issuer

package
v5.4.39 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 42 Imported by: 0

Documentation

Overview

Package issuer is a generated GoMock package.

Package issuer is a generated GoMock package.

Index

Constants

View Source
const TokenTTL = 15 * time.Minute

TokenTTL is the time-to-live for issuance flows, access tokens and nonces.

Variables

View Source
var ErrUnknownIssuer = errors.New("unknown OpenID4VCI issuer")

ErrUnknownIssuer is returned when the given issuer is unknown.

View Source
var TimeFunc = time.Now

TimeFunc is a function that returns the time used, for e.g. signing time. It can be set for testing purposes.

Functions

This section is empty.

Types

type CredentialSearcher

type CredentialSearcher interface {
	// SearchCredential searches for issued credentials
	// If the passed context is empty, it'll not be part of the search query on the DB.
	SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
}

CredentialSearcher defines the functions to resolve or search for credentials. It is a separate interface from Store so when an object only needs resolving, it only needs the resolver.

type Flow

type Flow struct {
	ID string `json:"id"`
	// IssuerID is the identifier of the credential issuer.
	IssuerID string `json:"issuer_id"`
	// WalletID is the identifier of the wallet.
	WalletID string `json:"wallet_id"`
	// Grants is a list of grants that can be used to acquire an access token.
	Grants []Grant `json:"grants"`
	// Credentials is the list of Verifiable Credentials that be issued to the wallet through this flow.
	// It might be pre-determined (in the issuer-initiated flow) or determined during the flow execution (in the wallet-initiated flow).
	Credentials []vc.VerifiableCredential `json:"credentials"`
	Expiry      time.Time                 `json:"exp"`
}

Flow is an active OpenID4VCI credential issuance flow.

type Grant

type Grant struct {
	// Type is the type of grant, e.g. "urn:ietf:params:oauth:grant-type:pre-authorized_code".
	Type string `json:"type"`
	// Params is a map of parameters for the grant, e.g. "pre-authorized_code" for type "urn:ietf:params:oauth:grant-type:pre-authorized_code".
	Params map[string]interface{} `json:"params"`
}

Grant is a grant that has been issued for an OAuth2 state.

type Issuer

type Issuer interface {
	// Issue issues a credential by signing an unsigned credential.
	// The publish param indicates if the credendential should be published to the network.
	// The public param instructs the Publisher to publish the param with a certain visibility.
	Issue(ctx context.Context, unsignedCredential vc.VerifiableCredential, publish, public bool) (*vc.VerifiableCredential, error)
	// Revoke revokes a credential by the provided type.
	// It requires access to the private key of the issuer which will be used to sign the revocation.
	// It returns an error when the credential is not issued by this node or is already revoked.
	// The revocation will be published to the network by the issuers Publisher.
	Revoke(ctx context.Context, credentialID ssi.URI) (*credential.Revocation, error)
	CredentialSearcher
}

Issuer is a role in the network for a party who issues credentials about a subject to a holder.

func NewIssuer

func NewIssuer(store Store, vcrStore types.Writer, networkPublisher Publisher,
	openidHandlerFn func(ctx context.Context, id did.DID) (OpenIDHandler, error),
	didstore didstore.Store, keyStore crypto.KeyStore, jsonldManager jsonld.JSONLD, trustConfig *trust.Config,
) Issuer

NewIssuer creates a new issuer which implements the Issuer interface. If openidIssuerFn is nil, it won't try to issue over OpenID4VCI. It needs types.Writer since issued credentials need to be in the general VCR store, since that normally happens through receiving the just-issued credential over the network, but that doesn't happen when issuing over OpenID4VCI. Thus, it needs to explicitly save it to the VCR store when issuing over OpenID4VCI. See https://github.com/nuts-foundation/nuts-node/issues/2063

type MockCredentialSearcher

type MockCredentialSearcher struct {
	// contains filtered or unexported fields
}

