credential

package
v5.4.40 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: GPL-3.0 Imports: 13 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// NutsOrganizationCredentialType is the VC type for a NutsOrganizationCredential
	NutsOrganizationCredentialType = "NutsOrganizationCredential"
	// NutsAuthorizationCredentialType is the VC type for a NutsAuthorizationCredential
	NutsAuthorizationCredentialType = "NutsAuthorizationCredential"
	// NutsV1Context is the nuts V1 json-ld context
	NutsV1Context = "https://nuts.nl/credentials/v1"
)
View Source
const (
	// CredentialSubjectPath represents the JSON path to the holder of the VC
	CredentialSubjectPath = "credentialSubject.id"
	// RevocationSubjectPath represents the JSON path to the subject of a revocation, typically the VC id
	RevocationSubjectPath = "subject"
)

Variables

View Source
var (
	// NutsOrganizationCredentialTypeURI is the VC type for a NutsOrganizationCredentialType as URI
	NutsOrganizationCredentialTypeURI, _ = ssi.ParseURI(NutsOrganizationCredentialType)
	// NutsAuthorizationCredentialTypeURI is the VC type for a NutsAuthorizationCredentialType as URI
	NutsAuthorizationCredentialTypeURI, _ = ssi.ParseURI(NutsAuthorizationCredentialType)
	// NutsV1ContextURI is the nuts V1 json-ld context as URI
	NutsV1ContextURI = ssi.MustParseURI(NutsV1Context)
)
View Source
var ErrValidation = errors.New("validation failed")

ErrValidation is a common error indicating validation failed

View Source
var RevocationType = ssi.MustParseURI("CredentialRevocation")

RevocationType contains the JSON-LD type for a revocation

Functions

func ExtractTypes

func ExtractTypes(credential vc.VerifiableCredential) []string

ExtractTypes extract additional VC types from the VC as strings It removes the default `VerifiableCredential` type from the types, returns the rest.

func ValidNutsAuthorizationCredential

func ValidNutsAuthorizationCredential() *vc.VerifiableCredential

func ValidateRevocation

func ValidateRevocation(r Revocation) error

ValidateRevocation checks if a revocation record contains the required fields and if fields have the correct value.

Types

type AllFieldsDefinedValidator

type AllFieldsDefinedValidator struct {
	DocumentLoader ld.DocumentLoader
}

AllFieldsDefinedValidator is a Validator that tests whether all fields are defined in the JSON-LD context.

func (AllFieldsDefinedValidator) Validate

Validate implements Validator.Validate.

type BaseCredentialSubject

type BaseCredentialSubject struct {
	ID string `json:"id"`
}

BaseCredentialSubject defines the CredentialSubject struct for fields that are shared amongst all CredentialSubjects

type NutsAuthorizationCredentialSubject

type NutsAuthorizationCredentialSubject struct {
	// ID contains the DID of the subject
	ID string `json:"id"`
	// PurposeOfUse refers to the Bolt access policy
	PurposeOfUse string `json:"purposeOfUse"`
	// Resources contains additional individual resources that can be accessed.
	Resources []Resource `json:"resources,omitempty"`
	// Subject contains a URN referring to the subject of care (not the credential subject)
	Subject *string `json:"subject,omitempty"`
}

NutsAuthorizationCredentialSubject defines the CredentialSubject struct for the NutsAuthorizationCredential

type NutsOrganizationCredentialSubject

type NutsOrganizationCredentialSubject struct {
	ID           string            `json:"id"`
	Organization map[string]string `json:"organization"`
}

NutsOrganizationCredentialSubject defines the CredentialSubject struct for the NutsOrganizationCredential

type Resource

type Resource struct {
	// Path defines the path of the resource relative to the service base URL.
	// Which service acts as base URL is described by the Bolt.
	Path string `json:"path"`
	// Operations define which operations are allowed on the resource.
	Operations []string `json:"operations"`
	// UserContext defines if a user login contract is required for the resource.
	UserContext bool `json:"userContext"`
	// AssuranceLevel defines the assurance level required for the resource (low, substantial, high).
	// Should be set if userContext = true, defaults to low
	AssuranceLevel *string `json:"assuranceLevel"`
}

Resource defines a single accessbile resource

type Revocation

type Revocation struct {
	// Context contains the json-ld contexts
	Context []ssi.URI `json:"@context,omitempty"`
	// Type contains the json-ld type, usually this is CredentialRevocation
	Type []ssi.URI `json:"type,omitempty"`
	// Issuer refers to the party that issued the credential
	Issuer ssi.URI `json:"issuer"`
	// Subject refers to the VC that is revoked
	Subject ssi.URI `json:"subject"`
	// Reason describes why the VC has been revoked
	Reason string `json:"reason,omitempty"`
	// Date is a rfc3339 formatted datetime.
	Date time.Time `json:"date"`
	// Proof contains the cryptographic proof(s). It must be extracted using the Proofs method or UnmarshalProofValue method for non-generic proof fields.
	Proof *vc.JSONWebSignature2020Proof `json:"proof,omitempty"`
}

Revocation defines a proof that a VC has been revoked by its issuer.

func BuildRevocation

func BuildRevocation(issuer ssi.URI, subject ssi.URI) Revocation

BuildRevocation generates a revocation based on the credential

type Validator

type Validator interface {
	// Validate the given credential according to the rules of the VC type.
	Validate(credential vc.VerifiableCredential) error
}

Validator is the interface specific VC verification. Every VC will have its own rules of verification.

func FindValidator

func FindValidator(credential vc.VerifiableCredential) Validator

FindValidator finds the Validator the provided credential based on its Type When no additional type is provided, it returns the default validator

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL