEquals( - (await verifyProof(standaloneInner, standaloneProof, options))?.id, - innerKeyId, + mapLocal.documents.map(({ path, verified }) => ({ path, verified })), + [{ path: "/object", verified: true }, { path: "", verified: true }], ); - const rewrittenContext = structuredClone(standaloneInner); - rewrittenContext["@context"] = context; +}); + +test("tampering with an embedded signed child invalidates both proofs", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "tampered"); + const outer = await signOuterCreate(created, "tampered", inner); + const tampered = await serializeOutgoing(outer); + const tamperedInner = tampered.object as Record; + tamperedInner.content = "A tampered portable note"; + assertEquals( - await verifyProof(rewrittenContext, standaloneProof, options), + await verifyProof(tamperedInner, await parseProof(tamperedInner), options), null, ); assertEquals( - await verifyProof(embedded, standaloneProof, options), + await verifyProof(tampered, await parseProof(tampered), options), null, ); +}); + +test("replacing an embedded child proof invalidates only the outer proof", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const replacementCreated = Temporal.Instant.from("2023-02-25T23:36:38Z"); + const inner = await signDistinctContextNote(created, "replaced-proof"); + const replacement = await signDistinctContextNote( + replacementCreated, + "replaced-proof", + ); + const replacementProof = + (await serializeOutgoing(replacement, distinctInnerContext)) + .proof as Record; + const outer = await signOuterCreate(created, "replaced-proof", inner); + const compound = await serializeOutgoing(outer); + const replacedInner = compound.object as Record; + replacedInner.proof = replacementProof; + + assertEquals( + (await verifyProof(replacedInner, await parseProof(replacedInner), options)) + ?.id, + innerKeyId, + ); assertEquals( - (await verifyProof(compound, await parseProof(compound), options))?.id, - outerKeyId, + await verifyProof(compound, await parseProof(compound), options), + null, + ); +}); + +test("cloning or re-signing a signed child drops its retained representation", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "cloned"); + + // A clone may differ from the document the proof covers, so it must not + // reuse the retained JSON. + const cloned = inner.clone({}); + assert(cloned instanceof Note); + const clonedCompound = await serializeOutgoing( + await signOuterCreate(created, "cloned", cloned), ); + const clonedEmbedded = clonedCompound.object as Record; + assertEquals(clonedEmbedded["@context"], undefined); + assertEquals( + (clonedEmbedded.proof as Record)["@context"], + undefined, + ); + + // A second proof puts the child outside the map-local profile, which + // accepts exactly one direct proof per map, so nothing is retained. + const reSigned = await signObject( + inner, + ed25519PrivateKey, + innerKeyId, + { ...options, context: distinctInnerContext, created }, + ); + const reSignedCompound = await serializeOutgoing( + await signOuterCreate(created, "re-signed", reSigned), + ); + const reSignedEmbedded = reSignedCompound.object as Record; + assertEquals(reSignedEmbedded["@context"], undefined); +}); + +test("mutating a signed child does not change its embedded representation", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "mutated"); + const standaloneInner = await serializeOutgoing(inner, distinctInnerContext); + + // `signObject()` captures the document its proof covers. Mutating the + // returned object in place is unsupported and leaves the snapshot alone, + // so the embedded child still verifies. + const proof = (await Array.fromAsync(inner.getProofs(options)))[0]; + assert(proof.proofValue != null); + proof.proofValue[0] ^= 0xff; + + const compound = await serializeOutgoing( + await signOuterCreate(created, "mutated", inner), + ); + const embedded = compound.object as Record; + assertEquals(serialize(embedded), serialize(standaloneInner)); + assertEquals( + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + innerKeyId, + ); +}); +test("a signed child is embedded through a compactable ancestor too", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "compactable-parent"); + const standaloneInner = await serializeOutgoing(inner, distinctInnerContext); + // `Note` is compactable and `Question` is not, so the inner note is + // embedded by the fast path and then passed through the enclosing + // question's JSON-LD compaction. + const wrapper = new Note({ + id: parseIri(`ap+ef61://${innerDid}/objects/wrapper`), + attachments: [inner], + }); + const question = new Question({ + id: parseIri(`ap+ef61://${outerDid}/objects/question`), + exclusiveOptions: [wrapper], + }); + const serialized = await question.toJsonLd() as Record; + const embeddedWrapper = serialized.oneOf as Record; + const embedded = embeddedWrapper.attachment as Record; + + assertEquals(serialize(embedded), serialize(standaloneInner)); + assertEquals( + (await verifyProof(embedded, await parseProof(embedded), options))?.id, + innerKeyId, + ); +}); + +test("typed Create serialization bypasses a parsed child's JSON-LD cache", async () => { + // Parsing does not establish which representation was signed, so + // `fromJsonLd()` does not retain one and a reparsed secured child still + // loses its contexts when it is embedded through a typed parent. + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + const inner = await signDistinctContextNote(created, "reparsed-context"); + const standaloneInner = await serializeOutgoing(inner, distinctInnerContext); + const standaloneProof = await parseProof(standaloneInner); const reparsedInner = await Note.fromJsonLd(standaloneInner, { contextLoader: mockDocumentLoader, documentLoader: mockDocumentLoader, }); assert(reparsedInner instanceof Note); assertEquals(await reparsedInner.toJsonLd(), standaloneInner); - const reparsedOuter = await signObject( - new Create({ - id: parseIri(`ap+ef61://${outerDid}/activities/reparsed-context`), - actor: parseIri(`ap+ef61://${outerDid}/actor`), - object: reparsedInner, - }), - outerPrivateKey, - outerKeyId, - { ...options, created }, + + const reparsedCompound = await serializeOutgoing( + await signOuterCreate(created, "reparsed-context", reparsedInner), ); - const reparsedCompound = await normalizeOutgoingActivityJsonLd( - await reparsedOuter.toJsonLd({ format: "compact", ...options }), - mockDocumentLoader, - ) as Record; const reparsedEmbedded = reparsedCompound.object as Record; const reparsedEmbeddedProof = reparsedEmbedded.proof as Record< string, @@ -566,8 +722,6 @@ test("typed Create serialization bypasses a parsed child's JSON-LD cache", async reparsedEmbeddedProof.proofValue, (standaloneInner.proof as Record).proofValue, ); - assertEquals(reparsedEmbedded, compactedStandalone); - assertEquals(reparsedEmbedded, embedded); assertEquals( await verifyProof(reparsedEmbedded, standaloneProof, options), null, @@ -588,10 +742,6 @@ test("verifyProof() does not invent a missing child context", async () => { const receivedInnerProof = receivedInner.proof as Record; delete receivedInner["@context"]; delete receivedInnerProof["@context"]; - const inboundOptions = { - contextLoader: preloadedOnlyDocumentLoader, - documentLoader: preloadedOnlyDocumentLoader, - }; const snapshot = structuredClone(received); const proof = await DataIntegrityProof.fromJsonLd( received.proof, @@ -614,3 +764,32 @@ test("verifyProof() does not invent a missing child context", async () => { outerKeyId, ); }); + +test("signing a document too deep to retain still succeeds", async () => { + const created = Temporal.Instant.from("2023-02-24T23:36:38Z"); + // A retained representation has to pass a bounded plain-JSON check. A + // document that exceeds those bounds must fall back to ordinary + // serialization rather than make `signObject()` fail. + let deep = new Note({ + id: parseIri(`ap+ef61://${innerDid}/objects/deep-leaf`), + content: "A portable note nested past the retention bounds", + }); + for (let i = 0; i < 40; i++) { + deep = new Note({ + id: parseIri(`ap+ef61://${innerDid}/objects/deep-${i}`), + attachments: [deep], + }); + } + const signed = await signObject(deep, ed25519PrivateKey, innerKeyId, { + ...options, + context: distinctInnerContext, + created, + }); + + assertEquals((await Array.fromAsync(signed.getProofs(options))).length, 1); + const compound = await serializeOutgoing( + await signOuterCreate(created, "deep", signed), + ); + const embedded = compound.object as Record; + assertEquals(embedded["@context"], undefined); +}); diff --git a/packages/fedify/src/sig/proof.ts b/packages/fedify/src/sig/proof.ts index 83fabefa2..c8b1189b4 100644 --- a/packages/fedify/src/sig/proof.ts +++ b/packages/fedify/src/sig/proof.ts @@ -7,6 +7,7 @@ import { } from "@fedify/vocab"; import { type DocumentLoader, + encodeMultibase, formatIri, getDocumentLoader, getFe34Origin, @@ -14,6 +15,10 @@ import { parseIri, type RemoteDocument, } from "@fedify/vocab-runtime"; +import { + isPlainJsonTree, + retainSignedRepresentation, +} from "@fedify/vocab-runtime/internal/signed-representation"; import jsonld from "@fedify/vocab-runtime/jsonld"; import { getLogger } from "@logtape/logtape"; import { @@ -152,21 +157,96 @@ export interface CreateProofOptions { } /** - * Creates a proof for the given object. - * @param object The object to create a proof for. - * @param privateKey The private key to sign the proof with. - * @param keyId The key ID to use in the proof. It will be used by the verifier. - * @param options Additional options. See also {@link CreateProofOptions}. - * @returns The created proof. - * @throws {TypeError} If the private key is invalid or unsupported. - * @since 0.10.0 + * The outcome of {@link createProofInternal}: the proof, and the secured JSON + * document that the proof covers when Fedify was able to capture one. */ -export async function createProof( +interface CreatedProof { + readonly proof: DataIntegrityProof; + /** + * The complete secured JSON document, or `null` when it could not be + * captured with certainty. It is the exact JSON value the signer hashed, + * plus the proof that was computed over it, so removing its direct `proof` + * member reproduces the signing input byte for byte. + */ + readonly securedDocument: Record | null; +} + +function isJsonMap(value: unknown): value is Record { + return typeof value === "object" && value != null && !Array.isArray(value); +} + +/** + * Assembles the secured JSON document from the bytes that were just signed. + * + * The document is not re-derived from the vocabulary object: it is + * `compactMsg`, the value whose JCS form was hashed, with the serialized + * proof added. Every part of it is then checked against the digests and the + * signature that {@link createProofInternal} produced, so a document that is + * returned verifies under the map-local compound-proof profile by + * construction. Anything that does not check out yields `null`, and the + * caller simply does not retain a representation. + */ +async function captureSecuredDocument( + proof: DataIntegrityProof, + compactMsg: unknown, + msgCanon: string, + proofCanon: string, + proofValue: string, + contextLoader: DocumentLoader | undefined, +): Promise | null> { + if (!isJsonMap(compactMsg)) return null; + const documentContext = compactMsg["@context"]; + // A secured child has to carry its own context; without one it cannot be + // extracted from a parent document and verified on its own. + if (documentContext == null) return null; + if (globalThis.Object.hasOwn(compactMsg, "proof")) return null; + try { + const proofJson = await proof.toJsonLd({ + format: "compact", + contextLoader, + context: documentContext as + | string + | Record + | (string | Record)[], + }); + if (!isJsonMap(proofJson)) return null; + const { proofValue: serializedProofValue, ...proofConfiguration } = + proofJson; + if (serializedProofValue !== proofValue) return null; + if (serialize(proofConfiguration) !== proofCanon) return null; + const securedDocument: Record = { + ...structuredClone(compactMsg), + proof: structuredClone(proofJson), + }; + const { proof: _embeddedProof, ...unsecuredDocument } = securedDocument; + if (serialize(unsecuredDocument) !== msgCanon) return null; + // A document that is too large or too deep to validate cannot be + // retained. Signing still succeeds; only the representation is dropped. + if (!isPlainJsonTree(securedDocument)) return null; + return securedDocument; + } catch (error) { + logger.debug( + "Failed to capture the secured JSON document for a created proof; " + + "the signed object will not preserve its representation when it is " + + "embedded in another object.\n{error}", + { error }, + ); + return null; + } +} + +async function createProofInternal( object: Object, privateKey: CryptoKey, keyId: URL, { contextLoader, context, created }: CreateProofOptions = {}, -): Promise { + /** + * Whether to assemble the secured JSON document. Only `signObject()` needs + * it, and only when it can retain it, so `createProof()` skips the extra + * serialization. + */ + capture = false, +): Promise { validateCryptoKey(privateKey, "private"); if (privateKey.algorithm.name !== "Ed25519") { throw new TypeError("Unsupported algorithm: " + privateKey.algorithm.name); @@ -180,6 +260,10 @@ export async function createProof( compactMsg = await normalizeOutgoingActivityJsonLd( compactMsg, contextLoader, + // An embedded secured child is signed as it stands; rewriting anything + // inside it here would sign bytes that differ from the child's own + // signing input. + { preserveNestedSecuredDocuments: true }, ); const msgCanon = serialize(compactMsg); const encoder = new TextEncoder(); @@ -201,14 +285,52 @@ export async function createProof( const digest = new Uint8Array(proofDigest.byteLength + msgDigest.byteLength); digest.set(new Uint8Array(proofDigest), 0); digest.set(new Uint8Array(msgDigest), proofDigest.byteLength); - const sig = await crypto.subtle.sign("Ed25519", privateKey, digest); - return new DataIntegrityProof({ + const sig = new Uint8Array( + await crypto.subtle.sign("Ed25519", privateKey, digest), + ); + const proof = new DataIntegrityProof({ cryptosuite: "eddsa-jcs-2022", verificationMethod: keyId, proofPurpose: "assertionMethod", - created: created ?? Temporal.Now.instant(), - proofValue: new Uint8Array(sig), + created, + proofValue: sig, }); + const securedDocument = capture + ? await captureSecuredDocument( + proof, + compactMsg, + msgCanon, + proofCanon, + new TextDecoder().decode(encodeMultibase("base58btc", sig)), + contextLoader, + ) + : null; + return { proof, securedDocument }; +} + +/** + * Creates a proof for the given object. + * @param object The object to create a proof for. + * @param privateKey The private key to sign the proof with. + * @param keyId The key ID to use in the proof. It will be used by the verifier. + * @param options Additional options. See also {@link CreateProofOptions}. + * @returns The created proof. + * @throws {TypeError} If the private key is invalid or unsupported. + * @since 0.10.0 + */ +export async function createProof( + object: Object, + privateKey: CryptoKey, + keyId: URL, + options: CreateProofOptions = {}, +): Promise { + const { proof } = await createProofInternal( + object, + privateKey, + keyId, + options, + ); + return proof; } /** @@ -261,7 +383,16 @@ export async function signObject( for await (const proof of object.getProofs(options)) { existingProofs.push(proof); } - const proof = await createProof(object, privateKey, keyId, options); + // The map-local compound-proof profile accepts exactly one direct + // proof per map, so an object that already carried one cannot be + // embedded as a secured child and needs no capture. + const { proof, securedDocument } = await createProofInternal( + object, + privateKey, + keyId, + options, + existingProofs.length < 1, + ); if (span.isRecording()) { if (proof.cryptosuite != null) { span.setAttribute( @@ -282,7 +413,24 @@ export async function signObject( ); } } - return object.clone({ proofs: [...existingProofs, proof] }) as T; + const signed = object.clone({ + proofs: [...existingProofs, proof], + }) as T; + if (securedDocument != null) { + // Retain the secured JSON document so that embedding this object in + // another object's typed property emits the exact bytes its proof + // covers instead of reconstructing it under the parent's context. + retainSignedRepresentation(signed, securedDocument); + } else if (existingProofs.length > 0) { + logger.debug( + "The object {objectId} already had {proofCount} proof(s), so its " + + "signed representation is not retained for embedding; the " + + "map-local compound-proof profile accepts exactly one direct " + + "proof per map.", + { objectId: object.id?.href, proofCount: existingProofs.length }, + ); + } + return signed; } catch (error) { span.setStatus({ code: SpanStatusCode.ERROR, message: String(error) }); throw error; diff --git a/packages/vocab-runtime/deno.json b/packages/vocab-runtime/deno.json index 6f56da282..5c9c9418b 100644 --- a/packages/vocab-runtime/deno.json +++ b/packages/vocab-runtime/deno.json @@ -5,6 +5,7 @@ "exports": { ".": "./src/mod.ts", "./internal/jsonld-cache": "./src/internal/jsonld-cache.ts", + "./internal/signed-representation": "./src/internal/signed-representation.ts", "./jsonld": "./src/jsonld.ts", "./temporal": "./src/temporal.ts" }, diff --git a/packages/vocab-runtime/package.json b/packages/vocab-runtime/package.json index 92b9c2656..beec1f1e4 100644 --- a/packages/vocab-runtime/package.json +++ b/packages/vocab-runtime/package.json @@ -52,6 +52,16 @@ "require": "./dist/internal/jsonld-cache.cjs", "default": "./dist/internal/jsonld-cache.js" }, + "./internal/signed-representation": { + "types": { + "import": "./dist/internal/signed-representation.d.ts", + "require": "./dist/internal/signed-representation.d.cts", + "default": "./dist/internal/signed-representation.d.ts" + }, + "import": "./dist/internal/signed-representation.js", + "require": "./dist/internal/signed-representation.cjs", + "default": "./dist/internal/signed-representation.js" + }, "./temporal": { "types": { "import": "./dist/temporal.d.ts", diff --git a/packages/vocab-runtime/src/internal/signed-representation.ts b/packages/vocab-runtime/src/internal/signed-representation.ts new file mode 100644 index 000000000..25a0b245a --- /dev/null +++ b/packages/vocab-runtime/src/internal/signed-representation.ts @@ -0,0 +1,565 @@ +import preloadedContexts from "../contexts.ts"; + +/** + * A JSON map. Retained signed representations are always plain JSON maps. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export type SignedRepresentationJsonMap = Record; + +const RETAINED_SIGNED_REPRESENTATION = Symbol.for( + "@fedify/vocab-runtime.signedRepresentation.v1", +); + +const SIGNED_VALUE_SCOPE = Symbol.for( + "@fedify/vocab-runtime.signedValueScope.v1", +); + +/** + * The IRI namespace of the placeholder node references that stand in for a + * retained signed representation until the owning `toJsonLd()` frame puts the + * representation back. + */ +const MARKER_NAMESPACE = "urn:x-fedify-signed-value:"; + +/** Bounds applied when validating a retained signed representation. */ +const MAX_VALIDATION_DEPTH = 64; +const MAX_VALIDATION_NODES = 100_000; + +/** + * The depth to which placeholders are put back. It has to exceed + * {@link MAX_VALIDATION_DEPTH}, because a restored document is itself nested + * inside the document that embeds it. Running out of depth is an error + * rather than a stopping point: a placeholder left in an unvisited subtree + * would reach the wire in place of the secured child. + */ +const MAX_RESTORATION_DEPTH = 256; + +/** + * JSON-LD keywords that may appear at the top level of a context definition + * without endangering placeholder recovery. `@vocab` and `@base` are checked + * separately because they can rewrite the placeholder IRI. + */ +const HARMLESS_CONTEXT_KEYWORDS: ReadonlySet = new Set([ + "@protected", + "@version", + "@propagate", +]); + +/** + * Keyword aliases that are safe to leave in place because the placeholder + * recovery walker understands them. + */ +const ALLOWED_KEYWORD_ALIASES: ReadonlyMap = new Map([ + ["id", "@id"], + ["type", "@type"], +]); + +function isJsonMap(value: unknown): value is SignedRepresentationJsonMap { + if (value == null || typeof value !== "object" || Array.isArray(value)) { + return false; + } + const prototype = Object.getPrototypeOf(value); + return prototype === Object.prototype || prototype === null; +} + +/** + * Checks that a value is a plain JSON tree that is safe to embed verbatim in + * a serialized document: plain object and array prototypes only, string keys + * only, own enumerable data properties only, finite numbers, and no + * `undefined`. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function isPlainJsonTree(value: unknown): boolean { + let nodes = 0; + return check(value, 0); + + function check(current: unknown, depth: number): boolean { + if (depth > MAX_VALIDATION_DEPTH) return false; + if (++nodes > MAX_VALIDATION_NODES) return false; + if (current === null) return true; + switch (typeof current) { + case "string": + case "boolean": + return true; + case "number": + return Number.isFinite(current); + case "object": + break; + default: + return false; + } + if (Array.isArray(current)) { + if (Object.getPrototypeOf(current) !== Array.prototype) return false; + if (Object.getOwnPropertySymbols(current).length > 0) return false; + for (let i = 0; i < current.length; i++) { + const descriptor = Object.getOwnPropertyDescriptor(current, i); + if (descriptor == null || !("value" in descriptor)) return false; + if (!check(descriptor.value, depth + 1)) return false; + } + return true; + } + if (!isJsonMap(current)) return false; + if (Object.getOwnPropertySymbols(current).length > 0) return false; + for (const key of Object.getOwnPropertyNames(current)) { + const descriptor = Object.getOwnPropertyDescriptor(current, key); + if (descriptor == null || !("value" in descriptor)) return false; + if (!descriptor.enumerable) return false; + if (!check(descriptor.value, depth + 1)) return false; + } + return true; + } +} + +function deepFreeze(value: T): T { + if (value == null || typeof value !== "object") return value; + if (Object.isFrozen(value)) return value; + Object.freeze(value); + for (const child of Object.values(value as Record)) { + deepFreeze(child); + } + return value; +} + +/** + * Attaches the secured JSON document that a signer captured for `target`. + * + * The document is the exact JSON value that the object's own Object Integrity + * Proof covers. Nested serialization embeds it verbatim instead of + * reconstructing the object under the parent's JSON-LD context. The value is + * deep-frozen, so it is independent of anything done to `target` afterwards. + * + * `clone()` never carries the attachment, because a clone is a fresh instance. + * + * @internal Technically exported for `@fedify/fedify` and generated + * vocabulary classes, but not part of the public API contract. This is not + * considered public API for Semantic Versioning decisions. + */ +export function retainSignedRepresentation( + target: object, + securedDocument: SignedRepresentationJsonMap, +): void { + if (!isJsonMap(securedDocument) || !isPlainJsonTree(securedDocument)) { + throw new TypeError( + "The secured document must be a plain JSON map within the validation " + + `bounds (at most ${MAX_VALIDATION_DEPTH} levels deep and ` + + `${MAX_VALIDATION_NODES} nodes).`, + ); + } + Object.defineProperty(target, RETAINED_SIGNED_REPRESENTATION, { + value: deepFreeze(securedDocument), + enumerable: false, + writable: false, + configurable: true, + }); +} + +/** + * Returns the secured JSON document retained for `target`, if any. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function getRetainedSignedRepresentation( + target: unknown, +): SignedRepresentationJsonMap | undefined { + if (target == null || typeof target !== "object") return undefined; + const retained = (target as Record)[ + RETAINED_SIGNED_REPRESENTATION + ]; + return isJsonMap(retained) ? retained : undefined; +} + +function resolveContextEntry(entry: unknown): unknown { + if (typeof entry !== "string") return entry; + if (!Object.hasOwn(preloadedContexts, entry)) return undefined; + const document = preloadedContexts[entry]; + if (!isJsonMap(document)) return undefined; + return document["@context"]; +} + +/** + * Checks whether a JSON-LD context leaves placeholder node references + * recoverable after compaction. + * + * Placeholder recovery replaces a bare IRI string, `{"@id": …}`, or + * `{"id": …}`. A context that aliases `@id` under a different term, declares + * `@nest`, uses an `@id` or `@type` container, rebases or re-vocabularies the + * placeholder namespace, or defines a prefix that shortens the placeholder + * IRI could hide the placeholder from that walker or make the walker rewrite + * the wrong node. A context that cannot be resolved offline cannot be vetted + * at all. Any of those makes the context unsafe, and retention is then not + * used. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function isMarkerSafeContext(context: unknown): boolean { + return check(context, 0); + + function check(current: unknown, depth: number): boolean { + if (depth > 8) return false; + if (Array.isArray(current)) { + return current.every((entry) => check(entry, depth + 1)); + } + if (typeof current === "string") { + const resolved = resolveContextEntry(current); + if (resolved === undefined) return false; + return check(resolved, depth + 1); + } + if (current == null) return true; + if (!isJsonMap(current)) return false; + for (const [term, definition] of Object.entries(current)) { + if (term === "@vocab" || term === "@base") { + // A `@vocab` or `@base` that covers the placeholder namespace lets + // compaction emit a shortened or relative form of the marker. + if (typeof definition !== "string") return false; + if (sharesMarkerNamespace(definition)) return false; + continue; + } + if (term.startsWith("@")) { + if (!HARMLESS_CONTEXT_KEYWORDS.has(term)) return false; + continue; + } + // A term named `urn` turns `urn:x-fedify-signed-value:…` into + // something a JSON-LD processor reads as a compact IRI, which it + // rejects outright in safe mode. + if (MARKER_NAMESPACE.startsWith(`${term}:`)) return false; + if (!checkTerm(term, definition, depth)) return false; + } + return true; + } + + function checkTerm( + term: string, + definition: unknown, + depth: number, + ): boolean { + if (definition == null) return true; + if (typeof definition === "string") { + return checkTermTarget(term, definition); + } + if (!isJsonMap(definition)) return false; + const target = definition["@id"]; + if (target != null) { + if (typeof target !== "string") return false; + if (!checkTermTarget(term, target)) return false; + } + if ("@nest" in definition) return false; + if ("@reverse" in definition) return false; + const container = definition["@container"]; + const containers = Array.isArray(container) + ? container + : container == null + ? [] + : [container]; + for (const entry of containers) { + if (entry === "@id" || entry === "@type") return false; + } + if ("@context" in definition) { + if (!check(definition["@context"], depth + 1)) return false; + } + return true; + } + + function checkTermTarget(term: string, target: string): boolean { + if (target.startsWith("@")) { + return ALLOWED_KEYWORD_ALIASES.get(term) === target; + } + // A target with no scheme separator is not an IRI: it resolves through + // another term or through `@vocab`, so it can alias `@id` indirectly + // (`{ i: "id" }` where `id` is ActivityStreams' own `@id` alias). + // Resolving those chains is not worth it here; reject them and let the + // document take the ordinary-serialization fallback. + if (!target.includes(":")) return false; + // A prefix definition that covers the placeholder namespace lets + // compaction emit the marker as a compact IRI. + return !sharesMarkerNamespace(target); + } +} + +/** + * Reports whether an IRI prefix could shorten, relativize or otherwise hide a + * placeholder IRI. Both directions matter: a prefix shorter than the + * namespace covers every marker, and a longer one covers the markers whose + * random suffix happens to start with it. + */ +function sharesMarkerNamespace(prefix: string): boolean { + return MARKER_NAMESPACE.startsWith(prefix) || + prefix.startsWith(MARKER_NAMESPACE); +} + +/** + * The per-`toJsonLd()`-call state that tracks retained children. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export interface SignedValueScope { + /** Whether retained representations may be embedded at all. */ + readonly enabled: boolean; + /** Marker IRI for each retained instance seen in this call. */ + readonly markers: Map; + /** Retained document for each marker IRI. */ + readonly documents: Map; +} + +/** + * The result of entering a signed-value scope. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export interface SignedValueScopeEntry { + readonly scope: SignedValueScope; + /** + * Whether this frame created the scope, and therefore has to put the + * retained documents back before returning. + */ + readonly owner: boolean; +} + +/** + * Joins the signed-value scope of the enclosing `toJsonLd()` frame, or starts + * one when this frame is the outermost. + * + * `options` must already be the internal copy that the generated encoder + * makes, never the object a caller passed in: the scope is attached to it as + * an enumerable symbol-keyed property so that every `{...options}` spread in + * the generated code propagates it to nested and inherited frames. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function enterSignedValueScope( + options: { + format?: "compact" | "expand"; + context?: + | string + | Record + | (string | Record)[]; + }, +): SignedValueScopeEntry { + const existing = (options as Record)[SIGNED_VALUE_SCOPE]; + if (existing != null) { + return { scope: existing as SignedValueScope, owner: false }; + } + const scope: SignedValueScope = { + // A document that the caller asked to have expanded has no compact + // representation to preserve, so retention does not apply to it. + enabled: options.format !