Documentation
¶
Overview ¶
Package resolver is a generated GoMock package.
Package resolver is a generated GoMock package.
Package resolver is a generated GoMock package.
Package resolver is a generated GoMock package.
Index ¶
- Constants
- Variables
- func GetDIDFromURL(didURL string) (did.DID, error)
- func IsDeactivated(document did.Document) bool
- func IsFunctionalResolveError(target error) bool
- func IsServiceReference(endpoint string) bool
- func MakeServiceReference(subjectDID did.DID, serviceType string) ssi.URI
- func ValidateServiceReference(endpointURI ssi.URI) error
- type ChainedDIDResolver
- type DIDKeyResolver
- type DIDResolver
- type DIDResolverRouter
- type DIDServiceResolver
- type DocFinder
- type DocIterator
- type DocumentMetadata
- type KeyResolver
- type MockDIDResolver
- type MockDIDResolverMockRecorder
- type MockDocFinder
- type MockDocFinderMockRecorder
- type MockKeyResolver
- func (m *MockKeyResolver) EXPECT() *MockKeyResolverMockRecorder
- func (m *MockKeyResolver) ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)
- func (m *MockKeyResolver) ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)
- type MockKeyResolverMockRecorder
- type MockNutsKeyResolver
- type MockNutsKeyResolverMockRecorder
- type MockPredicate
- type MockPredicateMockRecorder
- type MockServiceResolver
- type MockServiceResolverMockRecorder
- type NutsKeyResolver
- type Predicate
- type RelationType
- type ResolveMetadata
- type ServiceQueryError
- type ServiceResolver
Constants ¶
const BaseURLServiceType = "node-http-services-baseurl"
BaseURLServiceType is type of the DID service which holds the base URL of the node's HTTP services, exposed to other Nuts nodes. E.g. OpenID4VCI or OAuth2 endpoints.
const DefaultMaxServiceReferenceDepth = 5
DefaultMaxServiceReferenceDepth holds the default max. allowed depth for DID service references.
const NutsSigningKeyType = AssertionMethod
NutsSigningKeyType defines the verification method relationship type for signing keys in Nuts DID Documents.
Variables ¶
var ErrDIDMethodNotSupported = errors.New("DID method not supported")
ErrDIDMethodNotSupported is returned when a DID method is not supported by the DID resolver
var ErrDIDNotManagedByThisNode = errors.New("DID document not managed by this node")
ErrDIDNotManagedByThisNode is returned when an operation needs the private key and if is not found on this host
var ErrDeactivated = deactivatedError{/* contains filtered or unexported fields */}
ErrDeactivated signals rejection due to document deactivation.
var ErrDuplicateService = errors.New("service type is duplicate")
ErrDuplicateService is returned when a DID Document contains a multiple services with the same type
var ErrKeyNotFound = errors.New("key not found in DID document")
ErrKeyNotFound is returned when a particular key or type of key is not found.
var ErrNoActiveController = deactivatedError{/* contains filtered or unexported fields */}
ErrNoActiveController The DID supplied to the DID resolution does not have any active controllers.
var ErrNotFound = errors.New("unable to find the DID document")
ErrNotFound The DID resolver was unable to find the DID document resulting from this resolution request.
var ErrServiceNotFound = errors.New("service not found in DID Document")
ErrServiceNotFound is returned when the service is not found on a DID
var ErrServiceReferenceToDeep = errors.New("service references are nested to deeply before resolving to a non-reference")
ErrServiceReferenceToDeep is returned when a service reference is chain is nested too deeply.
Functions ¶
func GetDIDFromURL ¶
GetDIDFromURL returns the DID from the given URL, stripping any query parameters, path segments and fragments.
func IsDeactivated ¶
IsDeactivated returns true if the DID.Document has already been deactivated
func IsFunctionalResolveError ¶
IsFunctionalResolveError returns true if the given error indicates the DID or service not being found or invalid, e.g. because it is deactivated, referenced too deeply, etc.
func IsServiceReference ¶
IsServiceReference checks whether the given endpoint string looks like a service reference (e.g. did:nuts:1234/serviceType?type=HelloWorld).
func MakeServiceReference ¶
MakeServiceReference creates a service reference, which can be used as query when looking up services.
func ValidateServiceReference ¶
func ValidateServiceReference(endpointURI ssi.URI) error
ValidateServiceReference checks whether the given URI matches the format for a service reference.
