Admit a JSON document that arrived as bytes, and return the value it denotes. The refusals are the point. A repeated member name gives one document two readings: two parties take the same bytes for two different documents and a signature over either reading verifies, and by the time a `serde_json::Value` exists the repeat is gone. Nesting past [`MAX_DEPTH`] containers is refused here rather than
(bytes: &[u8])
| 100 | /// admitted bytes then fail to deserialize, which is a disagreement between the |
| 101 | /// admission layer and `serde_json` rather than a statement about the input. |
| 102 | pub fn admit_document(bytes: &[u8]) -> Result<Value> { |
| 103 | jcs_admit::admit_with(bytes, &ADMISSION)?; |
| 104 | |
| 105 | // Sound only because the admission above has already walked these bytes and |
| 106 | // refused anything nested past MAX_DEPTH. serde_json's own recursion limit |
| 107 | // is switched off so the declared cap is the only cap: left on, it refuses |
| 108 | // at 128 while the admission admits 128, and a document this crate encodes |
| 109 | // is one it will not read back. This parse MUST stay ordered after |
| 110 | // `admit_with`. Parsed first, an input nested far enough would overflow |
| 111 | // the stack instead of returning an error. |
| 112 | let not_deserializable = |e: serde_json::Error| { |
| 113 | CanonicalError::Proof(format!("admitted document does not deserialize: {e}")) |
| 114 | }; |
| 115 | let mut de = serde_json::Deserializer::from_slice(bytes); |
| 116 | de.disable_recursion_limit(); |
| 117 | let value = Value::deserialize(&mut de).map_err(not_deserializable)?; |
| 118 | de.end().map_err(not_deserializable)?; |
| 119 | Ok(value) |
| 120 | } |
| 121 | |
| 122 | /// Canonicalize a JSON value into its RFC-8785 string form. |
| 123 | pub fn canonicalize(value: &Value) -> String { |