Event Model
Canonical signed event fields and caller-owned author/key authority.
An Event contains an author string, signer key, space, kind, references, attachments, capability strings, JSON body, creation timestamp, content-derived ID and signature. Canonical serialization orders object keys recursively; the ID covers the full canonical unsigned payload, not just the body. Two equal bodies can have different IDs when any other signed field differs.
EventBuilder::new(author, space, kind) builds the payload. body, created_at, ref_event, attachment and capability set fields. sign(&weave_crypto::KeyPair) signs locally. sign_with(public_key, signer) accepts a synchronous callback returning signature bytes; it is not an async wallet/remote-service API.
use woven::{EventBuilder, SpaceId};
fn make_event(keypair: &weave_crypto::KeyPair) -> woven::Result<woven::Event> {
EventBuilder::new(
"did:example:author",
SpaceId::new("woven://example/events")?,
"example.note",
)
.body(serde_json::json!({ "text": "hello" }))
.created_at(1_777_130_000)
.sign(keypair)
}This source-checked function expects caller-owned signing material. Before treating the author as an authenticated identity, verify that the trusted identity system binds that author string to the key. Capability/attachment strings are signed claims, not automatically validated grants or downloaded resources.
Event::verify(&public_key) checks key equality, recomputes the content ID and verifies the signature. to_strand_bytes/from_strand_bytes use the woven.event version-1 envelope. Unknown versions are rejected; that is strict version handling, not a promise of forward compatibility.