== "expand" && + (options.context == null || isMarkerSafeContext(options.context)), + markers: new Map(), + documents: new Map(), + }; + Object.defineProperty(options, SIGNED_VALUE_SCOPE, { + value: scope, + enumerable: true, + writable: false, + configurable: true, + }); + return { scope, owner: true }; +} + +/** + * Emits a placeholder node reference for a value that carries a retained + * signed representation, or `undefined` when it does not carry one. + * + * Both encoder paths use placeholders, never the retained document itself: + * an ancestor frame may still expand or compact the value, which would + * destroy an embedded document but leaves a node reference recoverable. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function retainedSignedValueRef( + value: unknown, + scope: SignedValueScope, +): { "@id": string } | undefined { + if (!scope.enabled) return undefined; + if (value == null || typeof value !== "object") return undefined; + const retained = getRetainedSignedRepresentation(value); + if (retained == null) return undefined; + let marker = scope.markers.get(value); + if (marker == null) { + // Validated once per instance per call; `retainSignedRepresentation()` + // already enforces this, so a failure here means the carrier was written + // by something other than a signer. + if (!isPlainJsonTree(retained)) return undefined; + marker = `${MARKER_NAMESPACE}${crypto.randomUUID()}`; + scope.markers.set(value, marker); + scope.documents.set(marker, retained); + } + return { "@id": marker }; +} + +function markerOf( + value: unknown, + scope: SignedValueScope, +): string | undefined { + return typeof value === "string" && scope.documents.has(value) + ? value + : undefined; +} + +/** + * Puts every retained signed representation back in place of its placeholder + * node reference. + * + * Only the frame that owns the scope calls this, and only after compaction + * and context embedding are complete. + * + * @throws {TypeError} If a retained document was not put back anywhere, or if + * any trace of a placeholder survives. Both mean the serialized + * document does not contain the secured child it was told to embed, + * and emitting it would produce a signed child that silently fails + * verification. + * + * @internal Technically exported for generated vocabulary classes, but not + * part of the public API contract. This is not considered public API for + * Semantic Versioning decisions. + */ +export function resolveSignedValues( + document: unknown, + scope: SignedValueScope, +): unknown { + if (scope.documents.size < 1) return document; + const restored = new Set(); + const resolved = restore(document, 0); + // Emitted references are not counted, because the generated encoders can + // legitimately emit one more or one fewer than the output holds: a subtype + // that redefines an inherited property re-encodes it after deleting the + // inherited key, and a functional property with redundant properties writes + // one encoded value under several keys. What must hold is that every + // retained document reached the output somewhere, and that no trace of a + // placeholder is left behind. + for (const marker of scope.documents.keys()) { + if (restored.has(marker)) continue; + throw new TypeError( + `Failed to preserve a signed child representation: the placeholder ` + + `${marker} is not in the serialized document.`, + ); + } + // A shortened or relativized marker no longer matches the walker's + // reference shapes, so look for the random suffix anywhere in the output, + // including in map keys. + const trace = findMarkerTrace(resolved, scope); + if (trace != null) { + throw new TypeError( + `Failed to preserve a signed child representation: a trace of the ` + + `placeholder ${trace} survived serialization.`, + ); + } + return resolved; + + function restore(value: unknown, depth: number): unknown { + if (depth > MAX_RESTORATION_DEPTH) { + throw new TypeError( + "Failed to preserve a signed child representation: the serialized " + + `document is nested deeper than ${MAX_RESTORATION_DEPTH} levels, ` + + "so a placeholder could be left unresolved.", + ); + } + const direct = markerOf(value, scope); + if (direct != null) return take(direct); + if (Array.isArray(value)) { + let changed = false; + const mapped = value.map((item) => { + const next = restore(item, depth + 1); + if (next !== item) changed = true; + return next; + }); + return changed ? mapped : value; + } + if (!isJsonMap(value)) return value; + const keys = Object.keys(value); + if (keys.length === 1 && (keys[0] === "@id" || keys[0] === "id")) { + const marker = markerOf(value[keys[0]], scope); + if (marker != null) return take(marker); + } + let changed = false; + // Write into a null-prototype object so that a key called `__proto__` + // becomes a regular own property instead of poisoning the chain. + const mapped: Record = Object.create(null); + for (const key of keys) { + // `@context` holds term definitions, never a node reference. + const next = key === "@context" + ? value[key] + : restore(value[key], depth + 1); + if (next !== value[key]) changed = true; + mapped[key] = next; + } + if (!changed) return value; + // Restore the ordinary prototype once every key is an own property, so + // that the result compares equal to a plain object literal. + return Object.setPrototypeOf(mapped, Object.prototype); + } + + function take(marker: string): SignedRepresentationJsonMap { + restored.add(marker); + // A fresh copy per insertion site, so that two sites never alias one + // object and a caller mutating the returned document cannot reach the + // frozen snapshot. The restored document is not traversed again. + return structuredClone( + scope.documents.get(marker), + ) as SignedRepresentationJsonMap; + } +} + +/** + * Finds any surviving trace of a placeholder IRI in a resolved document, + * matching the random suffix rather than the whole IRI so that a shortened, + * relativized or otherwise rewritten marker is caught too. + */ +function findMarkerTrace( + document: unknown, + scope: SignedValueScope, +): string | undefined { + const suffixes = new Map(); + for (const marker of scope.documents.keys()) { + suffixes.set(marker.slice(MARKER_NAMESPACE.length), marker); + } + return search(document, 0); + + function matched(value: string): string | undefined { + for (const [suffix, marker] of suffixes) { + if (value.includes(suffix)) return marker; + } + return undefined; + } + + function search(value: unknown, depth: number): string | undefined { + if (depth > MAX_RESTORATION_DEPTH) { + throw new TypeError( + "Failed to preserve a signed child representation: the serialized " + + `document is nested deeper than ${MAX_RESTORATION_DEPTH} levels, ` + + "so a surviving placeholder could go unnoticed.", + ); + } + if (typeof value === "string") return matched(value); + if (Array.isArray(value)) { + for (const item of value) { + const found = search(item, depth + 1); + if (found != null) return found; + } + return undefined; + } + if (value == null || typeof value !== "object") return undefined; + for (const [key, child] of Object.entries(value)) { + const found = matched(key) ?? search(child, depth + 1); + if (found != null) return found; + } + return undefined; + } +} diff --git a/packages/vocab-runtime/src/signed-representation.test.ts b/packages/vocab-runtime/src/signed-representation.test.ts new file mode 100644 index 000000000..c9c9e3922 --- /dev/null +++ b/packages/vocab-runtime/src/signed-representation.test.ts @@ -0,0 +1,338 @@ +import { deepStrictEqual, ok, strictEqual, throws } from "node:assert"; +import { test } from "node:test"; +import { + enterSignedValueScope, + getRetainedSignedRepresentation, + isMarkerSafeContext, + isPlainJsonTree, + resolveSignedValues, + retainedSignedValueRef, + retainSignedRepresentation, + type SignedValueScope, +} from "./internal/signed-representation.ts"; + +const securedDocument = { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + id: "ap://did:key:z6Mkabc/objects/1", + type: "Note", + content: "Hello", + proof: { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + ], + type: "DataIntegrityProof", + cryptosuite: "eddsa-jcs-2022", + created: "2023-02-24T23:36:38Z", + verificationMethod: "did:key:z6Mkabc#z6Mkabc", + proofPurpose: "assertionMethod", + proofValue: "z3FXQ", + }, +}; + +function newScope(options: Record = {}): SignedValueScope { + return enterSignedValueScope(options).scope; +} + +function retainedSubject(): object { + const subject = {}; + retainSignedRepresentation(subject, structuredClone(securedDocument)); + return subject; +} + +test("isPlainJsonTree() accepts plain JSON and rejects everything else", () => { + ok(isPlainJsonTree(securedDocument)); + ok(isPlainJsonTree([1, "two", null, { three: true }])); + ok(isPlainJsonTree(Object.create(null))); + + ok(!isPlainJsonTree(undefined)); + ok(!isPlainJsonTree(Number.NaN)); + ok(!isPlainJsonTree(Number.POSITIVE_INFINITY)); + ok(!isPlainJsonTree(new Date())); + ok(!isPlainJsonTree(new URL("https://example.com/"))); + ok(!isPlainJsonTree({ nested: { deeper: undefined } })); + + const withSymbolKey: Record = { a: 1 }; + withSymbolKey[Symbol("b")] = 2; + ok(!isPlainJsonTree(withSymbolKey)); + + const withAccessor = {}; + Object.defineProperty(withAccessor, "a", { get: () => 1, enumerable: true }); + ok(!isPlainJsonTree(withAccessor)); + + const withHiddenProperty = {}; + Object.defineProperty(withHiddenProperty, "a", { + value: 1, + enumerable: false, + }); + ok(!isPlainJsonTree(withHiddenProperty)); +}); + +test("retainSignedRepresentation() attaches a frozen, hidden snapshot", () => { + const subject: Record = {}; + retainSignedRepresentation(subject, structuredClone(securedDocument)); + const retained = getRetainedSignedRepresentation(subject); + + deepStrictEqual(retained, securedDocument); + ok(Object.isFrozen(retained)); + ok(Object.isFrozen((retained as Record).proof)); + // The carrier must not show up in ordinary enumeration or serialization. + deepStrictEqual(Object.keys(subject), []); + strictEqual(JSON.stringify(subject), "{}"); + // A fresh object, such as the one `clone()` builds, has no snapshot. + strictEqual(getRetainedSignedRepresentation({}), undefined); + strictEqual(getRetainedSignedRepresentation(null), undefined); + strictEqual(getRetainedSignedRepresentation("string"), undefined); +}); + +test("retainSignedRepresentation() rejects a value that is not plain JSON", () => { + throws( + () => + retainSignedRepresentation({}, { + created: new Date(), + } as unknown as Record), + TypeError, + ); + throws( + () => + retainSignedRepresentation( + {}, + [1, 2] as unknown as Record, + ), + TypeError, + ); +}); + +test("isMarkerSafeContext() accepts contexts Fedify can vet offline", () => { + ok(isMarkerSafeContext(null)); + ok(isMarkerSafeContext("https://www.w3.org/ns/activitystreams")); + ok(isMarkerSafeContext([ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + "https://w3id.org/fep/ef61", + ])); + ok(isMarkerSafeContext([ + "https://www.w3.org/ns/activitystreams", + { ex: "https://example.com/ns#" }, + ])); +}); + +test("isMarkerSafeContext() rejects contexts that could hide a placeholder", () => { + // A context Fedify cannot resolve offline cannot be vetted at all. + ok(!isMarkerSafeContext("https://example.com/unknown-context")); + // An `@id` alias other than ActivityStreams' own `id`. + ok(!isMarkerSafeContext({ identifier: "@id" })); + ok(!isMarkerSafeContext({ identifier: { "@id": "@id" } })); + // An indirect alias: `i` resolves through `id`, which ActivityStreams maps + // to `@id`. A target with no scheme separator is never an IRI. + ok( + !isMarkerSafeContext([ + "https://www.w3.org/ns/activitystreams", + { i: "id" }, + ]), + ); + ok(!isMarkerSafeContext({ relative: { "@id": "ns#term" } })); + // `@nest` moves a property value into a wrapper map. + ok(!isMarkerSafeContext({ payload: "@nest" })); + ok( + !isMarkerSafeContext({ + object: { + "@id": "https://www.w3.org/ns/activitystreams#object", + "@nest": "payload", + }, + }), + ); + // An id map or type map turns the identifier into a map key. + ok( + !isMarkerSafeContext({ + object: { + "@id": "https://www.w3.org/ns/activitystreams#object", + "@container": "@id", + }, + }), + ); + ok( + !isMarkerSafeContext({ + object: { + "@id": "https://www.w3.org/ns/activitystreams#object", + "@container": ["@set", "@type"], + }, + }), + ); + // A prefix, `@vocab` or `@base` covering the placeholder namespace lets + // compaction emit a shortened or relative marker. + ok(!isMarkerSafeContext({ urn: "urn:" })); + // A term named after the placeholder's scheme makes a JSON-LD processor + // read the marker as a compact IRI, whatever the term points at. + ok(!isMarkerSafeContext({ urn: "https://example.com/ns#" })); + ok(!isMarkerSafeContext({ urn: { "@id": "https://example.com/ns#urn" } })); + ok(!isMarkerSafeContext({ "@vocab": "urn:x-fedify-signed-value:" })); + ok(!isMarkerSafeContext({ "@base": "urn:" })); + ok(!isMarkerSafeContext({ everything: "" })); + // A scoped context is only as safe as its own definitions. + ok(isMarkerSafeContext({ + Note: { + "@id": "https://www.w3.org/ns/activitystreams#Note", + "@context": { ex: "https://example.com/ns#" }, + }, + })); + ok( + !isMarkerSafeContext({ + Note: { + "@id": "https://www.w3.org/ns/activitystreams#Note", + "@context": { identifier: "@id" }, + }, + }), + ); +}); + +test("enterSignedValueScope() gives each call its own scope", () => { + const callerOptions = { format: "compact" as const }; + const first = { ...callerOptions }; + const second = { ...callerOptions }; + const firstEntry = enterSignedValueScope(first); + const secondEntry = enterSignedValueScope(second); + + ok(firstEntry.owner); + ok(secondEntry.owner); + ok(firstEntry.scope !== secondEntry.scope); + // The caller's own object is never touched. + deepStrictEqual(Object.getOwnPropertySymbols(callerOptions), []); + + // A nested frame inherits the scope through the generated spread. + const nested = enterSignedValueScope({ ...first, format: "expand" }); + ok(!nested.owner); + strictEqual(nested.scope, firstEntry.scope); +}); + +test("enterSignedValueScope() disables retention where it cannot apply", () => { + ok(enterSignedValueScope({}).scope.enabled); + ok(enterSignedValueScope({ format: "compact" }).scope.enabled); + // An expanded document has no compact representation to preserve. + ok(!enterSignedValueScope({ format: "expand" }).scope.enabled); + // A context that could hide a placeholder turns the whole mechanism off + // rather than risking a corrupted document. + ok( + !enterSignedValueScope({ + format: "compact", + context: { identifier: "@id" } as unknown as Record, + }).scope.enabled, + ); +}); + +test("retainedSignedValueRef() mints one marker per instance", () => { + const scope = newScope(); + const subject = retainedSubject(); + const first = retainedSignedValueRef(subject, scope); + const second = retainedSignedValueRef(subject, scope); + + ok(first != null); + deepStrictEqual(first, second); + ok(first["@id"].startsWith("urn:x-fedify-signed-value:")); + strictEqual( + scope.documents.get(first["@id"]), + scope.documents.get(second!["@id"]), + ); + strictEqual(retainedSignedValueRef({}, scope), undefined); + strictEqual(retainedSignedValueRef(null, scope), undefined); + strictEqual( + retainedSignedValueRef(subject, newScope({ format: "expand" })), + undefined, + ); +}); + +test("resolveSignedValues() restores every supported reference shape", () => { + const scope = newScope(); + const subject = retainedSubject(); + const marker = retainedSignedValueRef(subject, scope)!["@id"]; + retainedSignedValueRef(subject, scope); + retainedSignedValueRef(subject, scope); + + const resolved = resolveSignedValues({ + "@context": ["https://www.w3.org/ns/activitystreams"], + object: marker, + attachment: [{ "@id": marker }], + tag: { id: marker }, + }, scope) as Record; + + deepStrictEqual(resolved.object, securedDocument); + deepStrictEqual((resolved.attachment as unknown[])[0], securedDocument); + deepStrictEqual(resolved.tag, securedDocument); + // Each site gets its own copy. + ok(resolved.object !== resolved.tag); +}); + +test("resolveSignedValues() leaves a document without placeholders alone", () => { + const scope = newScope(); + const document = { id: "https://example.com/notes/1" }; + strictEqual(resolveSignedValues(document, scope), document); +}); + +test("resolveSignedValues() does not rewrite a context definition", () => { + const scope = newScope(); + const subject = retainedSubject(); + const marker = retainedSignedValueRef(subject, scope)!["@id"]; + // A placeholder that only survives inside `@context` was never restored, + // so the accounting check has to reject the document. + throws( + () => resolveSignedValues({ "@context": { marker } }, scope), + TypeError, + ); +}); + +test("resolveSignedValues() rejects a document that lost a placeholder", () => { + const scope = newScope(); + const subject = retainedSubject(); + retainedSignedValueRef(subject, scope); + + throws( + () => resolveSignedValues({ id: "https://example.com/notes/1" }, scope), + TypeError, + ); +}); + +test("resolveSignedValues() rejects a document that kept a placeholder trace", () => { + const scope = newScope(); + const subject = retainedSubject(); + const marker = retainedSignedValueRef(subject, scope)!["@id"]; + const uuid = marker.slice("urn:x-fedify-signed-value:".length); + + throws( + () => resolveSignedValues({ object: marker, note: `sv:${uuid}` }, scope), + TypeError, + ); +}); + +test("resolveSignedValues() restores a placeholder only where it is a reference", () => { + const scope = newScope(); + const subject = retainedSubject(); + const marker = retainedSignedValueRef(subject, scope)!["@id"]; + + // A map with more than the identifier is a node of its own, not a + // reference, so only the string inside it is replaced. + const resolved = resolveSignedValues( + { object: { "@id": marker, type: "Note" } }, + scope, + ) as Record; + const object = resolved.object as Record; + deepStrictEqual(object["@id"], securedDocument); + strictEqual(object.type, "Note"); +}); + +test("resolveSignedValues() refuses a document too deep to walk", () => { + const scope = newScope(); + const subject = retainedSubject(); + const marker = retainedSignedValueRef(subject, scope)!["@id"]; + // The shallow occurrence alone must not satisfy the check: a placeholder in + // an unvisited subtree would otherwise reach the wire. + let deep: unknown = { "@id": marker }; + for (let i = 0; i < 300; i++) deep = { attachment: deep }; + + throws( + () => resolveSignedValues({ object: marker, tag: deep }, scope), + TypeError, + ); +}); diff --git a/packages/vocab-runtime/tsdown.config.ts b/packages/vocab-runtime/tsdown.config.ts index 4e23314be..6441197af 100644 --- a/packages/vocab-runtime/tsdown.config.ts +++ b/packages/vocab-runtime/tsdown.config.ts @@ -7,6 +7,7 @@ export default [ entry: [ "src/mod.ts", "src/internal/jsonld-cache.ts", + "src/internal/signed-representation.ts", "src/jsonld.ts", "src/temporal.ts", ], diff --git a/packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap b/packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap index 000a5ab27..9b087cf93 100644 --- a/packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap +++ b/packages/vocab-tools/src/__snapshots__/class.test.ts.deno.snap @@ -33,6 +33,11 @@ import { isTrustedIriOrigin, normalizeJsonLdIris } from \\"@fedify/vocab-runtime/internal/jsonld-cache\\"; +import { + enterSignedValueScope, + resolveSignedValues, + retainedSignedValueRef +} from \\"@fedify/vocab-runtime/internal/signed-representation\\"; import { isTemporalDuration, isTemporalInstant, @@ -1229,6 +1234,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -9251,6 +9263,10 @@ get translations(): (Translation)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -9260,7 +9276,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9272,7 +9288,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9288,7 +9304,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9308,7 +9324,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9324,11 +9340,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9363,7 +9379,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9371,7 +9387,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9422,7 +9438,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9430,7 +9446,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9446,11 +9462,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9466,11 +9482,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9486,7 +9502,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9494,7 +9510,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9510,7 +9526,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9518,7 +9534,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9534,7 +9550,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9542,7 +9558,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9574,11 +9590,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9594,11 +9610,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9614,11 +9630,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9634,11 +9650,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9689,7 +9705,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9697,7 +9713,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9749,11 +9765,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9769,11 +9785,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9789,11 +9805,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9809,11 +9825,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9897,11 +9913,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9953,11 +9969,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9973,11 +9989,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9993,11 +10009,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -10033,7 +10049,9 @@ get translations(): (Translation)[] { result[\\"type\\"] = \\"Object\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -10042,7 +10060,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10062,7 +10080,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10082,7 +10100,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10125,7 +10143,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10191,7 +10209,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10211,7 +10229,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10231,7 +10249,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10251,7 +10269,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10271,7 +10289,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10291,7 +10309,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10334,7 +10352,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10354,7 +10372,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10374,7 +10392,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10394,7 +10412,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10460,7 +10478,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10523,7 +10541,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10543,7 +10561,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10563,7 +10581,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10583,7 +10601,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10686,7 +10704,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10746,7 +10764,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10766,7 +10784,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10786,7 +10804,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10870,7 +10888,9 @@ get translations(): (Translation)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -13837,6 +13857,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -13909,6 +13936,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -13924,7 +13955,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Emoji\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -13987,7 +14020,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -14285,6 +14320,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -14876,6 +14918,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -14891,11 +14937,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14937,11 +14983,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14957,7 +15003,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"ChatMessage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -14976,7 +15024,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15020,7 +15068,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15084,7 +15132,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -15779,6 +15829,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -18173,6 +18230,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -18190,7 +18251,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2DjTTboo3CNHU2a2JQqUSE2dbv9D_actor) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18210,7 +18271,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18230,7 +18291,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3JQCmF2Ww56Ag9EWRYoSZRDNCYtF_target) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18250,7 +18311,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_u4QGFbRFcYmPEKGbPv1hpBR9r5G_result) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18270,7 +18331,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_25zu2s3VxVujgEKqrDycjE284XQR_origin) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18290,7 +18351,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3c5t2x7DYRo2shwTxpkd4kYSS5WQ_instrument) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18354,7 +18415,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19167,6 +19230,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19245,6 +19315,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -19306,7 +19380,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19642,6 +19718,13 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19756,6 +19839,10 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -19803,7 +19890,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} result[\\"type\\"] = \\"PropertyValue\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -19891,7 +19980,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20354,6 +20445,13 @@ unit?: string | null;numericalValue?: Decimal | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -20472,6 +20570,10 @@ unit?: string | null;numericalValue?: Decimal | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -20513,7 +20615,9 @@ unit?: string | null;numericalValue?: Decimal | null;} result[\\"type\\"] = \\"om2:Measure\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -20598,7 +20702,9 @@ unit?: string | null;numericalValue?: Decimal | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20995,6 +21101,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -21548,6 +21661,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -21563,11 +21680,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21583,11 +21700,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21603,7 +21720,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"AnnounceAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -21622,7 +21741,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21642,7 +21761,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21706,7 +21825,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22092,6 +22213,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22170,6 +22298,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22231,7 +22363,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22616,6 +22750,13 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22828,6 +22969,10 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22968,7 +23113,9 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -23666,6 +23813,13 @@ manualApprovals?