MockCredentialSearcher is a mock of CredentialSearcher interface.

func NewMockCredentialSearcher

func NewMockCredentialSearcher(ctrl *gomock.Controller) *MockCredentialSearcher

NewMockCredentialSearcher creates a new mock instance.

func (*MockCredentialSearcher) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockCredentialSearcher) SearchCredential

func (m *MockCredentialSearcher) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)

SearchCredential mocks base method.

type MockCredentialSearcherMockRecorder

type MockCredentialSearcherMockRecorder struct {
	// contains filtered or unexported fields
}

MockCredentialSearcherMockRecorder is the mock recorder for MockCredentialSearcher.

func (*MockCredentialSearcherMockRecorder) SearchCredential

func (mr *MockCredentialSearcherMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call

SearchCredential indicates an expected call of SearchCredential.

type MockIssuer

type MockIssuer struct {
	// contains filtered or unexported fields
}

MockIssuer is a mock of Issuer interface.

func NewMockIssuer

func NewMockIssuer(ctrl *gomock.Controller) *MockIssuer

NewMockIssuer creates a new mock instance.

func (*MockIssuer) EXPECT

func (m *MockIssuer) EXPECT() *MockIssuerMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockIssuer) Issue

func (m *MockIssuer) Issue(ctx context.Context, unsignedCredential vc.VerifiableCredential, publish, public bool) (*vc.VerifiableCredential, error)

Issue mocks base method.

func (*MockIssuer) Revoke

func (m *MockIssuer) Revoke(ctx context.Context, credentialID ssi.URI) (*credential.Revocation, error)

Revoke mocks base method.

func (*MockIssuer) SearchCredential

func (m *MockIssuer) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)

SearchCredential mocks base method.

type MockIssuerMockRecorder

type MockIssuerMockRecorder struct {
	// contains filtered or unexported fields
}

MockIssuerMockRecorder is the mock recorder for MockIssuer.

func (*MockIssuerMockRecorder) Issue

func (mr *MockIssuerMockRecorder) Issue(ctx, unsignedCredential, publish, public interface{}) *gomock.Call

Issue indicates an expected call of Issue.

func (*MockIssuerMockRecorder) Revoke

func (mr *MockIssuerMockRecorder) Revoke(ctx, credentialID interface{}) *gomock.Call

Revoke indicates an expected call of Revoke.

func (*MockIssuerMockRecorder) SearchCredential

func (mr *MockIssuerMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call

SearchCredential indicates an expected call of SearchCredential.

type MockOpenIDHandler

type MockOpenIDHandler struct {
	// contains filtered or unexported fields
}

MockOpenIDHandler is a mock of OpenIDHandler interface.

func NewMockOpenIDHandler

func NewMockOpenIDHandler(ctrl *gomock.Controller) *MockOpenIDHandler

NewMockOpenIDHandler creates a new mock instance.

func (*MockOpenIDHandler) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockOpenIDHandler) HandleAccessTokenRequest

func (m *MockOpenIDHandler) HandleAccessTokenRequest(ctx context.Context, preAuthorizedCode string) (string, string, error)

HandleAccessTokenRequest mocks base method.

func (*MockOpenIDHandler) HandleCredentialRequest

func (m *MockOpenIDHandler) HandleCredentialRequest(ctx context.Context, request openid4vci.CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)

HandleCredentialRequest mocks base method.

func (*MockOpenIDHandler) Metadata

Metadata mocks base method.

func (*MockOpenIDHandler) OfferCredential

func (m *MockOpenIDHandler) OfferCredential(ctx context.Context, credential vc.VerifiableCredential, walletIdentifier string) error

OfferCredential mocks base method.

func (*MockOpenIDHandler) ProviderMetadata

func (m *MockOpenIDHandler) ProviderMetadata() openid4vci.ProviderMetadata

ProviderMetadata mocks base method.

type MockOpenIDHandlerMockRecorder

type MockOpenIDHandlerMockRecorder struct {
	// contains filtered or unexported fields
}

MockOpenIDHandlerMockRecorder is the mock recorder for MockOpenIDHandler.

func (*MockOpenIDHandlerMockRecorder) HandleAccessTokenRequest

func (mr *MockOpenIDHandlerMockRecorder) HandleAccessTokenRequest(ctx, preAuthorizedCode interface{}) *gomock.Call

HandleAccessTokenRequest indicates an expected call of HandleAccessTokenRequest.

func (*MockOpenIDHandlerMockRecorder) HandleCredentialRequest

func (mr *MockOpenIDHandlerMockRecorder) HandleCredentialRequest(ctx, request, accessToken interface{}) *gomock.Call

HandleCredentialRequest indicates an expected call of HandleCredentialRequest.

func (*MockOpenIDHandlerMockRecorder) Metadata

func (mr *MockOpenIDHandlerMockRecorder) Metadata() *gomock.Call

Metadata indicates an expected call of Metadata.

func (*MockOpenIDHandlerMockRecorder) OfferCredential

func (mr *MockOpenIDHandlerMockRecorder) OfferCredential(ctx, credential, walletIdentifier interface{}) *gomock.Call

OfferCredential indicates an expected call of OfferCredential.

func (*MockOpenIDHandlerMockRecorder) ProviderMetadata

func (mr *MockOpenIDHandlerMockRecorder) ProviderMetadata() *gomock.Call

ProviderMetadata indicates an expected call of ProviderMetadata.

type MockPublisher

type MockPublisher struct {
	// contains filtered or unexported fields
}

MockPublisher is a mock of Publisher interface.

func NewMockPublisher

func NewMockPublisher(ctrl *gomock.Controller) *MockPublisher

NewMockPublisher creates a new mock instance.

func (*MockPublisher) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockPublisher) PublishCredential

func (m *MockPublisher) PublishCredential(ctx context.Context, verifiableCredential vc.VerifiableCredential, public bool) error

PublishCredential mocks base method.

func (*MockPublisher) PublishRevocation

func (m *MockPublisher) PublishRevocation(ctx context.Context, revocation credential.Revocation) error

PublishRevocation mocks base method.

type MockPublisherMockRecorder

type MockPublisherMockRecorder struct {
	// contains filtered or unexported fields
}

MockPublisherMockRecorder is the mock recorder for MockPublisher.

func (*MockPublisherMockRecorder) PublishCredential

func (mr *MockPublisherMockRecorder) PublishCredential(ctx, verifiableCredential, public interface{}) *gomock.Call

PublishCredential indicates an expected call of PublishCredential.

func (*MockPublisherMockRecorder) PublishRevocation

func (mr *MockPublisherMockRecorder) PublishRevocation(ctx, revocation interface{}) *gomock.Call

PublishRevocation indicates an expected call of PublishRevocation.

type MockStore

type MockStore struct {
	// contains filtered or unexported fields
}

MockStore is a mock of Store interface.

func NewMockStore

func NewMockStore(ctrl *gomock.Controller) *MockStore

NewMockStore creates a new mock instance.

func (*MockStore) Close

func (m *MockStore) Close() error

Close mocks base method.

func (*MockStore) Diagnostics

func (m *MockStore) Diagnostics() []core.DiagnosticResult

Diagnostics mocks base method.

func (*MockStore) EXPECT

func (m *MockStore) EXPECT() *MockStoreMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockStore) GetCredential

func (m *MockStore) GetCredential(id ssi.URI) (*vc.VerifiableCredential, error)

GetCredential mocks base method.

func (*MockStore) GetRevocation

func (m *MockStore) GetRevocation(id ssi.URI) (*credential.Revocation, error)

GetRevocation mocks base method.

func (*MockStore) SearchCredential

func (m *MockStore) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)

SearchCredential mocks base method.

