Request body for POST /mobile-sync/devices.
username / password absent (missing field or explicit null) routes through the auto-mint path; a value is strictly validated.
Device registered (one-time password echo)
Canonical success envelope: { "data": T, "ts": <unix millis i64> }.
ts is chrono::Utc::now().timestamp_millis(), set in the webserver handler via [ApiEnvelope::now] (the contract carries only the type + the clock helper, not a hard dependency on when the handler reads the clock). rename_all = "camelCase" is a no-op for the single-word fields here but is declared for forward-compat.
IMPORTANT (utoipa v4): every concrete ApiEnvelope<X> that needs a named OpenAPI component is declared in the #[aliases(...)] block below. Add a new alias line whenever a new payload type needs enveloping. NEVER register the bare ApiEnvelope in components(schemas(...)) — utoipa errors on a bare generic, and an un-aliased generic inlines an anonymous schema.
Result of registering an iPhone Shortcut device. password is the one and only plaintext echo to the frontend — afterwards it exists solely as a PHC hash server-side. The two QR PNGs arrive base64-encoded (encoded daemon-side) ready for <img src="data:image/png;base64,...">.
Server time when the response was built (unix epoch milliseconds).