[redact] policy. describeWorld reports that per field, and storedForms
turns a plaintext you know into the value the store actually holds.
Describe
describeWorld(slug, options?) reads the world’s head version through GET /api/public/worlds/{slug}
and returns a WorldDescription. Pass the slug alone.
The fields that matter for querying:
The same document is what
gateway worlds describe <slug> prints, and what it prints for a local
world directory through the runtime. See the CLI page.
Look up a hashed field by its plaintext
storedForms(world, field, plaintext) returns every value the store may hold for that field given
that plaintext:
The rule is the one the runtime hashed with, byte for byte, so a stored form you compute here
matches a row the world captured from the vendor. No lowercasing, no trimming: the plaintext is
hashed exactly as given.
The salt is the connector’s slug, from
connector.toml, not the world’s platform slug. They
can differ: the spycloud-world world hashes under spycloud. storedForms reads the salt from
world.redact.slug, which describeWorld supplies, so pass the description through unchanged.
Building the policy by hand and salting with the platform slug produces digests that never
match a row.redactionOf(world.redact, field) returns which policy a field falls under, ranked the way the
runtime applies them.
Keep real data out covers the author’s side: how hash, drop, preserve
and round are declared in connector.toml, which fields each one matches, and how to redact
rows on the way in.
Which fields answer a plaintext query
A field markedhash or preserve answers a plaintext lookup, through storedForms. A field in
the clear answers the plaintext as given. A field marked drop answers nothing, by policy: it was
never written. Plan your queries from describeWorld first, and never import plaintext into a
field the policy hashes.
You rarely call storedForms yourself. queryRows(slug, entity, { where, resolve: true }) does
the resolution for every value in where and runs the query, and its resolved field reports
the form each value became, so a miss on a dropped field is explainable:
Where to go next
- Worlds to open a world and dispatch a run.
- World sessions to drive one task against a live copy.
- Put data in a world for the rows contract and the import path.
- Keep real data out for declaring the policy these functions read.