betterwithage commited on
Commit
32e4f58
·
verified ·
1 Parent(s): 00604b0

fix: make Council payload digest independently verifiable

Browse files

Wraps the signed Council body with its canonical SHA-256 so the public verifier can independently run the payload-digest check.

Files changed (1) hide show
  1. a11oy_ayllu.py +6 -2
a11oy_ayllu.py CHANGED
@@ -800,8 +800,7 @@ def register(app, ns: str = "a11oy") -> str:
800
  signer = _runtime_signer(request)
801
  nemo_route = _nemo_council_route(prompt, sign_fn=signer)
802
  contract = _build_council_contract(prompt, result, nemo_route)
803
- receipt = _make_receipt({
804
- "schema": "szl.ayllu.council-receipt/v2",
805
  "council_id": council_id,
806
  "prompt_sha256": hashlib.sha256(prompt.encode()).hexdigest(),
807
  "participants": result["participants"],
@@ -814,6 +813,11 @@ def register(app, ns: str = "a11oy") -> str:
814
  "nemo_route_receipt_sha256": _receipt_sha(
815
  (contract.get("routing") or {}).get("receipt")),
816
  "human_checkpoint": contract["human_checkpoint"],
 
 
 
 
 
817
  }, sign_fn=signer)
818
  return JSONResponse({"council_id": council_id, "result": result,
819
  "contract": contract, "receipt": receipt})
 
800
  signer = _runtime_signer(request)
801
  nemo_route = _nemo_council_route(prompt, sign_fn=signer)
802
  contract = _build_council_contract(prompt, result, nemo_route)
803
+ receipt_body = {
 
804
  "council_id": council_id,
805
  "prompt_sha256": hashlib.sha256(prompt.encode()).hexdigest(),
806
  "participants": result["participants"],
 
813
  "nemo_route_receipt_sha256": _receipt_sha(
814
  (contract.get("routing") or {}).get("receipt")),
815
  "human_checkpoint": contract["human_checkpoint"],
816
+ }
817
+ receipt = _make_receipt({
818
+ "schema": "szl.ayllu.council-receipt/v2",
819
+ "body": receipt_body,
820
+ "payload_digest": _sha256_json(receipt_body),
821
  }, sign_fn=signer)
822
  return JSONResponse({"council_id": council_id, "result": result,
823
  "contract": contract, "receipt": receipt})