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -23850,6 +24004,10 @@ get manualApprovals(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -23930,7 +24088,9 @@ get manualApprovals(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -24338,6 +24498,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -24891,6 +25058,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -24906,11 +25077,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24926,11 +25097,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24946,7 +25117,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"LikeAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -24965,7 +25138,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -24985,7 +25158,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -25049,7 +25222,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25434,6 +25609,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -25512,6 +25694,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -25573,7 +25759,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25860,6 +26048,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -26413,6 +26608,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -26428,11 +26627,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26448,11 +26647,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26468,7 +26667,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"ReplyAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -26487,7 +26688,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26507,7 +26708,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26571,7 +26772,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -26956,6 +27159,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27034,6 +27244,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -27095,7 +27309,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -27382,6 +27598,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27934,6 +28157,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -27949,11 +28176,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27969,11 +28196,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27989,7 +28216,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"QuoteAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -28008,7 +28237,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28028,7 +28257,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28092,7 +28321,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -28477,6 +28708,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -28555,6 +28793,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -28616,7 +28858,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -29069,6 +29313,13 @@ urls?: ((URL | Link))[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -29725,6 +29976,10 @@ get urls(): ((URL | Link))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -29750,7 +30005,7 @@ get urls(): ((URL | Link))[] { compactItems = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -29770,7 +30025,7 @@ get urls(): ((URL | Link))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -29854,7 +30109,9 @@ get urls(): ((URL | Link))[] { result[\\"type\\"] = \\"Translation\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/22cd\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -29883,7 +30140,7 @@ get urls(): ((URL | Link))[] { array = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -30019,7 +30276,9 @@ get urls(): ((URL | Link))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -30664,6 +30923,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31214,6 +31480,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -31229,11 +31499,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31249,11 +31519,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31269,7 +31539,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeatureAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -31288,7 +31560,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31308,7 +31580,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31372,7 +31644,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -31754,6 +32028,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31832,6 +32113,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -31893,7 +32178,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -32357,6 +32644,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -35360,6 +35654,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -35391,11 +35689,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35411,11 +35709,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35431,11 +35729,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35451,7 +35749,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -35459,7 +35757,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35475,11 +35773,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35495,11 +35793,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35515,11 +35813,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35535,11 +35833,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35555,11 +35853,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35575,11 +35873,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35595,11 +35893,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35615,11 +35913,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35635,7 +35933,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Collection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -35677,7 +35977,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35697,7 +35997,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35717,7 +36017,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35737,7 +36037,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35757,7 +36057,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35777,7 +36077,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35797,7 +36097,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35817,7 +36117,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35837,7 +36137,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35857,7 +36157,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35877,7 +36177,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35897,7 +36197,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35961,7 +36261,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37038,6 +37340,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37369,6 +37678,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -37384,7 +37697,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -37392,7 +37705,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -37405,7 +37718,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"OrderedCollection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -37424,7 +37739,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -37488,7 +37803,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37840,6 +38157,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37969,6 +38293,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -38020,7 +38348,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeaturedCollection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"discoverable\\":\\"toot:discoverable\\",\\"Hashtag\\":\\"as:Hashtag\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -38123,7 +38453,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -38506,6 +38838,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39058,6 +39397,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -39073,11 +39416,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39093,11 +39436,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39113,7 +39456,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeaturedItem\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -39132,7 +39477,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39152,7 +39497,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39216,7 +39561,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -39688,6 +40035,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39810,6 +40164,10 @@ get endpoints(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -39870,7 +40228,9 @@ get endpoints(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -40173,6 +40533,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -40230,6 +40597,10 @@ endpoints?: (URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -40280,7 +40651,9 @@ endpoints?: (URL)[];} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -40664,6 +41037,13 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -41058,6 +41438,10 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -41085,7 +41469,7 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | array = []; for (const v of this.#_2mHVKxqA7zncjveJrDEo3pWpMZqg_verificationMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -41206,7 +41590,9 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -41819,6 +42205,13 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -42185,6 +42578,10 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -42194,7 +42591,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi compactItems = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -42214,7 +42611,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -42246,7 +42643,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi result[\\"type\\"] = \\"CryptographicKey\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://w3id.org/security/v1\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -42255,7 +42654,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi array = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -42328,7 +42727,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -42811,6 +43212,13 @@ controller?: Application | Group | Organization | Person | Service | URL | null; /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43181,6 +43589,10 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -43190,7 +43602,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; compactItems = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -43210,7 +43622,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -43242,7 +43654,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; result[\\"type\\"] = \\"Multikey\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://w3id.org/security/multikey/v1\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -43251,7 +43665,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; array = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -43327,7 +43741,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -43752,6 +44168,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43882,6 +44305,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -43937,7 +44364,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Agreement\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"},\\"Agreement\\":\\"vf:Agreement\\",\\"Commitment\\":\\"vf:Commitment\\",\\"stipulates\\":\\"vf:stipulates\\",\\"stipulatesReciprocal\\":\\"vf:stipulatesReciprocal\\",\\"satisfies\\":{\\"@id\\":\\"vf:satisfies\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44040,7 +44469,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -44484,6 +44915,13 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -44606,6 +45044,10 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -44651,7 +45093,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} result[\\"type\\"] = \\"Commitment\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"Commitment\\":\\"vf:Commitment\\",\\"satisfies\\":{\\"@id\\":\\"vf:satisfies\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44733,7 +45177,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -45225,6 +45671,13 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -45423,6 +45876,10 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -45524,7 +45981,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur result[\\"type\\"] = \\"Intent\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"Intent\\":\\"vf:Intent\\",\\"action\\":\\"vf:action\\",\\"resourceConformsTo\\":{\\"@id\\":\\"vf:resourceConformsTo\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"availableQuantity\\":\\"vf:availableQuantity\\",\\"minimumQuantity\\":\\"vf:minimumQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -45666,7 +46125,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -46246,6 +46707,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -46429,6 +46897,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -46516,7 +46988,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Proposal\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"},\\"Proposal\\":\\"vf:Proposal\\",\\"Intent\\":\\"vf:Intent\\",\\"purpose\\":\\"vf:purpose\\",\\"unitBased\\":\\"vf:unitBased\\",\\"publishes\\":\\"vf:publishes\\",\\"reciprocal\\":\\"vf:reciprocal\\",\\"action\\":\\"vf:action\\",\\"resourceConformsTo\\":{\\"@id\\":\\"vf:resourceConformsTo\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"availableQuantity\\":\\"vf:availableQuantity\\",\\"minimumQuantity\\":\\"vf:minimumQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -46659,7 +47133,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47117,6 +47593,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47195,6 +47678,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47256,7 +47743,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47517,6 +48006,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47595,6 +48091,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47656,7 +48156,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47912,6 +48414,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47990,6 +48499,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -48051,7 +48564,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -48828,6 +49343,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -53314,6 +53836,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -53348,11 +53874,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53368,11 +53894,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53417,7 +53943,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53425,7 +53951,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53441,7 +53967,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53449,7 +53975,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53465,11 +53991,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53485,11 +54011,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53505,11 +54031,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53525,11 +54051,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53545,11 +54071,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53565,11 +54091,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53585,11 +54111,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53689,7 +54215,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53709,7 +54235,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53725,7 +54251,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53745,7 +54271,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53761,11 +54287,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53813,7 +54339,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Application\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -53855,7 +54383,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53875,7 +54403,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53935,7 +54463,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53955,7 +54483,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53975,7 +54503,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53995,7 +54523,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54015,7 +54543,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54035,7 +54563,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54055,7 +54583,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54075,7 +54603,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54095,7 +54623,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54215,7 +54743,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54235,7 +54763,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54255,7 +54783,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54359,7 +54887,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56060,6 +56590,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56138,6 +56675,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56199,7 +56740,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56467,6 +57010,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56545,6 +57095,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56606,7 +57160,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56899,6 +57455,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -57490,6 +58053,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -57505,11 +58072,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57551,11 +58118,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57571,7 +58138,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Article\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -57590,7 +58159,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57634,7 +58203,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57698,7 +58267,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58166,6 +58737,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58324,6 +58902,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -58387,7 +58969,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Document\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -58516,7 +59100,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58926,6 +59512,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58998,6 +59591,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -59013,7 +59610,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Audio\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -59076,7 +59675,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59331,6 +59932,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59409,6 +60017,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59470,7 +60082,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59731,6 +60345,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59809,6 +60430,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59870,7 +60495,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -60168,6 +60795,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -60960,6 +61594,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -60975,11 +61613,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -60995,11 +61633,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61015,11 +61653,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61035,7 +61673,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"CollectionPage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -61054,7 +61694,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61074,7 +61714,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61094,7 +61734,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61158,7 +61798,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61598,6 +62240,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -61676,6 +62325,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -61737,7 +62390,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61992,6 +62647,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62070,6 +62732,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62131,7 +62797,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62384,6 +63052,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62462,6 +63137,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62523,7 +63202,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62929,6 +63610,13 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -63208,6 +63896,10 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -63329,7 +64021,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -63511,7 +64205,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -64112,6 +64808,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64184,6 +64887,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -64199,7 +64906,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Event\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -64262,7 +64971,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64518,6 +65229,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64596,6 +65314,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -64657,7 +65379,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64914,6 +65638,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64992,6 +65723,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -65053,7 +65788,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -65830,6 +66567,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -70316,6 +71060,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -70350,11 +71098,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70370,11 +71118,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70419,7 +71167,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70427,7 +71175,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70443,7 +71191,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70451,7 +71199,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70467,11 +71215,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70487,11 +71235,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70507,11 +71255,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70527,11 +71275,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70547,11 +71295,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70567,11 +71315,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70587,11 +71335,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70691,7 +71439,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70711,7 +71459,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70727,7 +71475,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70747,7 +71495,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70763,11 +71511,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70815,7 +71563,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Group\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -70857,7 +71607,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70877,7 +71627,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70937,7 +71687,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70957,7 +71707,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70977,7 +71727,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70997,7 +71747,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71017,7 +71767,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71037,7 +71787,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71057,7 +71807,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71077,7 +71827,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71097,7 +71847,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71217,7 +71967,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71237,7 +71987,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71257,7 +72007,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71361,7 +72111,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -73304,6 +74056,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -73920,6 +74679,10 @@ get names(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -74060,7 +74823,7 @@ get names(): ((string | LanguageString))[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -74068,7 +74831,7 @@ get names(): ((string | LanguageString))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -74084,7 +74847,9 @@ get names(): ((string | LanguageString))[] { result[\\"type\\"] = \\"Link\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -74262,7 +75027,7 @@ get names(): ((string | LanguageString))[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -74315,7 +75080,9 @@ get names(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -75053,6 +75820,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75111,6 +75885,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75126,7 +75904,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result[\\"type\\"] = \\"Hashtag\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"Hashtag\\":\\"as:Hashtag\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75178,7 +75958,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75425,6 +76207,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75497,6 +76286,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75512,7 +76305,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Image\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75575,7 +76370,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75831,6 +76628,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75909,6 +76713,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -75970,7 +76778,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76229,6 +77039,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76307,6 +77124,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76368,7 +77189,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76623,6 +77446,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76701,6 +77531,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76762,7 +77596,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77017,6 +77853,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77095,6 +77938,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77156,7 +78003,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77411,6 +78260,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77489,6 +78345,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77550,7 +78410,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77803,6 +78665,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77881,6 +78750,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77942,7 +78815,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78175,6 +79050,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78233,6 +79115,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -78248,7 +79134,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result[\\"type\\"] = \\"Mention\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -78300,7 +79188,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78556,6 +79446,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78634,6 +79531,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -78695,7 +79596,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78990,6 +79893,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -79581,6 +80491,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -79596,11 +80510,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79642,11 +80556,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79662,7 +80576,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Note\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -79681,7 +80597,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79725,7 +80641,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79789,7 +80705,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -80254,6 +81172,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -80613,6 +81538,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -80628,7 +81557,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -80636,7 +81565,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -80665,7 +81594,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"OrderedCollectionPage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -80684,7 +81615,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -80771,7 +81702,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -81667,6 +82600,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -86153,6 +87093,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -86187,11 +87131,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86207,11 +87151,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86256,7 +87200,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86264,7 +87208,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86280,7 +87224,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86288,7 +87232,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86304,11 +87248,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86324,11 +87268,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86344,11 +87288,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86364,11 +87308,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86384,11 +87328,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86404,11 +87348,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86424,11 +87368,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86528,7 +87472,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86548,7 +87492,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86564,7 +87508,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86584,7 +87528,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86600,11 +87544,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86652,7 +87596,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Organization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -86694,7 +87640,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86714,7 +87660,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86774,7 +87720,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86794,7 +87740,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86814,7 +87760,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86834,7 +87780,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86854,7 +87800,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86874,7 +87820,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86894,7 +87840,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86914,7 +87860,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86934,7 +87880,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87054,7 +88000,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87074,7 +88020,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87094,7 +88040,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87198,7 +88144,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -88890,6 +89838,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -88962,6 +89917,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -88977,7 +89936,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Page\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -89040,7 +90001,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -89817,6 +90780,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -94303,6 +95273,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -94337,11 +95311,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94357,11 +95331,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94406,7 +95380,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94414,7 +95388,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94430,7 +95404,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94438,7 +95412,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94454,11 +95428,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94474,11 +95448,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94494,11 +95468,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94514,11 +95488,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94534,11 +95508,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94554,11 +95528,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94574,11 +95548,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94678,7 +95652,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94698,7 +95672,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94714,7 +95688,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94734,7 +95708,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94750,11 +95724,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94802,7 +95776,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Person\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -94844,7 +95820,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94864,7 +95840,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94924,7 +95900,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94944,7 +95920,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94964,7 +95940,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94984,7 +95960,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95004,7 +95980,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95024,7 +96000,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95044,7 +96020,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95064,7 +96040,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95084,7 +96060,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95204,7 +96180,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95224,7 +96200,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95244,7 +96220,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95348,7 +96324,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -97127,6 +98105,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -97367,6 +98352,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -97478,7 +98467,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Place\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -97676,7 +98667,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -98241,6 +99234,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -98554,6 +99554,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -98569,11 +99573,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -98589,7 +99593,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Profile\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -98608,7 +99614,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -98672,7 +99678,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -99112,6 +100120,13 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -100267,6 +101282,10 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -100284,7 +101303,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2N5scKaVEcdYHFmfKYYacAwUhUgQ_oneOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100304,7 +101323,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2mV6isMTPRKbWdLCjcpiEysq5dAY_anyOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100370,7 +101389,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100414,7 +101433,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100478,7 +101497,9 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101145,6 +102166,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101223,6 +102251,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101284,7 +102316,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101539,6 +102573,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101617,6 +102658,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101678,7 +102723,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -102040,6 +103087,13 @@ relationships?