Schemas for the whole v1 surface: 38 methods, 9 events, 25 named types and the
JSON-RPC envelope, with x-privileged / x-transports / x-deadlineMs / x-errors
annotations that both generators emit as data rather than prose.
Four generators over one IR (contracts/codegen/schema_ir.py), so the C++ structs,
the TypeScript types and the OpenRPC document cannot disagree about what the
contract says:
gen_cpp.py -> core/generated/velox_proto.{hpp,cpp}
gen_ts.py -> extension/src/shared/protocol/
gen_openrpc.py -> contracts/openrpc.json
gen_cpp_conformance.py -> tests/conformance/cpp/fixture_dispatcher.hpp
Inbound parsing never throws: parse<T>() returns std::expected<T, ParseError> and
nlohmann's throwing ADL from_json is deliberately not emitted. Schema constraints
(minimum, maxLength, pattern, ...) become real runtime checks in both languages —
the daemon does not trust the extension and the extension does not trust the
daemon.
59 golden fixtures: a success case per method, 12 error cases, 9 events. Replayed
by tests/conformance/ against both the generated C++ and a live server over both
transports. tools/mockd serves the same fixtures with unhappy-path flags so the
GUI and EXT lanes never wait for veloxd.
run.sh also proves capture.offer fails open: with a daemon answering slower than
750 ms the client gives up and lets Firefox take the download.
core/generated/ is libveloxproto, a separate target from libveloxcore, which
still never sees JSON — see docs/adr/0009.
Co-Authored-By: Claude Opus 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_012fgjnqFCS5h5L7gZTZo3rV
53 lines
2.8 KiB
JSON
53 lines
2.8 KiB
JSON
{
|
|
"$schema": "https://json-schema.org/draft/2020-12/schema",
|
|
"$id": "https://velox.dev/schema/methods/capture.offer.schema.json",
|
|
"title": "capture.offer",
|
|
"description": "Firefox offers an intercepted response to the daemon. The daemon MUST reply within 750 ms; the extension abandons the offer and lets Firefox download normally on timeout. This deadline is the whole reason capture fails open, and it is conformance-tested: a daemon that is slow, down, or erroring must never cost the user a download.",
|
|
"x-privileged": false,
|
|
"x-transports": ["uds", "ws"],
|
|
"x-deadlineMs": 750,
|
|
"x-errors": [-32011],
|
|
"type": "object",
|
|
"properties": {
|
|
"params": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["url", "method", "tabUrl"],
|
|
"properties": {
|
|
"url": { "type": "string", "format": "uri" },
|
|
"method": { "type": "string", "enum": ["GET", "POST"] },
|
|
"tabUrl": { "type": "string", "format": "uri" },
|
|
"headers": { "oneOf": [{ "$ref": "https://velox.dev/schema/types/Headers.schema.json" }, { "type": "null" }] },
|
|
"cookies": {
|
|
"type": ["array", "null"],
|
|
"description": "Cookies for the URL, so authenticated downloads work outside the browser.",
|
|
"items": { "$ref": "https://velox.dev/schema/types/Cookie.schema.json" }
|
|
},
|
|
"contentType": { "type": ["string", "null"] },
|
|
"contentLength": { "type": ["integer", "null"], "minimum": 0 },
|
|
"contentDisposition": { "type": ["string", "null"] },
|
|
"filename": { "type": ["string", "null"], "description": "The extension's best guess; the daemon may override it." },
|
|
"userAgent": { "type": ["string", "null"] },
|
|
"referrer": { "type": ["string", "null"] },
|
|
"origin": { "type": ["string", "null"], "description": "moz-extension://... The daemon verifies this on the WS transport and refuses anything else." },
|
|
"requestId": { "type": ["string", "null"], "description": "The extension's webRequest id, echoed in logs so a capture decision can be traced back to one browser request." }
|
|
}
|
|
},
|
|
"result": {
|
|
"type": "object",
|
|
"additionalProperties": false,
|
|
"required": ["action"],
|
|
"properties": {
|
|
"action": { "type": "string", "enum": ["take", "ignore"] },
|
|
"taskId": { "type": ["string", "null"], "format": "uuid", "description": "Set when action is 'take'." },
|
|
"reason": {
|
|
"type": ["string", "null"],
|
|
"description": "Why the offer was declined. Set when action is 'ignore'; the extension logs it in the popup's diagnostics.",
|
|
"enum": ["excluded_host", "type_not_monitored", "below_min_size", "duplicate",
|
|
"capture_disabled", "user_declined", "rule_ignore", null]
|
|
}
|
|
}
|
|
}
|
|
}
|
|
}
|