Signature
Signature is one verb's shape, as a caller would write it.
Command
gnokey query vm/qeval -remote "https://rpc.gno.land" -data "gno.land/r/moul/x/upgrade/schema/facade/v0.Signature()"
Result
untrusted-render: every string Render echoes is either a verb name validated by parseSchema against [a-z0-9_] at accept time, or a package path read off a crossing frame. No caller-typed payload is ever rendered.
Package facade is the permanent entry point of the "API as data" upgrade pattern (pattern G of the exploration; see ../../README.md).
Patterns E and F put a Go interface at the permanent path, which fixes the method set at deploy: adding an operation later needs a whole extra realm. This one puts a single entry point there instead,
1Call(cur realm, verb, payload string) string
and moves the API into DATA that each implementation declares. The signature that can never change is that one line; everything the application does can still grow.
Three things fall out of the API being data, and they are the reason to pay the price below:
The price is the type system. Arguments are strings a caller encodes, and a misspelled verb is an abort at runtime rather than a compile error. Pattern F is the other side of that trade and both ship here on purpose.
State is deliberately out of scope. These handlers are pure; where an application's data should live is pattern C's question, and the answer does not change because the entry point became a string.
Signature is one verb's shape, as a caller would write it.
gnokey query vm/qeval -remote "https://rpc.gno.land" -data "gno.land/r/moul/x/upgrade/schema/facade/v0.Signature()"