func (*MockStore) StoreCredential

func (m *MockStore) StoreCredential(vc vc.VerifiableCredential) error

StoreCredential mocks base method.

func (*MockStore) StoreRevocation

func (m *MockStore) StoreRevocation(r credential.Revocation) error

StoreRevocation mocks base method.

type MockStoreMockRecorder

type MockStoreMockRecorder struct {
	// contains filtered or unexported fields
}

MockStoreMockRecorder is the mock recorder for MockStore.

func (*MockStoreMockRecorder) Close

func (mr *MockStoreMockRecorder) Close() *gomock.Call

Close indicates an expected call of Close.

func (*MockStoreMockRecorder) Diagnostics

func (mr *MockStoreMockRecorder) Diagnostics() *gomock.Call

Diagnostics indicates an expected call of Diagnostics.

func (*MockStoreMockRecorder) GetCredential

func (mr *MockStoreMockRecorder) GetCredential(id interface{}) *gomock.Call

GetCredential indicates an expected call of GetCredential.

func (*MockStoreMockRecorder) GetRevocation

func (mr *MockStoreMockRecorder) GetRevocation(id interface{}) *gomock.Call

GetRevocation indicates an expected call of GetRevocation.

func (*MockStoreMockRecorder) SearchCredential

func (mr *MockStoreMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call

SearchCredential indicates an expected call of SearchCredential.

func (*MockStoreMockRecorder) StoreCredential

func (mr *MockStoreMockRecorder) StoreCredential(vc interface{}) *gomock.Call

StoreCredential indicates an expected call of StoreCredential.

func (*MockStoreMockRecorder) StoreRevocation

func (mr *MockStoreMockRecorder) StoreRevocation(r interface{}) *gomock.Call

StoreRevocation indicates an expected call of StoreRevocation.

type MockkeyResolver

type MockkeyResolver struct {
	// contains filtered or unexported fields
}

MockkeyResolver is a mock of keyResolver interface.

func NewMockkeyResolver

func NewMockkeyResolver(ctrl *gomock.Controller) *MockkeyResolver

NewMockkeyResolver creates a new mock instance.

func (*MockkeyResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockkeyResolver) ResolveAssertionKey

func (m *MockkeyResolver) ResolveAssertionKey(ctx context.Context, issuerDID did.DID) (crypto.Key, error)

ResolveAssertionKey mocks base method.

type MockkeyResolverMockRecorder

type MockkeyResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockkeyResolverMockRecorder is the mock recorder for MockkeyResolver.

func (*MockkeyResolverMockRecorder) ResolveAssertionKey

func (mr *MockkeyResolverMockRecorder) ResolveAssertionKey(ctx, issuerDID interface{}) *gomock.Call

ResolveAssertionKey indicates an expected call of ResolveAssertionKey.

type Nonce

type Nonce struct {
	Nonce  string    `json:"nonce"`
	Expiry time.Time `json:"exp"`
}

Nonce is a nonce that has been issued for an OpenID4VCI flow, to be used by the wallet when requesting credentials. A nonce can only be used once (doh), and is only valid for a certain period of time.

type OpenIDHandler

type OpenIDHandler interface {
	// ProviderMetadata returns the OpenID Connect provider metadata.
	ProviderMetadata() openid4vci.ProviderMetadata
	// HandleAccessTokenRequest handles an OAuth2 access token request for the given issuer and pre-authorized code.
	// It returns the access token and a c_nonce.
	HandleAccessTokenRequest(ctx context.Context, preAuthorizedCode string) (string, string, error)
	// Metadata returns the OpenID4VCI credential issuer metadata for the given issuer.
	Metadata() openid4vci.CredentialIssuerMetadata
	// OfferCredential sends a credential offer to the specified wallet. It derives the issuer from the credential.
	OfferCredential(ctx context.Context, credential vc.VerifiableCredential, walletIdentifier string) error
	// HandleCredentialRequest requests a credential from the given issuer.
	HandleCredentialRequest(ctx context.Context, request openid4vci.CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
}

