Skip to content

recovery

client.recovery runs break-glass recovery. An Owner asks to recover a key domain, or the whole tenant, to a new domain owner. Custodians take part with their backup key shares. The last custodian of the quorum rebuilds the key.

ask

ask starts a ceremony. An Owner calls it after a fresh multi-factor sign-in. The request is recorded in the Seald Healthcare Cloud and in Seald Healthcare’s own records at once, before anything else happens. The asking Owner may be the new domain owner.

ask(request: { domains: Locator[] | 'all'; newOwner: Person; reason: string; reference: string }): Promise<Decided<Ceremony>>;
ParameterTypeDescription
domainsLocator[] or "all"The key domains to recover, or every key domain in the tenant.
newOwnerPersonWho becomes domain owner. May be the Owner who asks.
reasonstringWhy the ceremony is asked for.
referencestringThe ticket or record this ceremony is tied to.

Returns: A Decided<Ceremony>.

Records: Recover. See Audit actions.

Who may call it: The Owner role.

Errors: no-session, unreachable, canceled.

ceremonies

ceremonies returns the ceremonies that every Owner and custodian sees.

ceremonies(): Promise<Ceremony[]>;

Returns: Every Ceremony an Owner or custodian may see.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

cancel

cancel cancels a ceremony before the quorum completes.

cancel(ceremonyId: string): Promise<void>;
ParameterTypeDescription
ceremonyIdstringThe ceremony to cancel.

Returns: Nothing.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

takePart

takePart agrees to a ceremony and presents the custodian’s share. The last custodian’s Client in the quorum holds the share in memory until the token arrives. It then rebuilds the key. This call resolves only once the recovery is committed. If the application closes before that, the custodian must present the share again.

takePart(ceremonyId: string, share: ShareInput): Promise<Participation>;
ParameterTypeDescription
ceremonyIdstringThe ceremony to take part in.
shareShareInputThis custodian’s backup key share, from backupKey.

Returns: A Participation: wrapped for every custodian but the last, rebuilt for the last of the quorum.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

refuse

refuse refuses to take part in a ceremony.

refuse(ceremonyId: string): Promise<void>;
ParameterTypeDescription
ceremonyIdstringThe ceremony to refuse.

Returns: Nothing.

Records: Nothing. Not a decision.

Errors: no-session, unreachable, not-found.

Types

Ceremony

interface Ceremony {
ceremonyId: string;
kind: 'recovery' | 'custodian-replacement';
state: 'open' | 'quorum' | 'completed' | 'canceled' | 'lapsed';
askedBy: RecipientId;
reason: string;
reference: string;
domains: Locator[] | 'all';
newOwner?: Person;
custodians: { person: Person; state: 'waiting' | 'agreed' | 'refused' }[];
quorum: number;
openedAt: Date;
lapsesAt: Date;
}
FieldTypeDescription
ceremonyIdstringIdentifies the ceremony.
kind"recovery" or "custodian-replacement"What the ceremony is for.
stateone of the five statesWhere the ceremony stands.
askedByRecipientIdWho asked for it.
reasonstringWhy it was asked for.
referencestringThe ticket or record it is tied to.
domainsLocator[] or "all"The key domains to recover.
newOwnerPerson, optionalWho becomes domain owner, for a recovery ceremony.
custodianslist of person and stateEach custodian and whether they are waiting, agreed or refused.
quorumnumberHow many custodians must agree.
openedAtdateWhen the ceremony opened.
lapsesAtdateWhen it lapses unfinished.

Participation

type Participation =
| { role: 'wrapped' }
| { role: 'rebuilt'; domains: Locator[] };
CasePayloadDescription
wrappednoneThis custodian’s share went to the others. The SDK then discarded it from this device’s memory.
rebuiltdomainsThis custodian’s Client is the last of the quorum. It held the share in memory, rebuilt the key once the token arrived, gave the new domain owner access, then discarded every piece from memory.