Documentation
¶
Index ¶
- Constants
- Variables
- func ExtractTypes(credential vc.VerifiableCredential) []string
- func ValidNutsAuthorizationCredential() *vc.VerifiableCredential
- func ValidateRevocation(r Revocation) error
- type AllFieldsDefinedValidator
- type BaseCredentialSubject
- type NutsAuthorizationCredentialSubject
- type NutsOrganizationCredentialSubject
- type Resource
- type Revocation
- type Validator
Constants ¶
const ( // NutsOrganizationCredentialType is the VC type for a NutsOrganizationCredential NutsOrganizationCredentialType = "NutsOrganizationCredential" // NutsAuthorizationCredentialType is the VC type for a NutsAuthorizationCredential NutsAuthorizationCredentialType = "NutsAuthorizationCredential" // NutsV1Context is the nuts V1 json-ld context NutsV1Context = "https://nuts.nl/credentials/v1" )
const ( // CredentialSubjectPath represents the JSON path to the holder of the VC CredentialSubjectPath = "credentialSubject.id" // RevocationSubjectPath represents the JSON path to the subject of a revocation, typically the VC id RevocationSubjectPath = "subject" )
Variables ¶
var (
// NutsOrganizationCredentialTypeURI is the VC type for a NutsOrganizationCredentialType as URI
NutsOrganizationCredentialTypeURI, _ = ssi.ParseURI(NutsOrganizationCredentialType)
// NutsAuthorizationCredentialTypeURI is the VC type for a NutsAuthorizationCredentialType as URI
NutsAuthorizationCredentialTypeURI, _ = ssi.ParseURI(NutsAuthorizationCredentialType)
// NutsV1ContextURI is the nuts V1 json-ld context as URI
NutsV1ContextURI = ssi.MustParseURI(NutsV1Context)
)
var ErrValidation = errors.New("validation failed")
ErrValidation is a common error indicating validation failed
var RevocationType = ssi.MustParseURI("CredentialRevocation")
RevocationType contains the JSON-LD type for a revocation
Functions ¶
func ExtractTypes ¶
func ExtractTypes(credential vc.VerifiableCredential) []string
ExtractTypes extract additional VC types from the VC as strings It removes the default `VerifiableCredential` type from the types, returns the rest.
func ValidNutsAuthorizationCredential ¶
func ValidNutsAuthorizationCredential() *vc.VerifiableCredential
func ValidateRevocation ¶
func ValidateRevocation(r Revocation) error
ValidateRevocation checks if a revocation record contains the required fields and if fields have the correct value.
Types ¶
type AllFieldsDefinedValidator ¶
type AllFieldsDefinedValidator struct {
DocumentLoader ld.DocumentLoader
}
AllFieldsDefinedValidator is a Validator that tests whether all fields are defined in the JSON-LD context.
func (AllFieldsDefinedValidator) Validate ¶
func (d AllFieldsDefinedValidator) Validate(input vc.VerifiableCredential) error
Validate implements Validator.Validate.
type BaseCredentialSubject ¶
type BaseCredentialSubject struct {
ID string `json:"id"`
}
BaseCredentialSubject defines the CredentialSubject struct for fields that are shared amongst all CredentialSubjects
type NutsAuthorizationCredentialSubject ¶
type NutsAuthorizationCredentialSubject struct {
// ID contains the DID of the subject
ID string `json:"id"`
// PurposeOfUse refers to the Bolt access policy
PurposeOfUse string `json:"purposeOfUse"`
// Resources contains additional individual resources that can be accessed.
Resources []Resource `json:"resources,omitempty"`
// Subject contains a URN referring to the subject of care (not the credential subject)
Subject *string `json:"subject,omitempty"`
}
NutsAuthorizationCredentialSubject defines the CredentialSubject struct for the NutsAuthorizationCredential
type NutsOrganizationCredentialSubject ¶
type NutsOrganizationCredentialSubject struct {
ID string `json:"id"`
Organization map[string]string `json:"organization"`
}
NutsOrganizationCredentialSubject defines the CredentialSubject struct for the NutsOrganizationCredential
type Resource ¶
type Resource struct {
// Path defines the path of the resource relative to the service base URL.
// Which service acts as base URL is described by the Bolt.
Path string `json:"path"`
// Operations define which operations are allowed on the resource.
Operations []string `json:"operations"`
// UserContext defines if a user login contract is required for the resource.
UserContext bool `json:"userContext"`
// AssuranceLevel defines the assurance level required for the resource (low, substantial, high).
// Should be set if userContext = true, defaults to low
AssuranceLevel *string `json:"assuranceLevel"`
}
Resource defines a single accessbile resource
type Revocation ¶
type Revocation struct {
// Context contains the json-ld contexts
Context []ssi.URI `json:"@context,omitempty"`
// Type contains the json-ld type, usually this is CredentialRevocation
Type []ssi.URI `json:"type,omitempty"`
// Issuer refers to the party that issued the credential
Issuer ssi.URI `json:"issuer"`
// Subject refers to the VC that is revoked
Subject ssi.URI `json:"subject"`
// Reason describes why the VC has been revoked
Reason string `json:"reason,omitempty"`
// Date is a rfc3339 formatted datetime.
Date time.Time `json:"date"`
// Proof contains the cryptographic proof(s). It must be extracted using the Proofs method or UnmarshalProofValue method for non-generic proof fields.
Proof *vc.JSONWebSignature2020Proof `json:"proof,omitempty"`
}
Revocation defines a proof that a VC has been revoked by its issuer.
func BuildRevocation ¶
func BuildRevocation(issuer ssi.URI, subject ssi.URI) Revocation
BuildRevocation generates a revocation based on the credential
type Validator ¶
type Validator interface {
// Validate the given credential according to the rules of the VC type.
Validate(credential vc.VerifiableCredential) error
}
Validator is the interface specific VC verification. Every VC will have its own rules of verification.
func FindValidator ¶
func FindValidator(credential vc.VerifiableCredential) Validator
FindValidator finds the Validator the provided credential based on its Type When no additional type is provided, it returns the default validator