///|
/// A timestamp preserved as the original RFC 3339 text.
///
/// Parsing and validation belong to the ingest stage. Keeping the value intact
/// here makes the domain model lossless and deterministic.
pub(all) struct Timestamp {
  value : String
} derive(Debug, Eq, ToJson)

///|
/// The kind of source file represented by an evidence item.
pub(all) enum EvidenceFormat {
  JsonLines
  PlainText
} derive(Debug, Eq, ToJson)

///|
/// Identifies the system component that produced an evidence item.
pub(all) struct EvidenceSource {
  system : String
  component : String
  host : String?
} derive(Debug, Eq, ToJson)

///|
/// A stable key-value metadata entry attached to a case or evidence item.
pub(all) struct MetadataEntry {
  key : String
  value : String
} derive(Debug, Eq, ToJson)

///|
/// Metadata shared by the case and its individual evidence items.
pub(all) struct EvidenceMetadata {
  entries : Array[MetadataEntry]
} derive(Debug, Eq, ToJson)

///|
/// One user-provided source file and its provenance information.
pub(all) struct EvidenceItem {
  id : String
  source : EvidenceSource
  path : String
  format : EvidenceFormat
  captured_at : Timestamp?
  metadata : EvidenceMetadata
} derive(Debug, Eq, ToJson)

///|
/// The top-level container for one incident investigation.
pub(all) struct Case {
  case_id : String
  title : String
  timezone : String
  collected_at : Timestamp
  evidence : Array[EvidenceItem]
  metadata : EvidenceMetadata
} derive(Debug, Eq, ToJson)