VÒNG ĐỜI TÀI NGUYÊN API
Chuyển trạng thái, hủy và retry
Client tích hợp theo state machine rõ ràng, không phải suy đoán yêu cầu timeout đã được xử lý hay chưa.
01
State machine của yêu cầu ký
created
→ awaiting_approval
→ approved
→ activated
→ signing
→ completed
Terminal/exception states:
rejected · expired · cancelled · provider_unavailable · failed02
Quy tắc chuyển trạng thái
| From | Action | To | Idempotency |
|---|---|---|---|
| created | Request approval options | awaiting_approval | Safe repeat |
| awaiting_approval | Verify WebAuthn approval | approved | Idempotent by assertion/challenge |
| approved | Activate signing authorization | activated | Idempotency key required |
| activated | Execute signature | signing/completed | Idempotency key required |
| created/awaiting_approval | Cancel | cancelled | Safe repeat |
| any non-terminal | Expire by policy | expired | Server controlled |
03
Thao tác bất đồng bộ
- 202 Accepted returns resource URI and retry-after guidance.
- GET resource supports polling with bounded backoff.
- Webhook events are at-least-once and must be deduplicated.
- Cancellation is best-effort after protected execution begins.
- Partial verification is represented explicitly, never converted to success.