OpenIDHandler defines the interface for handling OpenID4VCI issuer operations.

func NewOpenIDHandler

func NewOpenIDHandler(issuerDID did.DID, issuerIdentifierURL string, definitionsDIR string, httpClient core.HTTPRequestDoer, keyResolver types.KeyResolver, store OpenIDStore) (OpenIDHandler, error)

NewOpenIDHandler creates a new OpenIDHandler instance. The identifier is the Credential Issuer Identifier, e.g. https://example.com/issuer/

type OpenIDStore

type OpenIDStore interface {
	// Store saves a new Flow in the store.
	Store(ctx context.Context, flow Flow) error
	// StoreReference saves a reference to the given Flow, for looking it up later.
	// This is used for finding a flow given a secret, e.g. pre-authorized code, authorization code or nonce.
	// like a database index. The reference must be unique for all flows.
	// The expiry is the time-to-live for the reference. After this time, the reference is automatically deleted.
	// If the flow does not exist, or the reference does already exist, it returns an error.
	StoreReference(ctx context.Context, flowID string, refType string, reference string, expiry time.Time) error
	// FindByReference finds a Flow by its reference.
	// If the flow does not exist, it returns nil.
	FindByReference(ctx context.Context, refType string, reference string) (*Flow, error)
	// DeleteReference deletes the reference from the store.
	// It does not return an error if it doesn't exist anymore.
	DeleteReference(ctx context.Context, refType string, reference string) error
	// Close signals the store to close any owned resources.
	Close()
}

OpenIDStore defines the storage API for OpenID Credential Issuance flows.

func NewOpenIDMemoryStore

func NewOpenIDMemoryStore() OpenIDStore

NewOpenIDMemoryStore creates a new in-memory OpenIDStore.

type Publisher

type Publisher interface {
	// PublishCredential publishes the credential to the outside world.
	// A public flag is used to indicate if everybody can see the credential, or just the involved parties.
	PublishCredential(ctx context.Context, verifiableCredential vc.VerifiableCredential, public bool) error
	// PublishRevocation publishes the revocation to the outside world.
	// It indicates to the network a credential can no longer be used.
	PublishRevocation(ctx context.Context, revocation credential.Revocation) error
}

Publisher publishes new credentials and revocations to a channel. Used by a credential issuer.

func NewNetworkPublisher

func NewNetworkPublisher(networkTx network.Transactions, store didstore.Store, keyResolver crypto.KeyResolver) Publisher

NewNetworkPublisher creates a new networkPublisher which implements the Publisher interface. It is the default implementation to use for issuers to publish credentials and revocations to the Nuts network.

type Store

type Store interface {
	core.Diagnosable
	// GetCredential retrieves an issued credential by ID
	// Returns an ErrNotFound when the credential is not in the store
	// Returns an ErrMultipleFound when there are multiple credentials with this ID in the store
	GetCredential(id ssi.URI) (*vc.VerifiableCredential, error)
	// StoreCredential writes a VC to storage.
	StoreCredential(vc vc.VerifiableCredential) error
	// GetRevocation returns a revocation for a credential ID
	// Returns an ErrNotFound when the revocation is not in the store
	// Returns an ErrMultipleFound when there are multiple revocations for this credential ID in the store
	GetRevocation(id ssi.URI) (*credential.Revocation, error)
	// StoreRevocation writes a revocation to storage.
	StoreRevocation(r credential.Revocation) error
	CredentialSearcher
	// Closer closes and frees the underlying resources the store uses.
	io.Closer
}

Store defines the interface for an issuer store. An implementation stores all the issued credentials and the revocations.

func NewLeiaIssuerStore

func NewLeiaIssuerStore(dbPath string, backupStore stoabs.KVStore) (Store, error)

NewLeiaIssuerStore creates a new instance of leiaIssuerStore which implements the Store interface.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL