CAP never authorizes.
Deterministic attached-JWS framing plus the honest-signer refusal boundary.
Callers provide exactly %{"kid" => kid, "claims" => claims} with an
optional "algorithm" member selecting the emission pair — "Ed25519"
(protocol_revision 2, the default) or "ML-DSA-65" (protocol_revision 3).
This module
constructs the closed protected header, canonicalizes and validates the
payload through the existing artifact codec, and returns only the exact RFC
7515 signing bytes. The set-aware Acceptance producer refuses false
coordinates, equivocation, and ancestry that excludes any maximum accepted
head. The set-aware Termination producer refuses every revision except the
unique governing revision at the notice's own effective time.
This module never accepts a key, signer, callback, or custody handle and never signs. These refusal checks protect honest signers relative to their supplied view; they cannot constrain a dishonest signer or prove completeness.
Summary
Functions
Build an Acceptance signing input after R1/R2/R3 set refusal checks.
Assemble a validated signing input and its exact raw signature.
Build a canonical Party Descriptor signing input without signing.
Build a canonical Receipt signing input without signing.
Build a Termination signing input after R1/R2/R3 set refusal checks.
Types
Functions
@spec acceptance(term(), CharterAgreementProtocol.ArtifactSet.t()) :: {:ok, t()} | {:error, CharterAgreementProtocol.Error.t()}
Build an Acceptance signing input after R1/R2/R3 set refusal checks.
@spec assemble(term(), term()) :: {:ok, binary()} | {:error, CharterAgreementProtocol.Error.t()}
Assemble a validated signing input and its exact raw signature.
The signature byte length must equal the registry row's value for the input's emission alg (64 for the classical names, 3309 for ML-DSA-65).
@spec descriptor(term()) :: {:ok, t()} | {:error, CharterAgreementProtocol.Error.t()}
Build a canonical Party Descriptor signing input without signing.
@spec receipt(term()) :: {:ok, t()} | {:error, CharterAgreementProtocol.Error.t()}
Build a canonical Receipt signing input without signing.
@spec termination(term(), CharterAgreementProtocol.ArtifactSet.t()) :: {:ok, t()} | {:error, CharterAgreementProtocol.Error.t()}
Build a Termination signing input after R1/R2/R3 set refusal checks.