Documentation
¶
Overview ¶
Package issuer is a generated GoMock package.
Package issuer is a generated GoMock package.
Index ¶
- Constants
- Variables
- type CredentialSearcher
- type Flow
- type Grant
- type Issuer
- type MockCredentialSearcher
- type MockCredentialSearcherMockRecorder
- type MockIssuer
- func (m *MockIssuer) EXPECT() *MockIssuerMockRecorder
- func (m *MockIssuer) Issue(ctx context.Context, unsignedCredential vc.VerifiableCredential, ...) (*vc.VerifiableCredential, error)
- func (m *MockIssuer) Revoke(ctx context.Context, credentialID ssi.URI) (*credential.Revocation, error)
- func (m *MockIssuer) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
- type MockIssuerMockRecorder
- func (mr *MockIssuerMockRecorder) Issue(ctx, unsignedCredential, publish, public interface{}) *gomock.Call
- func (mr *MockIssuerMockRecorder) Revoke(ctx, credentialID interface{}) *gomock.Call
- func (mr *MockIssuerMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call
- type MockOpenIDHandler
- func (m *MockOpenIDHandler) EXPECT() *MockOpenIDHandlerMockRecorder
- func (m *MockOpenIDHandler) HandleAccessTokenRequest(ctx context.Context, preAuthorizedCode string) (string, string, error)
- func (m *MockOpenIDHandler) HandleCredentialRequest(ctx context.Context, request openid4vci.CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
- func (m *MockOpenIDHandler) Metadata() openid4vci.CredentialIssuerMetadata
- func (m *MockOpenIDHandler) OfferCredential(ctx context.Context, credential vc.VerifiableCredential, ...) error
- func (m *MockOpenIDHandler) ProviderMetadata() openid4vci.ProviderMetadata
- type MockOpenIDHandlerMockRecorder
- func (mr *MockOpenIDHandlerMockRecorder) HandleAccessTokenRequest(ctx, preAuthorizedCode interface{}) *gomock.Call
- func (mr *MockOpenIDHandlerMockRecorder) HandleCredentialRequest(ctx, request, accessToken interface{}) *gomock.Call
- func (mr *MockOpenIDHandlerMockRecorder) Metadata() *gomock.Call
- func (mr *MockOpenIDHandlerMockRecorder) OfferCredential(ctx, credential, walletIdentifier interface{}) *gomock.Call
- func (mr *MockOpenIDHandlerMockRecorder) ProviderMetadata() *gomock.Call
- type MockPublisher
- type MockPublisherMockRecorder
- type MockStore
- func (m *MockStore) Close() error
- func (m *MockStore) Diagnostics() []core.DiagnosticResult
- func (m *MockStore) EXPECT() *MockStoreMockRecorder
- func (m *MockStore) GetCredential(id ssi.URI) (*vc.VerifiableCredential, error)
- func (m *MockStore) GetRevocation(id ssi.URI) (*credential.Revocation, error)
- func (m *MockStore) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
- func (m *MockStore) StoreCredential(vc vc.VerifiableCredential) error
- func (m *MockStore) StoreRevocation(r credential.Revocation) error
- type MockStoreMockRecorder
- func (mr *MockStoreMockRecorder) Close() *gomock.Call
- func (mr *MockStoreMockRecorder) Diagnostics() *gomock.Call
- func (mr *MockStoreMockRecorder) GetCredential(id interface{}) *gomock.Call
- func (mr *MockStoreMockRecorder) GetRevocation(id interface{}) *gomock.Call
- func (mr *MockStoreMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call
- func (mr *MockStoreMockRecorder) StoreCredential(vc interface{}) *gomock.Call
- func (mr *MockStoreMockRecorder) StoreRevocation(r interface{}) *gomock.Call
- type MockkeyResolver
- type MockkeyResolverMockRecorder
- type Nonce
- type OpenIDHandler
- type OpenIDStore
- type Publisher
- type Store
Constants ¶
const TokenTTL = 15 * time.Minute
TokenTTL is the time-to-live for issuance flows, access tokens and nonces.
Variables ¶
var ErrUnknownIssuer = errors.New("unknown OpenID4VCI issuer")
ErrUnknownIssuer is returned when the given issuer is unknown.
var TimeFunc = time.Now
TimeFunc is a function that returns the time used, for e.g. signing time. It can be set for testing purposes.
Functions ¶
This section is empty.
Types ¶
type CredentialSearcher ¶
type CredentialSearcher interface {
// SearchCredential searches for issued credentials
// If the passed context is empty, it'll not be part of the search query on the DB.
SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
}
CredentialSearcher defines the functions to resolve or search for credentials. It is a separate interface from Store so when an object only needs resolving, it only needs the resolver.
type Flow ¶
type Flow struct {
ID string `json:"id"`
// IssuerID is the identifier of the credential issuer.
IssuerID string `json:"issuer_id"`
// WalletID is the identifier of the wallet.
WalletID string `json:"wallet_id"`
// Grants is a list of grants that can be used to acquire an access token.
Grants []Grant `json:"grants"`
// Credentials is the list of Verifiable Credentials that be issued to the wallet through this flow.
// It might be pre-determined (in the issuer-initiated flow) or determined during the flow execution (in the wallet-initiated flow).
Credentials []vc.VerifiableCredential `json:"credentials"`
Expiry time.Time `json:"exp"`
}
Flow is an active OpenID4VCI credential issuance flow.
type Grant ¶
type Grant struct {
// Type is the type of grant, e.g. "urn:ietf:params:oauth:grant-type:pre-authorized_code".
Type string `json:"type"`
// Params is a map of parameters for the grant, e.g. "pre-authorized_code" for type "urn:ietf:params:oauth:grant-type:pre-authorized_code".
Params map[string]interface{} `json:"params"`
}
Grant is a grant that has been issued for an OAuth2 state.
type Issuer ¶
type Issuer interface {
// Issue issues a credential by signing an unsigned credential.
// The publish param indicates if the credendential should be published to the network.
// The public param instructs the Publisher to publish the param with a certain visibility.
Issue(ctx context.Context, unsignedCredential vc.VerifiableCredential, publish, public bool) (*vc.VerifiableCredential, error)
// Revoke revokes a credential by the provided type.
// It requires access to the private key of the issuer which will be used to sign the revocation.
// It returns an error when the credential is not issued by this node or is already revoked.
// The revocation will be published to the network by the issuers Publisher.
Revoke(ctx context.Context, credentialID ssi.URI) (*credential.Revocation, error)
CredentialSearcher
}
Issuer is a role in the network for a party who issues credentials about a subject to a holder.
func NewIssuer ¶
func NewIssuer(store Store, vcrStore types.Writer, networkPublisher Publisher, openidHandlerFn func(ctx context.Context, id did.DID) (OpenIDHandler, error), didstore didstore.Store, keyStore crypto.KeyStore, jsonldManager jsonld.JSONLD, trustConfig *trust.Config, ) Issuer
NewIssuer creates a new issuer which implements the Issuer interface. If openidIssuerFn is nil, it won't try to issue over OpenID4VCI. It needs types.Writer since issued credentials need to be in the general VCR store, since that normally happens through receiving the just-issued credential over the network, but that doesn't happen when issuing over OpenID4VCI. Thus, it needs to explicitly save it to the VCR store when issuing over OpenID4VCI. See https://github.com/nuts-foundation/nuts-node/issues/2063
type MockCredentialSearcher ¶
type MockCredentialSearcher struct {
// contains filtered or unexported fields
}
MockCredentialSearcher is a mock of CredentialSearcher interface.
func NewMockCredentialSearcher ¶
func NewMockCredentialSearcher(ctrl *gomock.Controller) *MockCredentialSearcher
NewMockCredentialSearcher creates a new mock instance.
func (*MockCredentialSearcher) EXPECT ¶
func (m *MockCredentialSearcher) EXPECT() *MockCredentialSearcherMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockCredentialSearcher) SearchCredential ¶
func (m *MockCredentialSearcher) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
SearchCredential mocks base method.
type MockCredentialSearcherMockRecorder ¶
type MockCredentialSearcherMockRecorder struct {
// contains filtered or unexported fields
}
MockCredentialSearcherMockRecorder is the mock recorder for MockCredentialSearcher.
func (*MockCredentialSearcherMockRecorder) SearchCredential ¶
func (mr *MockCredentialSearcherMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call
SearchCredential indicates an expected call of SearchCredential.
type MockIssuer ¶
type MockIssuer struct {
// contains filtered or unexported fields
}
MockIssuer is a mock of Issuer interface.
func NewMockIssuer ¶
func NewMockIssuer(ctrl *gomock.Controller) *MockIssuer
NewMockIssuer creates a new mock instance.
func (*MockIssuer) EXPECT ¶
func (m *MockIssuer) EXPECT() *MockIssuerMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockIssuer) Issue ¶
func (m *MockIssuer) Issue(ctx context.Context, unsignedCredential vc.VerifiableCredential, publish, public bool) (*vc.VerifiableCredential, error)
Issue mocks base method.
func (*MockIssuer) Revoke ¶
func (m *MockIssuer) Revoke(ctx context.Context, credentialID ssi.URI) (*credential.Revocation, error)
Revoke mocks base method.
func (*MockIssuer) SearchCredential ¶
func (m *MockIssuer) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
SearchCredential mocks base method.
type MockIssuerMockRecorder ¶
type MockIssuerMockRecorder struct {
// contains filtered or unexported fields
}
MockIssuerMockRecorder is the mock recorder for MockIssuer.
func (*MockIssuerMockRecorder) Issue ¶
func (mr *MockIssuerMockRecorder) Issue(ctx, unsignedCredential, publish, public interface{}) *gomock.Call
Issue indicates an expected call of Issue.
func (*MockIssuerMockRecorder) Revoke ¶
func (mr *MockIssuerMockRecorder) Revoke(ctx, credentialID interface{}) *gomock.Call
Revoke indicates an expected call of Revoke.
func (*MockIssuerMockRecorder) SearchCredential ¶
func (mr *MockIssuerMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call
SearchCredential indicates an expected call of SearchCredential.
type MockOpenIDHandler ¶
type MockOpenIDHandler struct {
// contains filtered or unexported fields
}
MockOpenIDHandler is a mock of OpenIDHandler interface.
func NewMockOpenIDHandler ¶
func NewMockOpenIDHandler(ctrl *gomock.Controller) *MockOpenIDHandler
NewMockOpenIDHandler creates a new mock instance.
func (*MockOpenIDHandler) EXPECT ¶
func (m *MockOpenIDHandler) EXPECT() *MockOpenIDHandlerMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockOpenIDHandler) HandleAccessTokenRequest ¶
func (m *MockOpenIDHandler) HandleAccessTokenRequest(ctx context.Context, preAuthorizedCode string) (string, string, error)
HandleAccessTokenRequest mocks base method.
func (*MockOpenIDHandler) HandleCredentialRequest ¶
func (m *MockOpenIDHandler) HandleCredentialRequest(ctx context.Context, request openid4vci.CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
HandleCredentialRequest mocks base method.
func (*MockOpenIDHandler) Metadata ¶
func (m *MockOpenIDHandler) Metadata() openid4vci.CredentialIssuerMetadata
Metadata mocks base method.
func (*MockOpenIDHandler) OfferCredential ¶
func (m *MockOpenIDHandler) OfferCredential(ctx context.Context, credential vc.VerifiableCredential, walletIdentifier string) error
OfferCredential mocks base method.
func (*MockOpenIDHandler) ProviderMetadata ¶
func (m *MockOpenIDHandler) ProviderMetadata() openid4vci.ProviderMetadata
ProviderMetadata mocks base method.
type MockOpenIDHandlerMockRecorder ¶
type MockOpenIDHandlerMockRecorder struct {
// contains filtered or unexported fields
}
MockOpenIDHandlerMockRecorder is the mock recorder for MockOpenIDHandler.
func (*MockOpenIDHandlerMockRecorder) HandleAccessTokenRequest ¶
func (mr *MockOpenIDHandlerMockRecorder) HandleAccessTokenRequest(ctx, preAuthorizedCode interface{}) *gomock.Call
HandleAccessTokenRequest indicates an expected call of HandleAccessTokenRequest.
func (*MockOpenIDHandlerMockRecorder) HandleCredentialRequest ¶
func (mr *MockOpenIDHandlerMockRecorder) HandleCredentialRequest(ctx, request, accessToken interface{}) *gomock.Call
HandleCredentialRequest indicates an expected call of HandleCredentialRequest.
func (*MockOpenIDHandlerMockRecorder) Metadata ¶
func (mr *MockOpenIDHandlerMockRecorder) Metadata() *gomock.Call
Metadata indicates an expected call of Metadata.
func (*MockOpenIDHandlerMockRecorder) OfferCredential ¶
func (mr *MockOpenIDHandlerMockRecorder) OfferCredential(ctx, credential, walletIdentifier interface{}) *gomock.Call
OfferCredential indicates an expected call of OfferCredential.
func (*MockOpenIDHandlerMockRecorder) ProviderMetadata ¶
func (mr *MockOpenIDHandlerMockRecorder) ProviderMetadata() *gomock.Call
ProviderMetadata indicates an expected call of ProviderMetadata.
type MockPublisher ¶
type MockPublisher struct {
// contains filtered or unexported fields
}
MockPublisher is a mock of Publisher interface.
func NewMockPublisher ¶
func NewMockPublisher(ctrl *gomock.Controller) *MockPublisher
NewMockPublisher creates a new mock instance.
func (*MockPublisher) EXPECT ¶
func (m *MockPublisher) EXPECT() *MockPublisherMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockPublisher) PublishCredential ¶
func (m *MockPublisher) PublishCredential(ctx context.Context, verifiableCredential vc.VerifiableCredential, public bool) error
PublishCredential mocks base method.
func (*MockPublisher) PublishRevocation ¶
func (m *MockPublisher) PublishRevocation(ctx context.Context, revocation credential.Revocation) error
PublishRevocation mocks base method.
type MockPublisherMockRecorder ¶
type MockPublisherMockRecorder struct {
// contains filtered or unexported fields
}
MockPublisherMockRecorder is the mock recorder for MockPublisher.
func (*MockPublisherMockRecorder) PublishCredential ¶
func (mr *MockPublisherMockRecorder) PublishCredential(ctx, verifiableCredential, public interface{}) *gomock.Call
PublishCredential indicates an expected call of PublishCredential.
func (*MockPublisherMockRecorder) PublishRevocation ¶
func (mr *MockPublisherMockRecorder) PublishRevocation(ctx, revocation interface{}) *gomock.Call
PublishRevocation indicates an expected call of PublishRevocation.
type MockStore ¶
type MockStore struct {
// contains filtered or unexported fields
}
MockStore is a mock of Store interface.
func NewMockStore ¶
func NewMockStore(ctrl *gomock.Controller) *MockStore
NewMockStore creates a new mock instance.
func (*MockStore) Diagnostics ¶
func (m *MockStore) Diagnostics() []core.DiagnosticResult
Diagnostics mocks base method.
func (*MockStore) EXPECT ¶
func (m *MockStore) EXPECT() *MockStoreMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockStore) GetCredential ¶
GetCredential mocks base method.
func (*MockStore) GetRevocation ¶
func (m *MockStore) GetRevocation(id ssi.URI) (*credential.Revocation, error)
GetRevocation mocks base method.
func (*MockStore) SearchCredential ¶
func (m *MockStore) SearchCredential(credentialType ssi.URI, issuer did.DID, subject *ssi.URI) ([]vc.VerifiableCredential, error)
SearchCredential mocks base method.
func (*MockStore) StoreCredential ¶
func (m *MockStore) StoreCredential(vc vc.VerifiableCredential) error
StoreCredential mocks base method.
func (*MockStore) StoreRevocation ¶
func (m *MockStore) StoreRevocation(r credential.Revocation) error
StoreRevocation mocks base method.
type MockStoreMockRecorder ¶
type MockStoreMockRecorder struct {
// contains filtered or unexported fields
}
MockStoreMockRecorder is the mock recorder for MockStore.
func (*MockStoreMockRecorder) Close ¶
func (mr *MockStoreMockRecorder) Close() *gomock.Call
Close indicates an expected call of Close.
func (*MockStoreMockRecorder) Diagnostics ¶
func (mr *MockStoreMockRecorder) Diagnostics() *gomock.Call
Diagnostics indicates an expected call of Diagnostics.
func (*MockStoreMockRecorder) GetCredential ¶
func (mr *MockStoreMockRecorder) GetCredential(id interface{}) *gomock.Call
GetCredential indicates an expected call of GetCredential.
func (*MockStoreMockRecorder) GetRevocation ¶
func (mr *MockStoreMockRecorder) GetRevocation(id interface{}) *gomock.Call
GetRevocation indicates an expected call of GetRevocation.
func (*MockStoreMockRecorder) SearchCredential ¶
func (mr *MockStoreMockRecorder) SearchCredential(credentialType, issuer, subject interface{}) *gomock.Call
SearchCredential indicates an expected call of SearchCredential.
func (*MockStoreMockRecorder) StoreCredential ¶
func (mr *MockStoreMockRecorder) StoreCredential(vc interface{}) *gomock.Call
StoreCredential indicates an expected call of StoreCredential.
func (*MockStoreMockRecorder) StoreRevocation ¶
func (mr *MockStoreMockRecorder) StoreRevocation(r interface{}) *gomock.Call
StoreRevocation indicates an expected call of StoreRevocation.
type MockkeyResolver ¶
type MockkeyResolver struct {
// contains filtered or unexported fields
}
MockkeyResolver is a mock of keyResolver interface.
func NewMockkeyResolver ¶
func NewMockkeyResolver(ctrl *gomock.Controller) *MockkeyResolver
NewMockkeyResolver creates a new mock instance.
func (*MockkeyResolver) EXPECT ¶
func (m *MockkeyResolver) EXPECT() *MockkeyResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockkeyResolver) ResolveAssertionKey ¶
func (m *MockkeyResolver) ResolveAssertionKey(ctx context.Context, issuerDID did.DID) (crypto.Key, error)
ResolveAssertionKey mocks base method.
type MockkeyResolverMockRecorder ¶
type MockkeyResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockkeyResolverMockRecorder is the mock recorder for MockkeyResolver.
func (*MockkeyResolverMockRecorder) ResolveAssertionKey ¶
func (mr *MockkeyResolverMockRecorder) ResolveAssertionKey(ctx, issuerDID interface{}) *gomock.Call
ResolveAssertionKey indicates an expected call of ResolveAssertionKey.
type Nonce ¶
Nonce is a nonce that has been issued for an OpenID4VCI flow, to be used by the wallet when requesting credentials. A nonce can only be used once (doh), and is only valid for a certain period of time.
type OpenIDHandler ¶
type OpenIDHandler interface {
// ProviderMetadata returns the OpenID Connect provider metadata.
ProviderMetadata() openid4vci.ProviderMetadata
// HandleAccessTokenRequest handles an OAuth2 access token request for the given issuer and pre-authorized code.
// It returns the access token and a c_nonce.
HandleAccessTokenRequest(ctx context.Context, preAuthorizedCode string) (string, string, error)
// Metadata returns the OpenID4VCI credential issuer metadata for the given issuer.
Metadata() openid4vci.CredentialIssuerMetadata
// OfferCredential sends a credential offer to the specified wallet. It derives the issuer from the credential.
OfferCredential(ctx context.Context, credential vc.VerifiableCredential, walletIdentifier string) error
// HandleCredentialRequest requests a credential from the given issuer.
HandleCredentialRequest(ctx context.Context, request openid4vci.CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
}
OpenIDHandler defines the interface for handling OpenID4VCI issuer operations.
func NewOpenIDHandler ¶
func NewOpenIDHandler(issuerDID did.DID, issuerIdentifierURL string, definitionsDIR string, httpClient core.HTTPRequestDoer, keyResolver types.KeyResolver, store OpenIDStore) (OpenIDHandler, error)
NewOpenIDHandler creates a new OpenIDHandler instance. The identifier is the Credential Issuer Identifier, e.g. https://example.com/issuer/
type OpenIDStore ¶
type OpenIDStore interface {
// Store saves a new Flow in the store.
Store(ctx context.Context, flow Flow) error
// StoreReference saves a reference to the given Flow, for looking it up later.
// This is used for finding a flow given a secret, e.g. pre-authorized code, authorization code or nonce.
// like a database index. The reference must be unique for all flows.
// The expiry is the time-to-live for the reference. After this time, the reference is automatically deleted.
// If the flow does not exist, or the reference does already exist, it returns an error.
StoreReference(ctx context.Context, flowID string, refType string, reference string, expiry time.Time) error
// FindByReference finds a Flow by its reference.
// If the flow does not exist, it returns nil.
FindByReference(ctx context.Context, refType string, reference string) (*Flow, error)
// DeleteReference deletes the reference from the store.
// It does not return an error if it doesn't exist anymore.
DeleteReference(ctx context.Context, refType string, reference string) error
// Close signals the store to close any owned resources.
Close()
}
OpenIDStore defines the storage API for OpenID Credential Issuance flows.
func NewOpenIDMemoryStore ¶
func NewOpenIDMemoryStore() OpenIDStore
NewOpenIDMemoryStore creates a new in-memory OpenIDStore.
type Publisher ¶
type Publisher interface {
// PublishCredential publishes the credential to the outside world.
// A public flag is used to indicate if everybody can see the credential, or just the involved parties.
PublishCredential(ctx context.Context, verifiableCredential vc.VerifiableCredential, public bool) error
// PublishRevocation publishes the revocation to the outside world.
// It indicates to the network a credential can no longer be used.
PublishRevocation(ctx context.Context, revocation credential.Revocation) error
}
Publisher publishes new credentials and revocations to a channel. Used by a credential issuer.
func NewNetworkPublisher ¶
func NewNetworkPublisher(networkTx network.Transactions, store didstore.Store, keyResolver crypto.KeyResolver) Publisher
NewNetworkPublisher creates a new networkPublisher which implements the Publisher interface. It is the default implementation to use for issuers to publish credentials and revocations to the Nuts network.
type Store ¶
type Store interface {
core.Diagnosable
// GetCredential retrieves an issued credential by ID
// Returns an ErrNotFound when the credential is not in the store
// Returns an ErrMultipleFound when there are multiple credentials with this ID in the store
GetCredential(id ssi.URI) (*vc.VerifiableCredential, error)
// StoreCredential writes a VC to storage.
StoreCredential(vc vc.VerifiableCredential) error
// GetRevocation returns a revocation for a credential ID
// Returns an ErrNotFound when the revocation is not in the store
// Returns an ErrMultipleFound when there are multiple revocations for this credential ID in the store
GetRevocation(id ssi.URI) (*credential.Revocation, error)
// StoreRevocation writes a revocation to storage.
StoreRevocation(r credential.Revocation) error
CredentialSearcher
// Closer closes and frees the underlying resources the store uses.
io.Closer
}
Store defines the interface for an issuer store. An implementation stores all the issued credentials and the revocations.