openidfederation

package
v0.7.7 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 1, 2026 License: BSD-2-Clause Imports: 5 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Config

type Config struct {
	// Enabled enables the federation entity configuration endpoint.
	Enabled bool `yaml:"enabled" default:"false"`
	// EntityID is the entity identifier (defaults to PublicURL if empty).
	EntityID string `yaml:"entity_id,omitempty"`
	// AuthorityHints lists superior authority entity identifiers.
	AuthorityHints []string `yaml:"authority_hints,omitempty"`
	// OrganizationName is the human-readable organization name.
	OrganizationName string `yaml:"organization_name,omitempty"`
	// LogoURI is the organization logo URL.
	LogoURI string `yaml:"logo_uri,omitempty"`
	// TrustMarks contains pre-issued trust mark JWTs.
	TrustMarks []TrustMarkConfig `yaml:"trust_marks,omitempty" validate:"omitempty,dive"`
	// TTL is the validity period of the entity configuration in seconds.
	// Default: 86400 (24 hours).
	TTL int64 `yaml:"ttl" default:"86400"`
}

Config holds configuration for OpenID Federation participation.

type EntityConfiguration

type EntityConfiguration struct {
	// Issuer is the entity identifier (iss = sub).
	Issuer string `json:"iss"`
	// Subject is the entity identifier (must equal Issuer for entity configurations).
	Subject string `json:"sub"`
	// IssuedAt is the time the configuration was created.
	IssuedAt *jwt.NumericDate `json:"iat"`
	// ExpiresAt is the expiration time of this configuration.
	ExpiresAt *jwt.NumericDate `json:"exp"`
	// JWKS contains the entity's signing key(s) in JWK Set format.
	JWKS json.RawMessage `json:"jwks"`
	// AuthorityHints lists the entity identifiers of superior authorities.
	AuthorityHints []string `json:"authority_hints,omitempty"`
	// Metadata contains the entity's typed metadata.
	Metadata *EntityMetadata `json:"metadata,omitempty"`
	// TrustMarks contains trust marks issued to this entity.
	TrustMarks []TrustMark `json:"trust_marks,omitempty"`
}

EntityConfiguration represents an OpenID Federation Entity Configuration per OpenID Federation 1.0 §5.1.

type EntityMetadata

type EntityMetadata struct {
	// OpenIDCredentialIssuer contains OID4VCI issuer metadata.
	OpenIDCredentialIssuer map[string]any `json:"openid_credential_issuer,omitempty"`
	// OAuthAuthorizationServer contains OAuth2 AS metadata (RFC 8414).
	OAuthAuthorizationServer map[string]any `json:"oauth_authorization_server,omitempty"`
	// OpenIDRelyingParty contains verifier (RP) metadata.
	OpenIDRelyingParty map[string]any `json:"openid_relying_party,omitempty"`
	// FederationEntity contains federation-level metadata.
	FederationEntity map[string]any `json:"federation_entity,omitempty"`
}

EntityMetadata contains metadata for each entity type per OpenID Federation 1.0 §4.8.

func (*EntityMetadata) Clone

func (m *EntityMetadata) Clone() *EntityMetadata

Clone returns a copy of m, including fresh copies of its map fields, so that mutating the returned value (e.g. injecting federation_entity fields) never affects the caller's original *EntityMetadata or the maps it holds. A nil receiver yields an empty, non-nil *EntityMetadata.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service produces signed OpenID Federation entity configurations.

func New

func New(cfg *Config, signer Signer, publicURL string) *Service

New creates a federation service. publicURL is used as the entity_id when config.EntityID is empty.

func (*Service) BuildEntityConfiguration

func (s *Service) BuildEntityConfiguration(metadata *EntityMetadata) (string, error)

BuildEntityConfiguration produces a signed entity configuration JWT. The metadata parameter allows callers to inject service-specific metadata (e.g., openid_credential_issuer, openid_relying_party).

func (*Service) EntityID

func (s *Service) EntityID() string

EntityID returns the resolved entity identifier for this federation service.

func (*Service) SigningAlgorithm

func (s *Service) SigningAlgorithm() (string, error)

SigningAlgorithm returns the JWT algorithm this service's signer uses, e.g. for advertising request_object_signing_alg in openid_relying_party metadata.

type Signer

type Signer interface {
	GetJWK() (*jose.JSONWebKey, error)
	SignJWT(claims jwt.Claims) (string, error)
}

Signer is the subset of *pki.SignerConfig's capability that Service needs to produce a signed entity configuration. Defined here (consumer side) rather than depending on the concrete pki type, so callers can inject their own already-constructed signer instead of Service building one.

type TrustMark

type TrustMark struct {
	// ID is the trust mark identifier.
	ID string `json:"id"`
	// TrustMark is the trust mark JWT.
	TrustMark string `json:"trust_mark"`
}

TrustMark represents a trust mark issued to an entity.

type TrustMarkConfig

type TrustMarkConfig struct {
	// ID is the trust mark identifier.
	ID string `yaml:"id" validate:"required"`
	// JWT is the trust mark JWT string.
	JWT string `yaml:"jwt" validate:"required"`
}

TrustMarkConfig holds a configured trust mark.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL