Product versions on record
R8.5Is the version of the product the buyer was shown registered in a public append-only log, and does the agreement's record bind it by hash?
- Why it matters
- It settles whether this was what the buyer was shown, with evidence.
- What Lens looks for
- We check whether the product version a buyer was shown is in a public log and named in the agreement.
- Where it sits
- Product · Check 4 of 4
- Needed for
- No stage needs it. It counts toward its group.
- Builds on
- Signed product records R8.4
- Needed by
- Nothing
- Usually fixed by
- Developer · Weeks
What to do
Register each product version, and reference it from the ATR.
Product
Exactly what is sold?
The definition
- Definition
- Any public append-only log whose history a stranger can check qualifies: a transparency service whose receipt (RFC 9942, an RFC 9162 inclusion proof) verifies with a key it publishes at /.well-known/scitt-keys. A product exhibit is a JSON object in the agreement record with the role product, the product identifier (id), the version (the SHA-256 of the signed record as logged) and the URL at which the log serves the entry (entry).
- Passes when
- The agreement record from a consented nominal transaction carries at least one product exhibit, and for every one, the entry served at its URL is that version of that product, is a product record, and carries a receipt that verifies with a key its log publishes.
- Decided by
- A rule
- Evidence
- The ATR; the entry served at each exhibit's URL; the log's key set
- Steps
- settle
- Made as
- anon, lens