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103111,6 +104165,10 @@ relationships?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -103126,11 +104184,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103146,11 +104204,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103166,11 +104224,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103186,7 +104244,9 @@ relationships?: (Object | URL)[];} result[\\"type\\"] = \\"Relationship\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -103205,7 +104265,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103225,7 +104285,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103245,7 +104305,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103309,7 +104369,9 @@ relationships?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -103759,6 +104821,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103837,6 +104906,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -103898,7 +104971,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -104675,6 +105750,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -109161,6 +110243,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -109195,11 +110281,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109215,11 +110301,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109264,7 +110350,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109272,7 +110358,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109288,7 +110374,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109296,7 +110382,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109312,11 +110398,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109332,11 +110418,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109352,11 +110438,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109372,11 +110458,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109392,11 +110478,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109412,11 +110498,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109432,11 +110518,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109536,7 +110622,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109556,7 +110642,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109572,7 +110658,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109592,7 +110678,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109608,11 +110694,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109660,7 +110746,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Service\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -109702,7 +110790,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109722,7 +110810,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109782,7 +110870,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109802,7 +110890,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109822,7 +110910,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109842,7 +110930,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109862,7 +110950,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109882,7 +110970,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109902,7 +110990,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109922,7 +111010,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109942,7 +111030,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110062,7 +111150,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110082,7 +111170,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110102,7 +111190,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110206,7 +111294,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -112011,6 +113101,13 @@ contents?: ((string | LanguageString))[];mediaType?: string | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112155,6 +113252,10 @@ get contents(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -112199,7 +113300,9 @@ get contents(): ((string | LanguageString))[] { if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -112284,7 +113387,9 @@ get contents(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -112663,6 +113768,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112741,6 +113853,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -112802,7 +113918,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113057,6 +114175,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113135,6 +114260,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -113196,7 +114325,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113498,6 +114629,13 @@ formerTypes?: (\$EntityType)[];deleted?: Temporal.Instant | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113658,6 +114796,10 @@ get formerTypes(): (\$EntityType)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -113705,7 +114847,9 @@ get formerTypes(): (\$EntityType)[] { result[\\"type\\"] = \\"Tombstone\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -113811,7 +114955,9 @@ get formerTypes(): (\$EntityType)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114194,6 +115340,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114272,6 +115425,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114333,7 +115490,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114593,6 +115752,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114671,6 +115837,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114732,7 +115902,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114990,6 +116162,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115068,6 +116247,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115129,7 +116312,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115376,6 +116561,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115448,6 +116640,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -115463,7 +116659,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Video\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -115526,7 +116724,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115780,6 +116980,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115858,6 +117065,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115919,7 +117130,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { diff --git a/packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap b/packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap index ecd4871f3..9d1276100 100644 --- a/packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap +++ b/packages/vocab-tools/src/__snapshots__/class.test.ts.node.snap @@ -31,6 +31,11 @@ import { isTrustedIriOrigin, normalizeJsonLdIris } from \\"@fedify/vocab-runtime/internal/jsonld-cache\\"; +import { + enterSignedValueScope, + resolveSignedValues, + retainedSignedValueRef +} from \\"@fedify/vocab-runtime/internal/signed-representation\\"; import { isTemporalDuration, isTemporalInstant, @@ -1227,6 +1232,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -9249,6 +9261,10 @@ get translations(): (Translation)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -9258,7 +9274,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9270,7 +9286,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9286,7 +9302,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9306,7 +9322,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9322,11 +9338,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9361,7 +9377,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9369,7 +9385,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9420,7 +9436,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9428,7 +9444,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9444,11 +9460,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9464,11 +9480,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9484,7 +9500,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9492,7 +9508,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9508,7 +9524,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9516,7 +9532,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9532,7 +9548,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9540,7 +9556,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9572,11 +9588,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9592,11 +9608,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9612,11 +9628,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9632,11 +9648,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9687,7 +9703,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9695,7 +9711,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9747,11 +9763,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9767,11 +9783,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9787,11 +9803,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9807,11 +9823,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9895,11 +9911,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9951,11 +9967,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9971,11 +9987,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9991,11 +10007,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -10031,7 +10047,9 @@ get translations(): (Translation)[] { result[\\"type\\"] = \\"Object\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -10040,7 +10058,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10060,7 +10078,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10080,7 +10098,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10123,7 +10141,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10189,7 +10207,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10209,7 +10227,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10229,7 +10247,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10249,7 +10267,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10269,7 +10287,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10289,7 +10307,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10332,7 +10350,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10352,7 +10370,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10372,7 +10390,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10392,7 +10410,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10458,7 +10476,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10521,7 +10539,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10541,7 +10559,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10561,7 +10579,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10581,7 +10599,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10684,7 +10702,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10744,7 +10762,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10764,7 +10782,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10784,7 +10802,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10868,7 +10886,9 @@ get translations(): (Translation)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -13835,6 +13855,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -13907,6 +13934,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -13922,7 +13953,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Emoji\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -13985,7 +14018,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -14283,6 +14318,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -14874,6 +14916,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -14889,11 +14935,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14935,11 +14981,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14955,7 +15001,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"ChatMessage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -14974,7 +15022,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15018,7 +15066,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15082,7 +15130,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -15777,6 +15827,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -18171,6 +18228,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -18188,7 +18249,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2DjTTboo3CNHU2a2JQqUSE2dbv9D_actor) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18208,7 +18269,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18228,7 +18289,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3JQCmF2Ww56Ag9EWRYoSZRDNCYtF_target) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18248,7 +18309,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_u4QGFbRFcYmPEKGbPv1hpBR9r5G_result) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18268,7 +18329,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_25zu2s3VxVujgEKqrDycjE284XQR_origin) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18288,7 +18349,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3c5t2x7DYRo2shwTxpkd4kYSS5WQ_instrument) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18352,7 +18413,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19165,6 +19228,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19243,6 +19313,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -19304,7 +19378,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19640,6 +19716,13 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19754,6 +19837,10 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -19801,7 +19888,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} result[\\"type\\"] = \\"PropertyValue\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -19889,7 +19978,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20352,6 +20443,13 @@ unit?: string | null;numericalValue?: Decimal | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -20470,6 +20568,10 @@ unit?: string | null;numericalValue?: Decimal | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -20511,7 +20613,9 @@ unit?: string | null;numericalValue?: Decimal | null;} result[\\"type\\"] = \\"om2:Measure\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -20596,7 +20700,9 @@ unit?: string | null;numericalValue?: Decimal | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20993,6 +21099,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -21546,6 +21659,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -21561,11 +21678,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21581,11 +21698,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21601,7 +21718,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"AnnounceAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -21620,7 +21739,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21640,7 +21759,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21704,7 +21823,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22090,6 +22211,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22168,6 +22296,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22229,7 +22361,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22614,6 +22748,13 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22826,6 +22967,10 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22966,7 +23111,9 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -23664,6 +23811,13 @@ manualApprovals?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -23848,6 +24002,10 @@ get manualApprovals(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -23928,7 +24086,9 @@ get manualApprovals(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -24336,6 +24496,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -24889,6 +25056,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -24904,11 +25075,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24924,11 +25095,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24944,7 +25115,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"LikeAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -24963,7 +25136,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -24983,7 +25156,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -25047,7 +25220,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25432,6 +25607,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -25510,6 +25692,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -25571,7 +25757,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25858,6 +26046,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -26411,6 +26606,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -26426,11 +26625,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26446,11 +26645,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26466,7 +26665,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"ReplyAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -26485,7 +26686,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26505,7 +26706,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26569,7 +26770,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -26954,6 +27157,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27032,6 +27242,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -27093,7 +27307,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -27380,6 +27596,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27932,6 +28155,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -27947,11 +28174,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27967,11 +28194,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27987,7 +28214,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"QuoteAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -28006,7 +28235,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28026,7 +28255,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28090,7 +28319,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -28475,6 +28706,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -28553,6 +28791,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -28614,7 +28856,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -29067,6 +29311,13 @@ urls?: ((URL | Link))[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -29723,6 +29974,10 @@ get urls(): ((URL | Link))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -29748,7 +30003,7 @@ get urls(): ((URL | Link))[] { compactItems = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -29768,7 +30023,7 @@ get urls(): ((URL | Link))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -29852,7 +30107,9 @@ get urls(): ((URL | Link))[] { result[\\"type\\"] = \\"Translation\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/22cd\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -29881,7 +30138,7 @@ get urls(): ((URL | Link))[] { array = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -30017,7 +30274,9 @@ get urls(): ((URL | Link))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -30662,6 +30921,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31212,6 +31478,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -31227,11 +31497,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31247,11 +31517,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31267,7 +31537,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeatureAuthorization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -31286,7 +31558,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31306,7 +31578,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31370,7 +31642,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -31752,6 +32026,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31830,6 +32111,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -31891,7 +32176,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -32355,6 +32642,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -35358,6 +35652,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -35389,11 +35687,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35409,11 +35707,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35429,11 +35727,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35449,7 +35747,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -35457,7 +35755,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35473,11 +35771,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35493,11 +35791,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35513,11 +35811,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35533,11 +35831,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35553,11 +35851,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35573,11 +35871,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35593,11 +35891,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35613,11 +35911,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35633,7 +35931,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Collection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -35675,7 +35975,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35695,7 +35995,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35715,7 +36015,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35735,7 +36035,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35755,7 +36055,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35775,7 +36075,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35795,7 +36095,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35815,7 +36115,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35835,7 +36135,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35855,7 +36155,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35875,7 +36175,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35895,7 +36195,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35959,7 +36259,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37036,6 +37338,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37367,6 +37676,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -37382,7 +37695,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -37390,7 +37703,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -37403,7 +37716,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"OrderedCollection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -37422,7 +37737,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -37486,7 +37801,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37838,6 +38155,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37967,6 +38291,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -38018,7 +38346,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeaturedCollection\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"discoverable\\":\\"toot:discoverable\\",\\"Hashtag\\":\\"as:Hashtag\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -38121,7 +38451,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -38504,6 +38836,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39056,6 +39395,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -39071,11 +39414,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39091,11 +39434,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39111,7 +39454,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"FeaturedItem\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -39130,7 +39475,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39150,7 +39495,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39214,7 +39559,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -39686,6 +40033,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39808,6 +40162,10 @@ get endpoints(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -39868,7 +40226,9 @@ get endpoints(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -40171,6 +40531,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -40228,6 +40595,10 @@ endpoints?: (URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -40278,7 +40649,9 @@ endpoints?: (URL)[];} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -40662,6 +41035,13 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -41056,6 +41436,10 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -41083,7 +41467,7 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | array = []; for (const v of this.