RequestContext class
The unit of work that flows through the security pipeline.
A RequestContext represents a single incoming request (e.g. an API call, a wallet transaction, a login attempt) as it travels through each SecurityLayer. It is intentionally mutable in one place only — metadata — so layers can pass derived data (like computed risk features) to later layers without redesigning the model.
Constructors
-
RequestContext({Map<
String, String> ? headers, dynamic body, String? userId, required String ipAddress, required String deviceId, DateTime? timestamp, Map<String, dynamic> ? metadata}) -
Creates a request context.
ipAddressanddeviceIdare required; everything else is optional and defaults sensibly (e.g.timestampdefaults to the current UTC time).
Properties
- body → dynamic
-
The request payload. Typically a decoded JSON map, but left as
dynamicso the engine can be used for any transport shape.final - deviceId → String
-
A stable identifier for the originating device, used for
device-change and fraud heuristics.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
-
headers
→ Map<
String, String> -
Raw request headers (e.g.
Authorization,X-Signature).final - ipAddress → String
-
The originating IP address of the request.
final
-
metadata
→ Map<
String, dynamic> -
Free-form bag for cross-layer state. Layers may read and write to
this map to share derived information (e.g. computed risk scores,
sanitized payloads) with layers that run later in the pipeline.
final
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- signature → String?
-
Convenience getter for the signature/auth header, checked in a
case-insensitive way since header casing varies by client/proxy.
no setter
- signedTimestamp → DateTime?
-
The timestamp the client claims to have signed the request at,
carried in the
X-Timestampheader. This is distinct from timestamp (the server's receipt time, used for rate limiting and logging): signature verification must use the timestamp the client actually signed, not the time the server happened to receive the request, or every signature would fail to verify.no setter - timestamp → DateTime
-
When the request was received.
final
- userId → String?
-
The authenticated (or claimed) user performing the request.
May be null for anonymous/unauthenticated requests.
final
Methods
-
getMeta<
T> (String key) → T? - Reads a value from metadata, returning null if absent.
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
setMeta(
String key, dynamic value) → void -
Writes a value into metadata. Used by layers to hand derived data
(e.g.
riskFeatures,sanitizedBody) to downstream layers. -
toString(
) → String -
A string representation of this object.
override
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited