{
 "$schema": "https://json-schema.org/draft/2020-12/schema",
 "$id": "https://real-life.org/rltp/v1/schemas/rltp-delivery-document.schema.json",
 "title": "RLTP Delivery Document Profile (rltp-delivery@0.79)",
 "description": "RLTP document profile (Delivery 3): proof REQUIRED on delivery-ack and registry-declaration (their authenticity has no other carrier; a delivery-ack carries the DataIntegrityProof form for signature-class payloads and the deniable {mac} form (HMAC over JCS of the document without proof, under the channel ack key) for designated-verifier payloads per the 4.2/4.4 acknowledgement class rule; the schema conditions proof presence by type — which of the two ack proof forms applies is class state the receiver checks at validation (stage 8), not schema-expressible), MUST be absent on the other own types; own types' payload schemas carry \\$id = Type URI, companion-registered types dispatch through the 4.4 registry entry.",
 "type": "object",
 "required": [
  "id",
  "type",
  "issuer",
  "recipient",
  "threadId",
  "issuedAt",
  "payload"
 ],
 "additionalProperties": false,
 "properties": {
  "id": {
   "$ref": "#/$defs/uuid"
  },
  "type": {
   "type": "string",
   "pattern": "^https://real-life\\.org/trust-tasks/[a-z0-9-]+/[0-9]+\\.[0-9]+$"
  },
  "issuer": {
   "$ref": "#/$defs/didKey"
  },
  "recipient": {
   "$ref": "#/$defs/didKey"
  },
  "threadId": {
   "$ref": "#/$defs/uuid"
  },
  "ceremony": {
   "type": "object",
   "description": "OPTIONAL and structurally unconstrained per Trust Tasks 4.11.1: this schema imposes NOTHING on its members — every framework field (enactment, step, round, terminal, prev, ...) passes through unrejected, in any shape. The single RLTP profile rule lives in prose (Contract section 3): a present enactment value MUST recompute against enclosed material; it grants no authority."
  },
  "issuedAt": {
   "$ref": "#/$defs/rfc3339utc"
  },
  "payload": {
   "type": "object"
  },
  "proof": {
   "oneOf": [
    {
     "type": "object",
     "required": [
      "type",
      "cryptosuite",
      "created",
      "verificationMethod",
      "proofPurpose",
      "proofValue"
     ],
     "properties": {
      "type": {
       "const": "DataIntegrityProof"
      },
      "cryptosuite": {
       "const": "eddsa-jcs-2022"
      },
      "created": {
       "$ref": "#/$defs/rfc3339utc"
      },
      "verificationMethod": {
       "type": "string",
       "pattern": "^did:key:z6Mk[1-9A-HJ-NP-Za-km-z]{44}#z6Mk[1-9A-HJ-NP-Za-km-z]{44}$"
      },
      "proofPurpose": {
       "const": "assertionMethod"
      },
      "proofValue": {
       "type": "string",
       "pattern": "^z[1-9A-HJ-NP-Za-km-z]+$"
      }
     },
     "additionalProperties": false
    },
    {
     "type": "object",
     "additionalProperties": false,
     "required": [
      "mac"
     ],
     "properties": {
      "mac": {
       "type": "string",
       "pattern": "^u[A-Za-z0-9_-]{42}[AEIMQUYcgkosw048]$"
      }
     },
     "description": "deniable acknowledgement proof (4.4 acknowledgement class rule): HMAC-SHA-256 over JCS of the document without proof under the arrival tuple's ack key — for acks of designated-verifier payloads only"
    }
   ]
  }
 },
 "$defs": {
  "uuid": {
   "type": "string",
   "pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$"
  },
  "didKey": {
   "type": "string",
   "pattern": "^did:key:z6Mk[1-9A-HJ-NP-Za-km-z]{44}$"
  },
  "rfc3339utc": {
   "type": "string",
   "pattern": "^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9](\\.[0-9]{1,3})?Z$"
  }
 },
 "allOf": [
  {
   "if": {
    "properties": {
     "type": {
      "const": "https://real-life.org/trust-tasks/delivery-ack/0.1"
     }
    },
    "required": [
     "type"
    ]
   },
   "then": {
    "required": [
     "proof"
    ]
   }
  },
  {
   "if": {
    "properties": {
     "type": {
      "const": "https://real-life.org/trust-tasks/registry-declaration/0.1"
     }
    },
    "required": [
     "type"
    ]
   },
   "then": {
    "required": [
     "proof"
    ],
    "properties": {
     "proof": {
      "type": "object",
      "required": [
       "type",
       "cryptosuite",
       "created",
       "verificationMethod",
       "proofPurpose",
       "proofValue"
      ],
      "properties": {
       "type": {
        "const": "DataIntegrityProof"
       },
       "cryptosuite": {
        "const": "eddsa-jcs-2022"
       },
       "created": {
        "$ref": "#/$defs/rfc3339utc"
       },
       "verificationMethod": {
        "type": "string",
        "pattern": "^did:key:z6Mk[1-9A-HJ-NP-Za-km-z]{44}#z6Mk[1-9A-HJ-NP-Za-km-z]{44}$"
       },
       "proofPurpose": {
        "const": "assertionMethod"
       },
       "proofValue": {
        "type": "string",
        "pattern": "^z[1-9A-HJ-NP-Za-km-z]+$"
       }
      },
      "additionalProperties": false
     }
    }
   }
  },
  {
   "if": {
    "properties": {
     "type": {
      "const": "https://real-life.org/trust-tasks/encounter-bundle/0.1"
     }
    },
    "required": [
     "type"
    ]
   },
   "then": {
    "properties": {
     "proof": false
    }
   }
  },
  {
   "if": {
    "properties": {
     "type": {
      "const": "https://real-life.org/trust-tasks/encounter-credential-delivery/0.1"
     }
    },
    "required": [
     "type"
    ]
   },
   "then": {
    "properties": {
     "proof": false
    }
   }
  }
 ]
}