#_2mHVKxqA7zncjveJrDEo3pWpMZqg_verificationMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -41204,7 +41588,9 @@ cryptosuite?: \\"eddsa-jcs-2022\\" | null;verificationMethod?: Multikey | URL | // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -41817,6 +42203,13 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -42183,6 +42576,10 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -42192,7 +42589,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi compactItems = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -42212,7 +42609,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -42244,7 +42641,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi result[\\"type\\"] = \\"CryptographicKey\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://w3id.org/security/v1\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -42253,7 +42652,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi array = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -42326,7 +42725,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -42809,6 +43210,13 @@ controller?: Application | Group | Organization | Person | Service | URL | null; /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43179,6 +43587,10 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -43188,7 +43600,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; compactItems = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -43208,7 +43620,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -43240,7 +43652,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; result[\\"type\\"] = \\"Multikey\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://w3id.org/security/multikey/v1\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -43249,7 +43663,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; array = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -43325,7 +43739,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -43750,6 +44166,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43880,6 +44303,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -43935,7 +44362,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Agreement\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"},\\"Agreement\\":\\"vf:Agreement\\",\\"Commitment\\":\\"vf:Commitment\\",\\"stipulates\\":\\"vf:stipulates\\",\\"stipulatesReciprocal\\":\\"vf:stipulatesReciprocal\\",\\"satisfies\\":{\\"@id\\":\\"vf:satisfies\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44038,7 +44467,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -44482,6 +44913,13 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -44604,6 +45042,10 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -44649,7 +45091,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} result[\\"type\\"] = \\"Commitment\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"Commitment\\":\\"vf:Commitment\\",\\"satisfies\\":{\\"@id\\":\\"vf:satisfies\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44731,7 +45175,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -45223,6 +45669,13 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -45421,6 +45874,10 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -45522,7 +45979,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur result[\\"type\\"] = \\"Intent\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"Intent\\":\\"vf:Intent\\",\\"action\\":\\"vf:action\\",\\"resourceConformsTo\\":{\\"@id\\":\\"vf:resourceConformsTo\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"availableQuantity\\":\\"vf:availableQuantity\\",\\"minimumQuantity\\":\\"vf:minimumQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -45664,7 +46123,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -46244,6 +46705,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -46427,6 +46895,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -46514,7 +46986,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Proposal\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"vf\\":\\"https://w3id.org/valueflows/ont/vf#\\",\\"om2\\":\\"http://www.ontology-of-units-of-measure.org/resource/om-2/\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"},\\"Proposal\\":\\"vf:Proposal\\",\\"Intent\\":\\"vf:Intent\\",\\"purpose\\":\\"vf:purpose\\",\\"unitBased\\":\\"vf:unitBased\\",\\"publishes\\":\\"vf:publishes\\",\\"reciprocal\\":\\"vf:reciprocal\\",\\"action\\":\\"vf:action\\",\\"resourceConformsTo\\":{\\"@id\\":\\"vf:resourceConformsTo\\",\\"@type\\":\\"@id\\"},\\"resourceQuantity\\":\\"vf:resourceQuantity\\",\\"availableQuantity\\":\\"vf:availableQuantity\\",\\"minimumQuantity\\":\\"vf:minimumQuantity\\",\\"hasUnit\\":\\"om2:hasUnit\\",\\"hasNumericalValue\\":\\"om2:hasNumericalValue\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -46657,7 +47131,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47115,6 +47591,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47193,6 +47676,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47254,7 +47741,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47515,6 +48004,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47593,6 +48089,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47654,7 +48154,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47910,6 +48412,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47988,6 +48497,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -48049,7 +48562,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -48826,6 +49341,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -53312,6 +53834,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -53346,11 +53872,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53366,11 +53892,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53415,7 +53941,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53423,7 +53949,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53439,7 +53965,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53447,7 +53973,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53463,11 +53989,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53483,11 +54009,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53503,11 +54029,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53523,11 +54049,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53543,11 +54069,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53563,11 +54089,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53583,11 +54109,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53687,7 +54213,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53707,7 +54233,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53723,7 +54249,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53743,7 +54269,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53759,11 +54285,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53811,7 +54337,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Application\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -53853,7 +54381,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53873,7 +54401,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53933,7 +54461,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53953,7 +54481,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53973,7 +54501,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53993,7 +54521,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54013,7 +54541,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54033,7 +54561,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54053,7 +54581,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54073,7 +54601,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54093,7 +54621,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54213,7 +54741,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54233,7 +54761,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54253,7 +54781,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54357,7 +54885,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56058,6 +56588,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56136,6 +56673,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56197,7 +56738,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56465,6 +57008,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56543,6 +57093,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56604,7 +57158,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56897,6 +57453,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -57488,6 +58051,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -57503,11 +58070,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57549,11 +58116,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57569,7 +58136,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Article\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -57588,7 +58157,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57632,7 +58201,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57696,7 +58265,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58164,6 +58735,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58322,6 +58900,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -58385,7 +58967,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Document\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -58514,7 +59098,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58924,6 +59510,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58996,6 +59589,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -59011,7 +59608,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Audio\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -59074,7 +59673,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59329,6 +59930,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59407,6 +60015,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59468,7 +60080,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59729,6 +60343,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59807,6 +60428,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59868,7 +60493,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -60166,6 +60793,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -60958,6 +61592,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -60973,11 +61611,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -60993,11 +61631,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61013,11 +61651,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61033,7 +61671,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"CollectionPage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -61052,7 +61692,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61072,7 +61712,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61092,7 +61732,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61156,7 +61796,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61596,6 +62238,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -61674,6 +62323,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -61735,7 +62388,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61990,6 +62645,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62068,6 +62730,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62129,7 +62795,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62382,6 +63050,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62460,6 +63135,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62521,7 +63200,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62927,6 +63608,13 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -63206,6 +63894,10 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -63327,7 +64019,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -63509,7 +64203,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -64110,6 +64806,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64182,6 +64885,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -64197,7 +64904,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Event\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -64260,7 +64969,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64516,6 +65227,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64594,6 +65312,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -64655,7 +65377,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64912,6 +65636,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64990,6 +65721,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -65051,7 +65786,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -65828,6 +66565,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -70314,6 +71058,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -70348,11 +71096,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70368,11 +71116,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70417,7 +71165,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70425,7 +71173,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70441,7 +71189,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70449,7 +71197,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70465,11 +71213,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70485,11 +71233,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70505,11 +71253,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70525,11 +71273,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70545,11 +71293,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70565,11 +71313,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70585,11 +71333,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70689,7 +71437,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70709,7 +71457,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70725,7 +71473,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70745,7 +71493,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70761,11 +71509,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70813,7 +71561,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Group\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -70855,7 +71605,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70875,7 +71625,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70935,7 +71685,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70955,7 +71705,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70975,7 +71725,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70995,7 +71745,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71015,7 +71765,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71035,7 +71785,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71055,7 +71805,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71075,7 +71825,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71095,7 +71845,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71215,7 +71965,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71235,7 +71985,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71255,7 +72005,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71359,7 +72109,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -73302,6 +74054,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -73918,6 +74677,10 @@ get names(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -74058,7 +74821,7 @@ get names(): ((string | LanguageString))[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -74066,7 +74829,7 @@ get names(): ((string | LanguageString))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -74082,7 +74845,9 @@ get names(): ((string | LanguageString))[] { result[\\"type\\"] = \\"Link\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -74260,7 +75025,7 @@ get names(): ((string | LanguageString))[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -74313,7 +75078,9 @@ get names(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -75051,6 +75818,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75109,6 +75883,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75124,7 +75902,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result[\\"type\\"] = \\"Hashtag\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",{\\"Hashtag\\":\\"as:Hashtag\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75176,7 +75956,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75423,6 +76205,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75495,6 +76284,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75510,7 +76303,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Image\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75573,7 +76368,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75829,6 +76626,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75907,6 +76711,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -75968,7 +76776,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76227,6 +77037,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76305,6 +77122,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76366,7 +77187,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76621,6 +77444,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76699,6 +77529,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76760,7 +77594,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77015,6 +77851,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77093,6 +77936,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77154,7 +78001,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77409,6 +78258,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77487,6 +78343,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77548,7 +78408,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77801,6 +78663,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77879,6 +78748,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77940,7 +78813,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78173,6 +79048,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78231,6 +79113,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -78246,7 +79132,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result[\\"type\\"] = \\"Mention\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -78298,7 +79186,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78554,6 +79444,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78632,6 +79529,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -78693,7 +79594,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78988,6 +79891,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -79579,6 +80489,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -79594,11 +80508,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79640,11 +80554,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79660,7 +80574,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Note\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"sensitive\\":\\"as:sensitive\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -79679,7 +80595,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79723,7 +80639,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79787,7 +80703,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -80252,6 +81170,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -80611,6 +81536,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -80626,7 +81555,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -80634,7 +81563,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -80663,7 +81592,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"OrderedCollectionPage\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\",{\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"fedibird\\":\\"http://fedibird.com/ns#\\",\\"ChatMessage\\":\\"http://litepub.social/ns#ChatMessage\\",\\"sensitive\\":\\"as:sensitive\\",\\"votersCount\\":\\"toot:votersCount\\",\\"Emoji\\":\\"toot:Emoji\\",\\"Hashtag\\":\\"as:Hashtag\\",\\"quote\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quote\\",\\"@type\\":\\"@id\\"},\\"quoteUrl\\":\\"as:quoteUrl\\",\\"_misskey_quote\\":\\"misskey:_misskey_quote\\",\\"quoteUri\\":\\"fedibird:quoteUri\\",\\"QuoteAuthorization\\":\\"https://w3id.org/fep/044f#QuoteAuthorization\\",\\"QuoteRequest\\":\\"https://w3id.org/fep/044f#QuoteRequest\\",\\"quoteAuthorization\\":{\\"@id\\":\\"https://w3id.org/fep/044f#quoteAuthorization\\",\\"@type\\":\\"@id\\"},\\"emojiReactions\\":{\\"@id\\":\\"fedibird:emojiReactions\\",\\"@type\\":\\"@id\\"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -80682,7 +81613,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -80769,7 +81700,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -81665,6 +82598,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -86151,6 +87091,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -86185,11 +87129,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86205,11 +87149,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86254,7 +87198,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86262,7 +87206,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86278,7 +87222,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86286,7 +87230,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86302,11 +87246,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86322,11 +87266,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86342,11 +87286,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86362,11 +87306,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86382,11 +87326,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86402,11 +87346,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86422,11 +87366,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86526,7 +87470,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86546,7 +87490,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86562,7 +87506,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86582,7 +87526,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86598,11 +87542,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86650,7 +87594,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Organization\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -86692,7 +87638,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86712,7 +87658,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86772,7 +87718,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86792,7 +87738,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86812,7 +87758,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86832,7 +87778,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86852,7 +87798,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86872,7 +87818,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86892,7 +87838,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86912,7 +87858,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86932,7 +87878,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87052,7 +87998,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87072,7 +88018,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87092,7 +88038,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87196,7 +88142,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -88888,6 +89836,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -88960,6 +89915,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -88975,7 +89934,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Page\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -89038,7 +89999,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -89815,6 +90778,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -94301,6 +95271,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -94335,11 +95309,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94355,11 +95329,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94404,7 +95378,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94412,7 +95386,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94428,7 +95402,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94436,7 +95410,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94452,11 +95426,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94472,11 +95446,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94492,11 +95466,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94512,11 +95486,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94532,11 +95506,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94552,11 +95526,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94572,11 +95546,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94676,7 +95650,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94696,7 +95670,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94712,7 +95686,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94732,7 +95706,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94748,11 +95722,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94800,7 +95774,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Person\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -94842,7 +95818,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94862,7 +95838,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94922,7 +95898,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94942,7 +95918,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94962,7 +95938,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94982,7 +95958,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95002,7 +95978,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95022,7 +95998,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95042,7 +96018,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95062,7 +96038,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95082,7 +96058,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95202,7 +96178,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95222,7 +96198,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95242,7 +96218,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95346,7 +96322,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -97125,6 +98103,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -97365,6 +98350,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -97476,7 +98465,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Place\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -97674,7 +98665,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -98239,6 +99232,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -98552,6 +99552,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -98567,11 +99571,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -98587,7 +99591,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Profile\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -98606,7 +99612,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -98670,7 +99676,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -99110,6 +100118,13 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -100265,6 +101280,10 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -100282,7 +101301,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2N5scKaVEcdYHFmfKYYacAwUhUgQ_oneOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100302,7 +101321,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2mV6isMTPRKbWdLCjcpiEysq5dAY_anyOf) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100368,7 +101387,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100412,7 +101431,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100476,7 +101495,9 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101143,6 +102164,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101221,6 +102249,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101282,7 +102314,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101537,6 +102571,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101615,6 +102656,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101676,7 +102721,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -102038,6 +103085,13 @@ relationships?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103109,6 +104163,10 @@ relationships?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -103124,11 +104182,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103144,11 +104202,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103164,11 +104222,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103184,7 +104242,9 @@ relationships?: (Object | URL)[];} result[\\"type\\"] = \\"Relationship\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -103203,7 +104263,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103223,7 +104283,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103243,7 +104303,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103307,7 +104367,9 @@ relationships?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -103757,6 +104819,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103835,6 +104904,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -103896,7 +104969,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -104673,6 +105748,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -109159,6 +110241,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -109193,11 +110279,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109213,11 +110299,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109262,7 +110348,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109270,7 +110356,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109286,7 +110372,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109294,7 +110380,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109310,11 +110396,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109330,11 +110416,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109350,11 +110436,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109370,11 +110456,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109390,11 +110476,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109410,11 +110496,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109430,11 +110516,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109534,7 +110620,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109554,7 +110640,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109570,7 +110656,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109590,7 +110676,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109606,11 +110692,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109658,7 +110744,9 @@ get gateways(): (URL)[] { result[\\"type\\"] = \\"Service\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/fep/ef61\\",\\"https://w3id.org/security/v1\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://www.w3.org/ns/did/v1\\",\\"https://w3id.org/security/multikey/v1\\",\\"https://gotosocial.org/ns\\",\\"https://w3id.org/fep/7aa9\\",{\\"alsoKnownAs\\":{\\"@id\\":\\"as:alsoKnownAs\\",\\"@type\\":\\"@id\\"},\\"featuredCollections\\":{\\"@id\\":\\"https://w3id.org/fep/7aa9#featuredCollections\\",\\"@type\\":\\"@id\\"},\\"manuallyApprovesFollowers\\":\\"as:manuallyApprovesFollowers\\",\\"movedTo\\":{\\"@id\\":\\"as:movedTo\\",\\"@type\\":\\"@id\\"},\\"toot\\":\\"http://joinmastodon.org/ns#\\",\\"Emoji\\":\\"toot:Emoji\\",\\"featured\\":{\\"@id\\":\\"toot:featured\\",\\"@type\\":\\"@id\\"},\\"featuredTags\\":{\\"@id\\":\\"toot:featuredTags\\",\\"@type\\":\\"@id\\"},\\"discoverable\\":\\"toot:discoverable\\",\\"suspended\\":\\"toot:suspended\\",\\"memorial\\":\\"toot:memorial\\",\\"indexable\\":\\"toot:indexable\\",\\"schema\\":\\"http://schema.org#\\",\\"PropertyValue\\":\\"schema:PropertyValue\\",\\"value\\":\\"schema:value\\",\\"misskey\\":\\"https://misskey-hub.net/ns#\\",\\"_misskey_followedMessage\\":\\"misskey:_misskey_followedMessage\\",\\"isCat\\":\\"misskey:isCat\\"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -109700,7 +110788,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109720,7 +110808,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109780,7 +110868,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109800,7 +110888,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109820,7 +110908,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109840,7 +110928,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109860,7 +110948,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109880,7 +110968,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109900,7 +110988,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109920,7 +111008,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109940,7 +111028,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110060,7 +111148,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110080,7 +111168,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110100,7 +111188,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { \\"@id\\": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110204,7 +111292,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -112009,6 +113099,13 @@ contents?: ((string | LanguageString))[];mediaType?: string | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112153,6 +113250,10 @@ get contents(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -112197,7 +113298,9 @@ get contents(): ((string | LanguageString))[] { if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = \\"https://www.w3.org/ns/activitystreams\\"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -112282,7 +113385,9 @@ get contents(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -112661,6 +113766,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112739,6 +113851,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -112800,7 +113916,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113055,6 +114173,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113133,6 +114258,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -113194,7 +114323,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113496,6 +114627,13 @@ formerTypes?: ($EntityType)[];deleted?: Temporal.Instant | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113656,6 +114794,10 @@ get formerTypes(): ($EntityType)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -113703,7 +114845,9 @@ get formerTypes(): ($EntityType)[] { result[\\"type\\"] = \\"Tombstone\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v1\\",\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -113809,7 +114953,9 @@ get formerTypes(): ($EntityType)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114192,6 +115338,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114270,6 +115423,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114331,7 +115488,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114591,6 +115750,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114669,6 +115835,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114730,7 +115900,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114988,6 +116160,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115066,6 +116245,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115127,7 +116310,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115374,6 +116559,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115446,6 +116638,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -115461,7 +116657,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result[\\"type\\"] = \\"Video\\"; if (this.id != null) result[\\"id\\"] = formatIri(this.id); result[\\"@context\\"] = [\\"https://www.w3.org/ns/activitystreams\\",\\"https://w3id.org/security/data-integrity/v2\\",{\\"digestMultibase\\":\\"https://www.w3.org/ns/credentials/v2#digestMultibase\\"},\\"https://gotosocial.org/ns\\"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -115524,7 +116722,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115778,6 +116978,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115856,6 +117063,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115917,7 +117128,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { diff --git a/packages/vocab-tools/src/__snapshots__/class.test.ts.snap b/packages/vocab-tools/src/__snapshots__/class.test.ts.snap index 4f00dc000..7e531bd16 100644 --- a/packages/vocab-tools/src/__snapshots__/class.test.ts.snap +++ b/packages/vocab-tools/src/__snapshots__/class.test.ts.snap @@ -33,6 +33,11 @@ import { isTrustedIriOrigin, normalizeJsonLdIris } from "@fedify/vocab-runtime/internal/jsonld-cache"; +import { + enterSignedValueScope, + resolveSignedValues, + retainedSignedValueRef +} from "@fedify/vocab-runtime/internal/signed-representation"; import { isTemporalDuration, isTemporalInstant, @@ -1229,6 +1234,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -9251,6 +9263,10 @@ get translations(): (Translation)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -9260,7 +9276,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9272,7 +9288,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9288,7 +9304,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9308,7 +9324,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9324,11 +9340,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9363,7 +9379,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9371,7 +9387,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9422,7 +9438,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9430,7 +9446,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9446,11 +9462,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9466,11 +9482,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9486,7 +9502,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9494,7 +9510,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9510,7 +9526,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9518,7 +9534,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9534,7 +9550,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9542,7 +9558,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9574,11 +9590,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9594,11 +9610,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9614,11 +9630,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9634,11 +9650,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9689,7 +9705,7 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -9697,7 +9713,7 @@ get translations(): (Translation)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9749,11 +9765,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9769,11 +9785,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9789,11 +9805,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9809,11 +9825,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9897,11 +9913,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9953,11 +9969,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9973,11 +9989,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -9993,11 +10009,11 @@ get translations(): (Translation)[] { compactItems = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -10033,7 +10049,9 @@ get translations(): (Translation)[] { result["type"] = "Object"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"fedibird":"http://fedibird.com/ns#","sensitive":"as:sensitive","emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -10042,7 +10060,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_49BipA5dq9eoH8LX8xdsVumveTca_attachment) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10062,7 +10080,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42CGqJ94zgQ3ZBbfHwD8Hrr2L5Py_attributedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10082,7 +10100,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3ocC3VVi88cEd5sPWL8djkZsvTN6_audience) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10125,7 +10143,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3mhZzGXSpQ431mBSz2kvych22v4e_context) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10191,7 +10209,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_86xFhmgBapoMvYqjbjRuDPayTrS_generator) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10211,7 +10229,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_33CjRLy5ujtsUrwRSCrsggvGdKuR_icon) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10231,7 +10249,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3dXrUdkARxwyJLtJcYi1AJ92H41U_image) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10251,7 +10269,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fpbDrvZgf3Kq1a5V9aByFn8kx3s_inReplyTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10271,7 +10289,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_31k5MUZJsnsPNg8dQQJieWaXTFnR_location) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10291,7 +10309,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10334,7 +10352,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_7UpwM3JWcXhADcscukEehBorf6k_replies) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10354,7 +10372,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3kAfck9PcEYt2L7xug5y99YPbANs_shares) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10374,7 +10392,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_S3ceDnpMdzoTRCccB9FkJWrEzYW_likes) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10394,7 +10412,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_kMatyyNAuxoTD8GQMBfA5ogThMR_emojiReactions) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10460,7 +10478,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_5chuqj6s95p5gg2sk1HntGfarRf_tag) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10523,7 +10541,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3hFbw7DTpHhq3cvVhkY8njhcsXbd_to) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10543,7 +10561,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_aLZupjwL8XB7tzdLgCMXdjZ6qej_bto) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10563,7 +10581,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42a1SvBs24QSLzKcfjCyNTjW5a1g_cc) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10583,7 +10601,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3qvegKUB8YLgTXRpEf8E6JZSkz2H_bcc) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10686,7 +10704,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_42rPnotok1ivQ2RNCKNbeFJgx8b8_proof) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10746,7 +10764,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_3fCeb5aXaDDd4fvkQ96BLWifBUBa_likeAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10766,7 +10784,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_YA4wdUW7rYztAQ6SjhMnJCmcmtP_replyAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10786,7 +10804,7 @@ get translations(): (Translation)[] { array = []; for (const v of this.#_446xEaDBs3Fz6MyzP3PSBaLupkbJ_announceAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -10870,7 +10888,9 @@ get translations(): (Translation)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -13837,6 +13857,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -13909,6 +13936,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -13924,7 +13955,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Emoji"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -13987,7 +14020,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -14285,6 +14320,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -14876,6 +14918,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -14891,11 +14937,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14937,11 +14983,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -14957,7 +15003,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "ChatMessage"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","Emoji":"toot:Emoji","ChatMessage":"http://litepub.social/ns#ChatMessage","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -14976,7 +15024,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15020,7 +15068,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -15084,7 +15132,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -15779,6 +15829,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -18173,6 +18230,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -18190,7 +18251,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2DjTTboo3CNHU2a2JQqUSE2dbv9D_actor) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18210,7 +18271,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18230,7 +18291,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3JQCmF2Ww56Ag9EWRYoSZRDNCYtF_target) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18250,7 +18311,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_u4QGFbRFcYmPEKGbPv1hpBR9r5G_result) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18270,7 +18331,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_25zu2s3VxVujgEKqrDycjE284XQR_origin) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18290,7 +18351,7 @@ instruments?: (Object | URL)[];} array = []; for (const v of this.#_3c5t2x7DYRo2shwTxpkd4kYSS5WQ_instrument) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -18354,7 +18415,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19167,6 +19230,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19245,6 +19315,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -19306,7 +19380,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -19642,6 +19718,13 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -19756,6 +19839,10 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -19803,7 +19890,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} result["type"] = "PropertyValue"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -19891,7 +19980,9 @@ name?: string | LanguageString | null;value?: string | LanguageString | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20354,6 +20445,13 @@ unit?: string | null;numericalValue?: Decimal | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -20472,6 +20570,10 @@ unit?: string | null;numericalValue?: Decimal | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -20513,7 +20615,9 @@ unit?: string | null;numericalValue?: Decimal | null;} result["type"] = "om2:Measure"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"om2":"http://www.ontology-of-units-of-measure.org/resource/om-2/","hasUnit":"om2:hasUnit","hasNumericalValue":"om2:hasNumericalValue"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -20598,7 +20702,9 @@ unit?: string | null;numericalValue?: Decimal | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -20995,6 +21101,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -21548,6 +21661,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -21563,11 +21680,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21583,11 +21700,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -21603,7 +21720,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "AnnounceAuthorization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -21622,7 +21741,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21642,7 +21761,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -21706,7 +21825,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22092,6 +22213,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22170,6 +22298,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22231,7 +22363,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -22616,6 +22750,13 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -22828,6 +22969,10 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -22968,7 +23113,9 @@ canFeature?: InteractionRule | null;canLike?: InteractionRule | null;canReply?: // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -23666,6 +23813,13 @@ manualApprovals?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -23850,6 +24004,10 @@ get manualApprovals(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -23930,7 +24088,9 @@ get manualApprovals(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -24338,6 +24498,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -24891,6 +25058,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -24906,11 +25077,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24926,11 +25097,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -24946,7 +25117,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "LikeAuthorization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -24965,7 +25138,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -24985,7 +25158,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -25049,7 +25222,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25434,6 +25609,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -25512,6 +25694,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -25573,7 +25759,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -25860,6 +26048,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -26413,6 +26608,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -26428,11 +26627,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26448,11 +26647,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -26468,7 +26667,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "ReplyAuthorization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -26487,7 +26688,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26507,7 +26708,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -26571,7 +26772,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -26956,6 +27159,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27034,6 +27244,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -27095,7 +27309,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -27382,6 +27598,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -27934,6 +28157,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -27949,11 +28176,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27969,11 +28196,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -27989,7 +28216,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "QuoteAuthorization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -28008,7 +28237,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28028,7 +28257,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -28092,7 +28321,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -28477,6 +28708,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -28555,6 +28793,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -28616,7 +28858,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -29069,6 +29313,13 @@ urls?: ((URL | Link))[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -29725,6 +29976,10 @@ get urls(): ((URL | Link))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -29750,7 +30005,7 @@ get urls(): ((URL | Link))[] { compactItems = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -29770,7 +30025,7 @@ get urls(): ((URL | Link))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -29854,7 +30109,9 @@ get urls(): ((URL | Link))[] { result["type"] = "Translation"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/22cd"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -29883,7 +30140,7 @@ get urls(): ((URL | Link))[] { array = []; for (const v of this.#_hQqsdZa1zG8Ra1bQ3MBVsnmGnBR) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -30019,7 +30276,9 @@ get urls(): ((URL | Link))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -30664,6 +30923,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31214,6 +31480,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -31229,11 +31499,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31249,11 +31519,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -31269,7 +31539,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "FeatureAuthorization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -31288,7 +31560,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2114kRKbujWhxEUghdkRYYKbXTGi_interactingObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31308,7 +31580,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2wHyG75YnN15CDMaFk3VNjByu4aL_interactionTarget) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -31372,7 +31644,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -31754,6 +32028,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -31832,6 +32113,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -31893,7 +32178,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -32357,6 +32644,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -35360,6 +35654,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -35391,11 +35689,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35411,11 +35709,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35431,11 +35729,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35451,7 +35749,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -35459,7 +35757,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35475,11 +35773,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35495,11 +35793,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35515,11 +35813,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35535,11 +35833,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35555,11 +35853,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35575,11 +35873,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35595,11 +35893,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35615,11 +35913,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -35635,7 +35933,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Collection"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","ChatMessage":"http://litepub.social/ns#ChatMessage","sensitive":"as:sensitive","votersCount":"toot:votersCount","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","QuoteRequest":"https://w3id.org/fep/044f#QuoteRequest","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -35677,7 +35977,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3UyUdxnyn6cDn53QKrh4MBiearma_current) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35697,7 +35997,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_J52RqweMe6hhv7RnLJMC8BExTE5_first) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35717,7 +36017,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_gyJJnyEFnuNVi1HFZKfAn3Hfn26_last) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35737,7 +36037,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35757,7 +36057,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4TB9Qd9ddtcZEpMfzbHhzafE6jaJ_likesOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35777,7 +36077,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3manzgeKiPsugpztKGiaUUwJ3ito_sharesOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35797,7 +36097,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3T3oGm3twpcQUcrnMisXQtmDZ32X_repliesOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35817,7 +36117,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bvRkAFZjMfVD8jiUWZJr5YokSeN_inboxOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35837,7 +36137,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_4AHzVZDxHjK6uEWa9UiKHGK34yYm_outboxOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35857,7 +36157,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_41aoZ5M6yRUHy3Zx8q6iuZQxtopb_followersOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35877,7 +36177,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2nXT2Ah42UjEEQF5oJQ39CbKB1xj_followingOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35897,7 +36197,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2bsySzmT3qEZcrnoe3tZ5xBjXSju_likedOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -35961,7 +36261,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37038,6 +37340,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37369,6 +37678,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -37384,7 +37697,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -37392,7 +37705,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -37405,7 +37718,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "OrderedCollection"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","ChatMessage":"http://litepub.social/ns#ChatMessage","sensitive":"as:sensitive","votersCount":"toot:votersCount","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","QuoteRequest":"https://w3id.org/fep/044f#QuoteRequest","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -37424,7 +37739,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -37488,7 +37803,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -37840,6 +38157,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -37969,6 +38293,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -38020,7 +38348,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "FeaturedCollection"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"toot":"http://joinmastodon.org/ns#","sensitive":"as:sensitive","discoverable":"toot:discoverable","Hashtag":"as:Hashtag"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -38123,7 +38453,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -38506,6 +38838,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39058,6 +39397,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -39073,11 +39416,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39093,11 +39436,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -39113,7 +39456,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "FeaturedItem"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -39132,7 +39477,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_Ht5F1pFtcuyJkybWck37rPhwyQv_featuredObject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39152,7 +39497,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2gG5sxnwav2sb69C22RbERtJ8rba_featureAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -39216,7 +39561,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -39688,6 +40035,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -39810,6 +40164,10 @@ get endpoints(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -39870,7 +40228,9 @@ get endpoints(): (URL)[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -40173,6 +40533,13 @@ endpoints?: (URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -40230,6 +40597,10 @@ endpoints?: (URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -40280,7 +40651,9 @@ endpoints?: (URL)[];} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -40664,6 +41037,13 @@ cryptosuite?: "eddsa-jcs-2022" | null;verificationMethod?: Multikey | URL | null /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -41058,6 +41438,10 @@ cryptosuite?: "eddsa-jcs-2022" | null;verificationMethod?: Multikey | URL | null ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -41085,7 +41469,7 @@ cryptosuite?: "eddsa-jcs-2022" | null;verificationMethod?: Multikey | URL | null array = []; for (const v of this.#_2mHVKxqA7zncjveJrDEo3pWpMZqg_verificationMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -41206,7 +41590,9 @@ cryptosuite?: "eddsa-jcs-2022" | null;verificationMethod?: Multikey | URL | null // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -41819,6 +42205,13 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -42185,6 +42578,10 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -42194,7 +42591,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi compactItems = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -42214,7 +42611,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -42246,7 +42643,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi result["type"] = "CryptographicKey"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = "https://w3id.org/security/v1"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -42255,7 +42654,7 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi array = []; for (const v of this.#_5UJq9NDh3ZHgswFwwdVxQvJxdx2_owner) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -42328,7 +42727,9 @@ owner?: Application | Group | Organization | Person | Service | URL | null;publi // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -42811,6 +43212,13 @@ controller?: Application | Group | Organization | Person | Service | URL | null; /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43181,6 +43589,10 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -43190,7 +43602,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; compactItems = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -43210,7 +43622,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -43242,7 +43654,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; result["type"] = "Multikey"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = "https://w3id.org/security/multikey/v1"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -43251,7 +43665,7 @@ controller?: Application | Group | Organization | Person | Service | URL | null; array = []; for (const v of this.#_2yr3eUBTP6cNcyaxKzAXWjFsnGzN_controller) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -43327,7 +43741,9 @@ controller?: Application | Group | Organization | Person | Service | URL | null; // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -43752,6 +44168,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -43882,6 +44305,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -43937,7 +44364,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Agreement"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"vf":"https://w3id.org/valueflows/ont/vf#","om2":"http://www.ontology-of-units-of-measure.org/resource/om-2/","fedibird":"http://fedibird.com/ns#","sensitive":"as:sensitive","emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"},"Agreement":"vf:Agreement","Commitment":"vf:Commitment","stipulates":"vf:stipulates","stipulatesReciprocal":"vf:stipulatesReciprocal","satisfies":{"@id":"vf:satisfies","@type":"@id"},"resourceQuantity":"vf:resourceQuantity","hasUnit":"om2:hasUnit","hasNumericalValue":"om2:hasNumericalValue"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44040,7 +44469,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -44484,6 +44915,13 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -44606,6 +45044,10 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -44651,7 +45093,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} result["type"] = "Commitment"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"vf":"https://w3id.org/valueflows/ont/vf#","om2":"http://www.ontology-of-units-of-measure.org/resource/om-2/","Commitment":"vf:Commitment","satisfies":{"@id":"vf:satisfies","@type":"@id"},"resourceQuantity":"vf:resourceQuantity","hasUnit":"om2:hasUnit","hasNumericalValue":"om2:hasNumericalValue"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -44733,7 +45177,9 @@ satisfies?: URL | null;resourceQuantity?: Measure | null;} // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -45225,6 +45671,13 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -45423,6 +45876,10 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -45524,7 +45981,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur result["type"] = "Intent"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"vf":"https://w3id.org/valueflows/ont/vf#","om2":"http://www.ontology-of-units-of-measure.org/resource/om-2/","Intent":"vf:Intent","action":"vf:action","resourceConformsTo":{"@id":"vf:resourceConformsTo","@type":"@id"},"resourceQuantity":"vf:resourceQuantity","availableQuantity":"vf:availableQuantity","minimumQuantity":"vf:minimumQuantity","hasUnit":"om2:hasUnit","hasNumericalValue":"om2:hasNumericalValue"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -45666,7 +46125,9 @@ action?: string | null;resourceConformsTo?: URL | null;resourceQuantity?: Measur // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -46246,6 +46707,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -46429,6 +46897,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -46516,7 +46988,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Proposal"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"vf":"https://w3id.org/valueflows/ont/vf#","om2":"http://www.ontology-of-units-of-measure.org/resource/om-2/","fedibird":"http://fedibird.com/ns#","sensitive":"as:sensitive","emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"},"Proposal":"vf:Proposal","Intent":"vf:Intent","purpose":"vf:purpose","unitBased":"vf:unitBased","publishes":"vf:publishes","reciprocal":"vf:reciprocal","action":"vf:action","resourceConformsTo":{"@id":"vf:resourceConformsTo","@type":"@id"},"resourceQuantity":"vf:resourceQuantity","availableQuantity":"vf:availableQuantity","minimumQuantity":"vf:minimumQuantity","hasUnit":"om2:hasUnit","hasNumericalValue":"om2:hasNumericalValue"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -46659,7 +47133,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47117,6 +47593,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47195,6 +47678,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47256,7 +47743,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47517,6 +48006,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47595,6 +48091,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -47656,7 +48156,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -47912,6 +48414,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -47990,6 +48499,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -48051,7 +48564,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -48828,6 +49343,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -53314,6 +53836,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -53348,11 +53874,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53368,11 +53894,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53417,7 +53943,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53425,7 +53951,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53441,7 +53967,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53449,7 +53975,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53465,11 +53991,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53485,11 +54011,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53505,11 +54031,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53525,11 +54051,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53545,11 +54071,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53565,11 +54091,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53585,11 +54111,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53689,7 +54215,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53709,7 +54235,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53725,7 +54251,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -53745,7 +54271,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53761,11 +54287,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -53813,7 +54339,9 @@ get gateways(): (URL)[] { result["type"] = "Application"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61","https://w3id.org/security/v1","https://w3id.org/security/data-integrity/v1","https://www.w3.org/ns/did/v1","https://w3id.org/security/multikey/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"alsoKnownAs":{"@id":"as:alsoKnownAs","@type":"@id"},"featuredCollections":{"@id":"https://w3id.org/fep/7aa9#featuredCollections","@type":"@id"},"manuallyApprovesFollowers":"as:manuallyApprovesFollowers","movedTo":{"@id":"as:movedTo","@type":"@id"},"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji","featured":{"@id":"toot:featured","@type":"@id"},"featuredTags":{"@id":"toot:featuredTags","@type":"@id"},"discoverable":"toot:discoverable","suspended":"toot:suspended","memorial":"toot:memorial","indexable":"toot:indexable","schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value","misskey":"https://misskey-hub.net/ns#","_misskey_followedMessage":"misskey:_misskey_followedMessage","isCat":"misskey:isCat"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -53855,7 +54383,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53875,7 +54403,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53935,7 +54463,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53955,7 +54483,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53975,7 +54503,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -53995,7 +54523,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54015,7 +54543,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54035,7 +54563,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54055,7 +54583,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54075,7 +54603,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54095,7 +54623,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54215,7 +54743,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54235,7 +54763,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54255,7 +54783,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -54359,7 +54887,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56060,6 +56590,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56138,6 +56675,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56199,7 +56740,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56467,6 +57010,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -56545,6 +57095,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -56606,7 +57160,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -56899,6 +57455,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -57490,6 +58053,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -57505,11 +58072,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57551,11 +58118,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -57571,7 +58138,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Article"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","sensitive":"as:sensitive","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -57590,7 +58159,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57634,7 +58203,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -57698,7 +58267,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58166,6 +58737,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58324,6 +58902,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -58387,7 +58969,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Document"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v2",{"digestMultibase":"https://www.w3.org/ns/credentials/v2#digestMultibase"},"https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -58516,7 +59100,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -58926,6 +59512,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -58998,6 +59591,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -59013,7 +59610,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Audio"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v2",{"digestMultibase":"https://www.w3.org/ns/credentials/v2#digestMultibase"},"https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -59076,7 +59675,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59331,6 +59932,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59409,6 +60017,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59470,7 +60082,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -59731,6 +60345,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -59809,6 +60430,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -59870,7 +60495,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -60168,6 +60795,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -60960,6 +61594,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -60975,11 +61613,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -60995,11 +61633,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61015,11 +61653,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -61035,7 +61673,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "CollectionPage"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","ChatMessage":"http://litepub.social/ns#ChatMessage","sensitive":"as:sensitive","votersCount":"toot:votersCount","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","QuoteRequest":"https://w3id.org/fep/044f#QuoteRequest","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -61054,7 +61694,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2kWgBhQKjEauxx8C6qF3ZQamK4Le_partOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61074,7 +61714,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3BT4kQLcXhHx7TAWaNDKh8nFn9eY_next) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61094,7 +61734,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3b8yG8tDNzQFFEnWhCc13G8eHooA_prev) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -61158,7 +61798,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61598,6 +62240,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -61676,6 +62325,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -61737,7 +62390,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -61992,6 +62647,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62070,6 +62732,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62131,7 +62797,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62384,6 +63052,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -62462,6 +63137,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -62523,7 +63202,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -62929,6 +63610,13 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -63208,6 +63896,10 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -63329,7 +64021,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = "https://www.w3.org/ns/activitystreams"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -63511,7 +64205,9 @@ proxyUrl?: URL | null;oauthAuthorizationEndpoint?: URL | null;oauthTokenEndpoint // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -64112,6 +64808,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64184,6 +64887,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -64199,7 +64906,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Event"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -64262,7 +64971,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64518,6 +65229,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64596,6 +65314,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -64657,7 +65379,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -64914,6 +65638,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -64992,6 +65723,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -65053,7 +65788,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -65830,6 +66567,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -70316,6 +71060,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -70350,11 +71098,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70370,11 +71118,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70419,7 +71167,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70427,7 +71175,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70443,7 +71191,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70451,7 +71199,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70467,11 +71215,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70487,11 +71235,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70507,11 +71255,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70527,11 +71275,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70547,11 +71295,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70567,11 +71315,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70587,11 +71335,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70691,7 +71439,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70711,7 +71459,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70727,7 +71475,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -70747,7 +71495,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70763,11 +71511,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -70815,7 +71563,9 @@ get gateways(): (URL)[] { result["type"] = "Group"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61","https://w3id.org/security/v1","https://w3id.org/security/data-integrity/v1","https://www.w3.org/ns/did/v1","https://w3id.org/security/multikey/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"alsoKnownAs":{"@id":"as:alsoKnownAs","@type":"@id"},"featuredCollections":{"@id":"https://w3id.org/fep/7aa9#featuredCollections","@type":"@id"},"manuallyApprovesFollowers":"as:manuallyApprovesFollowers","movedTo":{"@id":"as:movedTo","@type":"@id"},"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji","featured":{"@id":"toot:featured","@type":"@id"},"featuredTags":{"@id":"toot:featuredTags","@type":"@id"},"discoverable":"toot:discoverable","suspended":"toot:suspended","memorial":"toot:memorial","indexable":"toot:indexable","schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value","misskey":"https://misskey-hub.net/ns#","_misskey_followedMessage":"misskey:_misskey_followedMessage","isCat":"misskey:isCat"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -70857,7 +71607,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70877,7 +71627,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70937,7 +71687,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70957,7 +71707,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70977,7 +71727,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -70997,7 +71747,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71017,7 +71767,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71037,7 +71787,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71057,7 +71807,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71077,7 +71827,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71097,7 +71847,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71217,7 +71967,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71237,7 +71987,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71257,7 +72007,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -71361,7 +72111,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -73304,6 +74056,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -73920,6 +74679,10 @@ get names(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -74060,7 +74823,7 @@ get names(): ((string | LanguageString))[] { compactItems = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Link ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -74068,7 +74831,7 @@ get names(): ((string | LanguageString))[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -74084,7 +74847,9 @@ get names(): ((string | LanguageString))[] { result["type"] = "Link"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -74262,7 +75027,7 @@ get names(): ((string | LanguageString))[] { array = []; for (const v of this.#_gCVTegXxWWCw6wWRxa1QF65zusg_preview) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Link ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -74315,7 +75080,9 @@ get names(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -75053,6 +75820,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75111,6 +75885,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75126,7 +75904,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result["type"] = "Hashtag"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams",{"Hashtag":"as:Hashtag"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75178,7 +75958,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75425,6 +76207,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75497,6 +76286,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -75512,7 +76305,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Image"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v2",{"digestMultibase":"https://www.w3.org/ns/credentials/v2#digestMultibase"},"https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -75575,7 +76370,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -75831,6 +76628,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -75909,6 +76713,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -75970,7 +76778,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76229,6 +77039,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76307,6 +77124,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76368,7 +77189,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -76623,6 +77446,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -76701,6 +77531,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -76762,7 +77596,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77017,6 +77853,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77095,6 +77938,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77156,7 +78003,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77411,6 +78260,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77489,6 +78345,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77550,7 +78410,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -77803,6 +78665,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -77881,6 +78750,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -77942,7 +78815,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78175,6 +79050,13 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78233,6 +79115,10 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -78248,7 +79134,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num result["type"] = "Mention"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = "https://www.w3.org/ns/activitystreams"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -78300,7 +79188,9 @@ names?: ((string | LanguageString))[];language?: Intl.Locale | null;height?: num // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78556,6 +79446,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -78634,6 +79531,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -78695,7 +79596,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -78990,6 +79893,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -79581,6 +80491,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -79596,11 +80510,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79642,11 +80556,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -79662,7 +80576,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Note"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","sensitive":"as:sensitive","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -79681,7 +80597,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79725,7 +80641,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -79789,7 +80705,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -80254,6 +81172,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -80613,6 +81538,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -80628,7 +81557,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Object ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -80636,7 +81565,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -80665,7 +81594,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "OrderedCollectionPage"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns",{"toot":"http://joinmastodon.org/ns#","misskey":"https://misskey-hub.net/ns#","fedibird":"http://fedibird.com/ns#","ChatMessage":"http://litepub.social/ns#ChatMessage","sensitive":"as:sensitive","votersCount":"toot:votersCount","Emoji":"toot:Emoji","Hashtag":"as:Hashtag","quote":{"@id":"https://w3id.org/fep/044f#quote","@type":"@id"},"quoteUrl":"as:quoteUrl","_misskey_quote":"misskey:_misskey_quote","quoteUri":"fedibird:quoteUri","QuoteAuthorization":"https://w3id.org/fep/044f#QuoteAuthorization","QuoteRequest":"https://w3id.org/fep/044f#QuoteRequest","quoteAuthorization":{"@id":"https://w3id.org/fep/044f#quoteAuthorization","@type":"@id"},"emojiReactions":{"@id":"fedibird:emojiReactions","@type":"@id"}}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -80684,7 +81615,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_2JPCKWTcfBmTCcW8Tv3TpRaLVaqg_items) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Object ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -80771,7 +81702,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -81667,6 +82600,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -86153,6 +87093,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -86187,11 +87131,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86207,11 +87151,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86256,7 +87200,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86264,7 +87208,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86280,7 +87224,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86288,7 +87232,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86304,11 +87248,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86324,11 +87268,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86344,11 +87288,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86364,11 +87308,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86384,11 +87328,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86404,11 +87348,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86424,11 +87368,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86528,7 +87472,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86548,7 +87492,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86564,7 +87508,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -86584,7 +87528,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86600,11 +87544,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -86652,7 +87596,9 @@ get gateways(): (URL)[] { result["type"] = "Organization"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61","https://w3id.org/security/v1","https://w3id.org/security/data-integrity/v1","https://www.w3.org/ns/did/v1","https://w3id.org/security/multikey/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"alsoKnownAs":{"@id":"as:alsoKnownAs","@type":"@id"},"featuredCollections":{"@id":"https://w3id.org/fep/7aa9#featuredCollections","@type":"@id"},"manuallyApprovesFollowers":"as:manuallyApprovesFollowers","movedTo":{"@id":"as:movedTo","@type":"@id"},"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji","featured":{"@id":"toot:featured","@type":"@id"},"featuredTags":{"@id":"toot:featuredTags","@type":"@id"},"discoverable":"toot:discoverable","suspended":"toot:suspended","memorial":"toot:memorial","indexable":"toot:indexable","schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value","misskey":"https://misskey-hub.net/ns#","_misskey_followedMessage":"misskey:_misskey_followedMessage","isCat":"misskey:isCat"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -86694,7 +87640,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86714,7 +87660,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86774,7 +87720,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86794,7 +87740,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86814,7 +87760,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86834,7 +87780,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86854,7 +87800,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86874,7 +87820,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86894,7 +87840,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86914,7 +87860,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -86934,7 +87880,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87054,7 +88000,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87074,7 +88020,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87094,7 +88040,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -87198,7 +88144,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -88890,6 +89838,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -88962,6 +89917,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -88977,7 +89936,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Page"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v2",{"digestMultibase":"https://www.w3.org/ns/credentials/v2#digestMultibase"},"https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -89040,7 +90001,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -89817,6 +90780,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -94303,6 +95273,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -94337,11 +95311,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94357,11 +95331,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94406,7 +95380,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94414,7 +95388,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94430,7 +95404,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94438,7 +95412,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94454,11 +95428,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94474,11 +95448,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94494,11 +95468,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94514,11 +95488,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94534,11 +95508,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94554,11 +95528,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94574,11 +95548,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94678,7 +95652,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94698,7 +95672,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94714,7 +95688,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -94734,7 +95708,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94750,11 +95724,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -94802,7 +95776,9 @@ get gateways(): (URL)[] { result["type"] = "Person"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61","https://w3id.org/security/v1","https://w3id.org/security/data-integrity/v1","https://www.w3.org/ns/did/v1","https://w3id.org/security/multikey/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"alsoKnownAs":{"@id":"as:alsoKnownAs","@type":"@id"},"featuredCollections":{"@id":"https://w3id.org/fep/7aa9#featuredCollections","@type":"@id"},"manuallyApprovesFollowers":"as:manuallyApprovesFollowers","movedTo":{"@id":"as:movedTo","@type":"@id"},"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji","featured":{"@id":"toot:featured","@type":"@id"},"featuredTags":{"@id":"toot:featuredTags","@type":"@id"},"discoverable":"toot:discoverable","suspended":"toot:suspended","memorial":"toot:memorial","indexable":"toot:indexable","schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value","misskey":"https://misskey-hub.net/ns#","_misskey_followedMessage":"misskey:_misskey_followedMessage","isCat":"misskey:isCat"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -94844,7 +95820,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94864,7 +95840,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94924,7 +95900,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94944,7 +95920,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94964,7 +95940,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -94984,7 +95960,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95004,7 +95980,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95024,7 +96000,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95044,7 +96020,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95064,7 +96040,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95084,7 +96060,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95204,7 +96180,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95224,7 +96200,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95244,7 +96220,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -95348,7 +96324,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -97127,6 +98105,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -97367,6 +98352,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -97478,7 +98467,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Place"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -97676,7 +98667,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -98241,6 +99234,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -98554,6 +99554,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -98569,11 +99573,11 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu compactItems = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -98589,7 +99593,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Profile"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -98608,7 +99614,7 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu array = []; for (const v of this.#_3CLQ1PLSXrhSQbTGGHuxNyaEFKM1_describes) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -98672,7 +99678,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -99112,6 +100120,13 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -100267,6 +101282,10 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -100284,7 +101303,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2N5scKaVEcdYHFmfKYYacAwUhUgQ_oneOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100304,7 +101323,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_2mV6isMTPRKbWdLCjcpiEysq5dAY_anyOf) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100370,7 +101389,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_3obhVLFML2Fh2Qsbg3BM2dec8S9e_quote) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100414,7 +101433,7 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti array = []; for (const v of this.#_ZKAEiJeuEvjeYkC4pG58D5vAJ4m_quoteAuthorization) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -100478,7 +101497,9 @@ instruments?: (Object | URL)[];exclusiveOptions?: (Object | URL)[];inclusiveOpti } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101145,6 +102166,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101223,6 +102251,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101284,7 +102316,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -101539,6 +102573,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -101617,6 +102658,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -101678,7 +102723,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -102040,6 +103087,13 @@ relationships?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103111,6 +104165,10 @@ relationships?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -103126,11 +104184,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103146,11 +104204,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103166,11 +104224,11 @@ relationships?: (Object | URL)[];} compactItems = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -103186,7 +104244,9 @@ relationships?: (Object | URL)[];} result["type"] = "Relationship"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -103205,7 +104265,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2Zqdmi46ZnDQsECS6mzwhrv3rUKq_subject) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103225,7 +104285,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_2MH19yxjn1wnHsNfa5n4JBhJzxyc_object) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103245,7 +104305,7 @@ relationships?: (Object | URL)[];} array = []; for (const v of this.#_4Lzz89F9qipAQSGkWyX9DGWiUojG_relationship) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -103309,7 +104369,9 @@ relationships?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -103759,6 +104821,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -103837,6 +104906,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -103898,7 +104971,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -104675,6 +105750,13 @@ services?: (DidService | URL)[];followedMessage?: string | null;cat?: boolean | /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -109161,6 +110243,10 @@ get gateways(): (URL)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -109195,11 +110281,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109215,11 +110301,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109264,7 +110350,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109272,7 +110358,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109288,7 +110374,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof OrderedCollection ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109296,7 +110382,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109312,11 +110398,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109332,11 +110418,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109352,11 +110438,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109372,11 +110458,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109392,11 +110478,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109412,11 +110498,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109432,11 +110518,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109536,7 +110622,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109556,7 +110642,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109572,7 +110658,7 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { const item = ( - v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : v instanceof Application ? await v.toJsonLd({ ...(options), format: undefined, context: undefined, @@ -109592,7 +110678,7 @@ get gateways(): (URL)[] { ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109608,11 +110694,11 @@ get gateways(): (URL)[] { compactItems = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { const item = ( - v instanceof URL ? formatIri(v) : await v.toJsonLd({ + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? formatIri(v) : await v.toJsonLd({ ...(options), format: undefined, context: undefined, - }) + })) ); compactItems.push(item); } @@ -109660,7 +110746,9 @@ get gateways(): (URL)[] { result["type"] = "Service"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/fep/ef61","https://w3id.org/security/v1","https://w3id.org/security/data-integrity/v1","https://www.w3.org/ns/did/v1","https://w3id.org/security/multikey/v1","https://gotosocial.org/ns","https://w3id.org/fep/7aa9",{"alsoKnownAs":{"@id":"as:alsoKnownAs","@type":"@id"},"featuredCollections":{"@id":"https://w3id.org/fep/7aa9#featuredCollections","@type":"@id"},"manuallyApprovesFollowers":"as:manuallyApprovesFollowers","movedTo":{"@id":"as:movedTo","@type":"@id"},"toot":"http://joinmastodon.org/ns#","Emoji":"toot:Emoji","featured":{"@id":"toot:featured","@type":"@id"},"featuredTags":{"@id":"toot:featuredTags","@type":"@id"},"discoverable":"toot:discoverable","suspended":"toot:suspended","memorial":"toot:memorial","indexable":"toot:indexable","schema":"http://schema.org#","PropertyValue":"schema:PropertyValue","value":"schema:value","misskey":"https://misskey-hub.net/ns#","_misskey_followedMessage":"misskey:_misskey_followedMessage","isCat":"misskey:isCat"}]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -109702,7 +110790,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_axq166E2eZADq34V4MYUc8KMZdC_publicKey) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109722,7 +110810,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4EHQFWZSz1k1d4LmPrQiMba2GbP3_assertionMethod) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109782,7 +110870,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3ghX3VfZXXbLvhCRH7QJqpzLrXjB_inbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109802,7 +110890,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_41QwhqJouoLg3h8dRPKat21brynC_outbox) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof OrderedCollection ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109822,7 +110910,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3yAv8jymNfNuJUDuBzJ1NQhdbAee_following) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109842,7 +110930,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_BBCTgfphhsFzpVfKTykGSpBNwoA_followers) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109862,7 +110950,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3bgkPwJanyTCoVFM9ovRcus8tKkU_liked) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109882,7 +110970,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4N1vBJzXDf8NbBumeECQMFvKetja_featured) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109902,7 +110990,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2MxnRRLq9iPzx5CFq2NPrXdUDCac_featuredTags) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109922,7 +111010,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_43Vdn8myiwHqPANJwoAEF3Yy3vsd_featuredCollections) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -109942,7 +111030,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3sG2Hdwn9qzKGu9mpYkqakAMUkH9_streams) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110062,7 +111150,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_2ZNWDhuNdSXBwEmrB5kwffdKGzok_movedTo) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110082,7 +111170,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_3NV7TGNhuABbryNjNi4wib4DgNpY_alsoKnownAs) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : v instanceof Application ? await v.toJsonLd(options) : v instanceof Group ? await v.toJsonLd(options) : v instanceof Organization ? await v.toJsonLd(options) : v instanceof Person ? await v.toJsonLd(options) : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110102,7 +111190,7 @@ get gateways(): (URL)[] { array = []; for (const v of this.#_4Q6NrKH6bazBGtxwG8vyG77ir7Tg_service) { let element = ( - v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options) + retainedSignedValueRef(v, signedValues.scope) ?? (v instanceof URL ? { "@id": formatIri(v) } : await v.toJsonLd(options)) ); if (Array.isArray(element)) { if (element.length < 1) continue; @@ -110206,7 +111294,9 @@ get gateways(): (URL)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -112011,6 +113101,13 @@ contents?: ((string | LanguageString))[];mediaType?: string | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112155,6 +113252,10 @@ get contents(): ((string | LanguageString))[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { const result: Record = {}; @@ -112199,7 +113300,9 @@ get contents(): ((string | LanguageString))[] { if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = "https://www.w3.org/ns/activitystreams"; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -112284,7 +113387,9 @@ get contents(): ((string | LanguageString))[] { // Embed context } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected isCompactable(): boolean { @@ -112663,6 +113768,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -112741,6 +113853,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -112802,7 +113918,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113057,6 +114175,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113135,6 +114260,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -113196,7 +114325,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -113498,6 +114629,13 @@ formerTypes?: ($EntityType)[];deleted?: Temporal.Instant | null;} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -113658,6 +114796,10 @@ get formerTypes(): ($EntityType)[] { ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -113705,7 +114847,9 @@ get formerTypes(): ($EntityType)[] { result["type"] = "Tombstone"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v1","https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -113811,7 +114955,9 @@ get formerTypes(): ($EntityType)[] { } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114194,6 +115340,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114272,6 +115425,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114333,7 +115490,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114593,6 +115752,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -114671,6 +115837,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -114732,7 +115902,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -114990,6 +116162,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115068,6 +116247,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115129,7 +116312,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115376,6 +116561,13 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115448,6 +116640,10 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); if (options.format == null && this.isCompactable()) { @@ -115463,7 +116659,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu result["type"] = "Video"; if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ["https://www.w3.org/ns/activitystreams","https://w3id.org/security/data-integrity/v2",{"digestMultibase":"https://www.w3.org/ns/credentials/v2#digestMultibase"},"https://gotosocial.org/ns"]; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } // deno-lint-ignore no-unused-vars prefer-const @@ -115526,7 +116724,9 @@ proofs?: (DataIntegrityProof | URL)[];interactionPolicy?: InteractionPolicy | nu } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { @@ -115780,6 +116980,13 @@ instruments?: (Object | URL)[];} /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. @@ -115858,6 +117065,10 @@ instruments?: (Object | URL)[];} ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); // deno-lint-ignore no-unused-vars prefer-const let array: unknown[]; @@ -115919,7 +117130,9 @@ instruments?: (Object | URL)[];} } } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected override isCompactable(): boolean { diff --git a/packages/vocab-tools/src/class.ts b/packages/vocab-tools/src/class.ts index 687e04746..cdfda68d2 100644 --- a/packages/vocab-tools/src/class.ts +++ b/packages/vocab-tools/src/class.ts @@ -18,6 +18,11 @@ const INTERNAL_RUNTIME_IMPORTS = [ "isTrustedIriOrigin", "normalizeJsonLdIris", ].join(",\n "); +const SIGNED_REPRESENTATION_IMPORTS = [ + "enterSignedValueScope", + "resolveSignedValues", + "retainedSignedValueRef", +].join(",\n "); const RUNTIME_IMPORTS = [ "canParseDecimal", "decodeMultibase", @@ -268,6 +273,7 @@ export async function* generateClasses( from "@opentelemetry/api";\n`; yield `import {\n ${RUNTIME_IMPORTS}\n} from "@fedify/vocab-runtime";\n`; yield `import {\n ${INTERNAL_RUNTIME_IMPORTS}\n} from "@fedify/vocab-runtime/internal/jsonld-cache";\n`; + yield `import {\n ${SIGNED_REPRESENTATION_IMPORTS}\n} from "@fedify/vocab-runtime/internal/signed-representation";\n`; yield `import { isTemporalDuration, isTemporalInstant, diff --git a/packages/vocab-tools/src/codec.ts b/packages/vocab-tools/src/codec.ts index 48ee93c50..afa7ce27e 100644 --- a/packages/vocab-tools/src/codec.ts +++ b/packages/vocab-tools/src/codec.ts @@ -95,6 +95,10 @@ export async function* generateEncoder( ...options, contextLoader: options.contextLoader ?? getDocumentLoader(), }; + // Joins the enclosing frame's signed-value scope, or starts one when this + // frame is the outermost. Only the owning frame puts retained signed + // child documents back in place of their placeholders. + const signedValues = enterSignedValueScope(options); `; if (isCompactableType(typeUri, types)) { yield ` @@ -127,6 +131,7 @@ export async function* generateEncoder( const item = ( `; if (!areAllScalarTypes(property.range, types)) { + yield "retainedSignedValueRef(v, signedValues.scope) ?? ("; yield "v instanceof URL ? formatIri(v) : "; } const encoders = getEncoders( @@ -137,6 +142,7 @@ export async function* generateEncoder( true, ); for (const code of encoders) yield code; + if (!areAllScalarTypes(property.range, types)) yield ")"; yield ` ); compactItems.push(item); @@ -180,7 +186,9 @@ export async function* generateEncoder( } if (this.id != null) result["id"] = formatIri(this.id); result["@context"] = ${JSON.stringify(type.defaultContext)}; - return result; + return signedValues.owner + ? resolveSignedValues(result, signedValues.scope) + : result; } `; } @@ -210,11 +218,13 @@ export async function* generateEncoder( let element = ( `; if (!areAllScalarTypes(property.range, types)) { + yield "retainedSignedValueRef(v, signedValues.scope) ?? ("; yield 'v instanceof URL ? { "@id": formatIri(v) } : '; } for (const code of getEncoders(property.range, types, "v", "options")) { yield code; } + if (!areAllScalarTypes(property.range, types)) yield ")"; yield ` ); if (Array.isArray(element)) { @@ -325,7 +335,9 @@ export async function* generateEncoder( } yield ` } - return compacted; + return signedValues.owner + ? resolveSignedValues(compacted, signedValues.scope) + : compacted; } protected ${emitOverride(typeUri, types)} isCompactable(): boolean { diff --git a/packages/vocab-tools/src/constructor.ts b/packages/vocab-tools/src/constructor.ts index ed07715cf..87d5e30e6 100644 --- a/packages/vocab-tools/src/constructor.ts +++ b/packages/vocab-tools/src/constructor.ts @@ -208,6 +208,13 @@ export async function* generateCloner( yield ` /** * Clones this instance, optionally updating it with the given values. + * + * A clone never inherits a signed JSON-LD representation retained by + * \`signObject()\`: the clone may differ from the document that the proof + * covers, so embedding the original secured JSON in a parent document + * would be wrong. Sign the clone again if it has to be embedded as a + * secured child. + * * @param values The values to update the clone with. * @param options The options to use for cloning. * @returns The cloned instance. diff --git a/packages/vocab/src/signed-representation.test.ts b/packages/vocab/src/signed-representation.test.ts new file mode 100644 index 000000000..b658f06a8 --- /dev/null +++ b/packages/vocab/src/signed-representation.test.ts @@ -0,0 +1,277 @@ +import { mockDocumentLoader, test } from "@fedify/fixture"; +import { + isMarkerSafeContext, + retainSignedRepresentation, +} from "@fedify/vocab-runtime/internal/signed-representation"; +import { assert, assertEquals } from "@std/assert"; +import * as vocab from "./vocab.ts"; +import { + Announce, + Create, + Note, + OrderedCollection, + Question, +} from "./vocab.ts"; + +const securedNote = { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + { ex: "https://example.com/ns#" }, + ], + id: "https://example.com/notes/1", + type: "Note", + content: "Hello", + proof: { + "@context": [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + { ex: "https://example.com/ns#" }, + ], + type: "DataIntegrityProof", + cryptosuite: "eddsa-jcs-2022", + created: "2023-02-24T23:36:38Z", + verificationMethod: "https://example.com/person#ed25519-key", + proofPurpose: "assertionMethod", + proofValue: "z3FXQ", + }, +}; + +const options = { contextLoader: mockDocumentLoader }; + +function retainedNote(): Note { + const note = new Note({ + id: new URL("https://example.com/notes/1"), + content: "Hello", + }); + retainSignedRepresentation(note, structuredClone(securedNote)); + return note; +} + +test("nested serialization embeds a retained signed representation", async () => { + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }); + const compact = await create.toJsonLd({ + format: "compact", + ...options, + }) as Record; + + // `Create` is not compactable, so this goes through the expand-then-compact + // path, which would otherwise dissolve the child's own contexts. + assertEquals(compact.object, securedNote); +}); + +test("nested serialization embeds a retained representation through a compactable parent", async () => { + const wrapper = new Note({ + id: new URL("https://example.com/notes/wrapper"), + attachments: [retainedNote()], + }); + const compact = await wrapper.toJsonLd(options) as Record; + assertEquals(compact.attachment, securedNote); + + // … and still when a non-compactable ancestor compacts the whole tree. + const question = new Question({ + id: new URL("https://example.com/questions/1"), + exclusiveOptions: [wrapper], + }); + const compacted = await question.toJsonLd(options) as Record; + const embeddedWrapper = compacted.oneOf as Record; + assertEquals(embeddedWrapper.attachment, securedNote); +}); + +test("nested serialization embeds one retained representation many times", async () => { + const note = retainedNote(); + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + objects: [note, note], + tags: [note], + }); + const compact = await create.toJsonLd({ + format: "compact", + ...options, + }) as Record; + const objects = compact.object as Record[]; + + assertEquals(objects.length, 2); + assertEquals(objects[0], securedNote); + assertEquals(objects[1], securedNote); + assertEquals(compact.tag, securedNote); + // Each site gets its own copy rather than an alias of one object. + assert(objects[0] !== objects[1]); + assert(objects[0] !== compact.tag); +}); + +test("nested serialization embeds a retained representation at any depth", async () => { + const announce = new Announce({ + id: new URL("https://example.com/activities/2"), + actor: new URL("https://example.com/person"), + object: new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }), + }); + const compact = await announce.toJsonLd({ + format: "compact", + ...options, + }) as Record; + const create = compact.object as Record; + + assertEquals(create.object, securedNote); +}); + +test("expanded serialization ignores a retained signed representation", async () => { + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }); + const expanded = await create.toJsonLd({ + format: "expand", + ...options, + }) as Record[]; + const objects = expanded[0][ + "https://www.w3.org/ns/activitystreams#object" + ] as Record[]; + + // An expanded document has no compact representation to preserve, so the + // child is expanded like any other object. + assertEquals( + objects[0]["@id"], + "https://example.com/notes/1", + ); + assertEquals( + objects[0]["@type"], + ["https://www.w3.org/ns/activitystreams#Note"], + ); +}); + +test("a context that could hide a placeholder turns retention off", async () => { + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }); + const hostileContext = [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + // An `@id` alias other than ActivityStreams' own `id` would make the + // placeholder indistinguishable from an ordinary property value. + { identifier: "@id" }, + ]; + const compact = await create.toJsonLd({ + format: "compact", + context: hostileContext as unknown as (string | Record)[], + ...options, + }) as Record; + const embedded = compact.object as Record; + + // Rather than risk corrupting the document, Fedify falls back to ordinary + // serialization, which reconstructs the child under the parent's context. + assertEquals(embedded["@context"], undefined); + assertEquals(embedded.proof, undefined); +}); + +test("a clone does not inherit a retained signed representation", async () => { + const note = retainedNote(); + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: note.clone({ content: "Changed" }), + }); + const compact = await create.toJsonLd({ + format: "compact", + ...options, + }) as Record; + const embedded = compact.object as Record; + + assertEquals(embedded["@context"], undefined); + assertEquals(embedded.content, "Changed"); +}); + +test("every generated default context keeps placeholders recoverable", async () => { + interface VocabClass { + new (values: { id?: URL | null }): { toJsonLd(): Promise }; + readonly typeId: URL; + } + const classes = Object.values(vocab).filter((value) => + typeof value === "function" && + (value as { typeId?: unknown }).typeId instanceof URL + ) as unknown as VocabClass[]; + assert(classes.length > 0); + for (const cls of classes) { + const serialized = await new cls({ + id: new URL("https://example.com/objects/1"), + }).toJsonLd() as Record; + assert( + isMarkerSafeContext(serialized["@context"]), + `${cls.typeId.href} has a default context that could hide a placeholder`, + ); + } +}); + +test("a subtype that redefines an inherited property still embeds a retained representation", async () => { + // `OrderedCollection` redefines `Collection.items` as `orderedItems`, so + // the inherited encoder runs first and its output is then dropped and + // re-encoded under the new key. + const collection = new OrderedCollection({ + id: new URL("https://example.com/collections/1"), + items: [retainedNote()], + }); + const compact = await collection.toJsonLd(options) as Record; + + assertEquals(compact.items, undefined); + assertEquals(compact.orderedItems, [securedNote]); +}); + +test("a context that shadows the placeholder scheme turns retention off", async () => { + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }); + const shadowingContext = [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + // A term named `urn` makes a JSON-LD processor read the placeholder as a + // compact IRI and reject it in safe mode. + { urn: "https://example.com/ns#" }, + ]; + const compact = await create.toJsonLd({ + format: "compact", + context: shadowingContext as unknown as (string | Record)[], + ...options, + }) as Record; + const embedded = compact.object as Record; + + assertEquals(embedded["@context"], undefined); + assertEquals(embedded.proof, undefined); +}); + +test("a context that aliases `@id` indirectly turns retention off", async () => { + const create = new Create({ + id: new URL("https://example.com/activities/1"), + actor: new URL("https://example.com/person"), + object: retainedNote(), + }); + const indirectContext = [ + "https://www.w3.org/ns/activitystreams", + "https://w3id.org/security/data-integrity/v1", + // `i` resolves through ActivityStreams' own `id`, so it aliases `@id` + // without naming the keyword. + { i: "id", object: "as:object" }, + ]; + const compact = await create.toJsonLd({ + format: "compact", + context: indirectContext as unknown as (string | Record)[], + ...options, + }) as Record; + const embedded = compact.object as Record; + + assertEquals(embedded["@context"], undefined); + assertEquals(embedded.proof, undefined); +}); From 5144fca0e518002fbe25b9fb5f8fc490d618ad78 Mon Sep 17 00:00:00 2001 From: Hong Minhee Date: Wed, 23 Sep 2026 02:22:13 +0900 Subject: [PATCH 2/2] Use node:assert in the vocab retention tests The new signed-representation tests imported @std/assert, which is a JSR package that @fedify/vocab does not declare. Deno resolves it through the workspace import map, so the Deno suite passed, but the Node.js and Bun suites run a tsdown bundle from dist-tests where the specifier is left external and unresolvable: Cannot find package '@std/assert' imported from packages/vocab/dist-tests/signed-representation.test.mjs Every other test in the package uses node:assert, which all three runtimes resolve. Switch to it. --- .../vocab/src/signed-representation.test.ts | 50 +++++++++---------- 1 file changed, 25 insertions(+), 25 deletions(-) diff --git a/packages/vocab/src/signed-representation.test.ts b/packages/vocab/src/signed-representation.test.ts index b658f06a8..aa8ef5af0 100644 --- a/packages/vocab/src/signed-representation.test.ts +++ b/packages/vocab/src/signed-representation.test.ts @@ -3,7 +3,7 @@ import { isMarkerSafeContext, retainSignedRepresentation, } from "@fedify/vocab-runtime/internal/signed-representation"; -import { assert, assertEquals } from "@std/assert"; +import { deepStrictEqual, ok } from "node:assert/strict"; import * as vocab from "./vocab.ts"; import { Announce, @@ -61,7 +61,7 @@ test("nested serialization embeds a retained signed representation", async () => // `Create` is not compactable, so this goes through the expand-then-compact // path, which would otherwise dissolve the child's own contexts. - assertEquals(compact.object, securedNote); + deepStrictEqual(compact.object, securedNote); }); test("nested serialization embeds a retained representation through a compactable parent", async () => { @@ -70,7 +70,7 @@ test("nested serialization embeds a retained representation through a compactabl attachments: [retainedNote()], }); const compact = await wrapper.toJsonLd(options) as Record; - assertEquals(compact.attachment, securedNote); + deepStrictEqual(compact.attachment, securedNote); // … and still when a non-compactable ancestor compacts the whole tree. const question = new Question({ @@ -79,7 +79,7 @@ test("nested serialization embeds a retained representation through a compactabl }); const compacted = await question.toJsonLd(options) as Record; const embeddedWrapper = compacted.oneOf as Record; - assertEquals(embeddedWrapper.attachment, securedNote); + deepStrictEqual(embeddedWrapper.attachment, securedNote); }); test("nested serialization embeds one retained representation many times", async () => { @@ -96,13 +96,13 @@ test("nested serialization embeds one retained representation many times", async }) as Record; const objects = compact.object as Record[]; - assertEquals(objects.length, 2); - assertEquals(objects[0], securedNote); - assertEquals(objects[1], securedNote); - assertEquals(compact.tag, securedNote); + deepStrictEqual(objects.length, 2); + deepStrictEqual(objects[0], securedNote); + deepStrictEqual(objects[1], securedNote); + deepStrictEqual(compact.tag, securedNote); // Each site gets its own copy rather than an alias of one object. - assert(objects[0] !== objects[1]); - assert(objects[0] !== compact.tag); + ok(objects[0] !== objects[1]); + ok(objects[0] !== compact.tag); }); test("nested serialization embeds a retained representation at any depth", async () => { @@ -121,7 +121,7 @@ test("nested serialization embeds a retained representation at any depth", async }) as Record; const create = compact.object as Record; - assertEquals(create.object, securedNote); + deepStrictEqual(create.object, securedNote); }); test("expanded serialization ignores a retained signed representation", async () => { @@ -140,11 +140,11 @@ test("expanded serialization ignores a retained signed representation", async () // An expanded document has no compact representation to preserve, so the // child is expanded like any other object. - assertEquals( + deepStrictEqual( objects[0]["@id"], "https://example.com/notes/1", ); - assertEquals( + deepStrictEqual( objects[0]["@type"], ["https://www.w3.org/ns/activitystreams#Note"], ); @@ -172,8 +172,8 @@ test("a context that could hide a placeholder turns retention off", async () => // Rather than risk corrupting the document, Fedify falls back to ordinary // serialization, which reconstructs the child under the parent's context. - assertEquals(embedded["@context"], undefined); - assertEquals(embedded.proof, undefined); + deepStrictEqual(embedded["@context"], undefined); + deepStrictEqual(embedded.proof, undefined); }); test("a clone does not inherit a retained signed representation", async () => { @@ -189,8 +189,8 @@ test("a clone does not inherit a retained signed representation", async () => { }) as Record; const embedded = compact.object as Record; - assertEquals(embedded["@context"], undefined); - assertEquals(embedded.content, "Changed"); + deepStrictEqual(embedded["@context"], undefined); + deepStrictEqual(embedded.content, "Changed"); }); test("every generated default context keeps placeholders recoverable", async () => { @@ -202,12 +202,12 @@ test("every generated default context keeps placeholders recoverable", async () typeof value === "function" && (value as { typeId?: unknown }).typeId instanceof URL ) as unknown as VocabClass[]; - assert(classes.length > 0); + ok(classes.length > 0); for (const cls of classes) { const serialized = await new cls({ id: new URL("https://example.com/objects/1"), }).toJsonLd() as Record; - assert( + ok( isMarkerSafeContext(serialized["@context"]), `${cls.typeId.href} has a default context that could hide a placeholder`, ); @@ -224,8 +224,8 @@ test("a subtype that redefines an inherited property still embeds a retained rep }); const compact = await collection.toJsonLd(options) as Record; - assertEquals(compact.items, undefined); - assertEquals(compact.orderedItems, [securedNote]); + deepStrictEqual(compact.items, undefined); + deepStrictEqual(compact.orderedItems, [securedNote]); }); test("a context that shadows the placeholder scheme turns retention off", async () => { @@ -248,8 +248,8 @@ test("a context that shadows the placeholder scheme turns retention off", async }) as Record; const embedded = compact.object as Record; - assertEquals(embedded["@context"], undefined); - assertEquals(embedded.proof, undefined); + deepStrictEqual(embedded["@context"], undefined); + deepStrictEqual(embedded.proof, undefined); }); test("a context that aliases `@id` indirectly turns retention off", async () => { @@ -272,6 +272,6 @@ test("a context that aliases `@id` indirectly turns retention off", async () => }) as Record; const embedded = compact.object as Record; - assertEquals(embedded["@context"], undefined); - assertEquals(embedded.proof, undefined); + deepStrictEqual(embedded["@context"], undefined); + deepStrictEqual(embedded.proof, undefined); });