Types ¶
type ChainedDIDResolver ¶
type ChainedDIDResolver struct {
Resolvers []DIDResolver
}
ChainedDIDResolver is a DID resolver that tries to resolve the DID with multiple resolvers. E.g., it could first attempt a caching DID resolver, then a network DID resolver. If the first resolver returns ErrNotFound, the next resolver is tried. Other errors of the first resolver are returned immediately.
func (ChainedDIDResolver) Resolve ¶
func (c ChainedDIDResolver) Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)
type DIDKeyResolver ¶
type DIDKeyResolver struct {
Resolver DIDResolver
}
DIDKeyResolver implements the DIDKeyResolver interface that uses keys from resolved DIDs.
func (DIDKeyResolver) ResolveKey ¶
func (r DIDKeyResolver) ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)
func (DIDKeyResolver) ResolveKeyByID ¶
func (r DIDKeyResolver) ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)
type DIDResolver ¶
type DIDResolver interface {
// Resolve returns a DID Document for the provided DID.
// If metadata is not provided the latest version is returned.
// If metadata is provided then the result is filtered or scoped on that metadata.
// It returns ErrNotFound if there are no corresponding DID documents or when the DID Documents are disjoint with the provided ResolveMetadata
// It returns ErrDeactivated if the DID Document has been deactivated and metadata is unset or metadata.AllowDeactivated is false.
// It returns ErrNoActiveController if all of the DID Documents controllers have been deactivated and metadata is unset or metadata.AllowDeactivated is false.
Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)
}
DIDResolver is the interface for DID resolvers: the process of getting the backing document of a DID.
type DIDResolverRouter ¶
type DIDResolverRouter struct {
// contains filtered or unexported fields
}
DIDResolverRouter is a DID resolver that can route to different DID resolvers based on the DID method
func (*DIDResolverRouter) Register ¶
func (r *DIDResolverRouter) Register(method string, resolver DIDResolver)
Register registers a DID resolver for the given DID method.
func (*DIDResolverRouter) Resolve ¶
func (r *DIDResolverRouter) Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)
Resolve looks up the right resolver for the given DID and delegates the resolution to it. If no resolver is registered for the given DID method, ErrDIDMethodNotSupported is returned.
type DIDServiceResolver ¶
type DIDServiceResolver struct {
Resolver DIDResolver
}
DIDServiceResolver is a wrapper around a DID store that allows resolving services, following references.
type DocFinder ¶
DocFinder is the interface that groups all methods for finding DID documents based on search conditions
type DocIterator ¶
type DocIterator func(doc did.Document, metadata DocumentMetadata) error
DocIterator is the function type for iterating over the all current DID Documents in the store
type DocumentMetadata ¶
type DocumentMetadata struct {
Created time.Time `json:"created"`
Updated *time.Time `json:"updated,omitempty"`
// Hash of DID document bytes. Is equal to payloadHash in network layer.
Hash hash.SHA256Hash `json:"hash"`
// PreviousHash of the previous version of this DID document
PreviousHash *hash.SHA256Hash `json:"previousHash,omitempty"`
// SourceTransactions points to the transaction(s) that created the current version of this DID Document.
// If multiple transactions are listed, the DID Document is conflicted
SourceTransactions []hash.SHA256Hash `json:"txs"`
// Deactivated indicates if the document is deactivated
Deactivated bool `json:"deactivated"`
}
DocumentMetadata holds the metadata of a DID document
func (DocumentMetadata) Copy ¶
func (m DocumentMetadata) Copy() DocumentMetadata
Copy creates a deep copy of DocumentMetadata
func (DocumentMetadata) IsConflicted ¶
func (m DocumentMetadata) IsConflicted() bool
IsConflicted returns if a DID Document is conflicted
type KeyResolver ¶
type KeyResolver interface {
// ResolveKeyByID looks up a specific key of the given RelationType and returns it as crypto.PublicKey.
// If multiple keys are valid, the first one is returned.
// An ErrKeyNotFound is returned when no key (of the specified type) is found.
ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)
// ResolveKey looks for a valid key of the given RelationType for the given DID, and returns its ID as string and the public key.
// If multiple keys are valid, the first one is returned.
// An ErrKeyNotFound is returned when no key (of the specified type) is found.
ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)
}
KeyResolver is the interface for resolving keys. This can be used for checking if a signing key is valid at a point in time or to just find a valid key for signing.
type MockDIDResolver ¶
type MockDIDResolver struct {
// contains filtered or unexported fields
}
MockDIDResolver is a mock of DIDResolver interface.
func NewMockDIDResolver ¶
func NewMockDIDResolver(ctrl *gomock.Controller) *MockDIDResolver
NewMockDIDResolver creates a new mock instance.
func (*MockDIDResolver) EXPECT ¶
func (m *MockDIDResolver) EXPECT() *MockDIDResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockDIDResolver) Resolve ¶
func (m *MockDIDResolver) Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)
Resolve mocks base method.
type MockDIDResolverMockRecorder ¶
type MockDIDResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockDIDResolverMockRecorder is the mock recorder for MockDIDResolver.
type MockDocFinder ¶
type MockDocFinder struct {
// contains filtered or unexported fields
}
MockDocFinder is a mock of DocFinder interface.
func NewMockDocFinder ¶
func NewMockDocFinder(ctrl *gomock.Controller) *MockDocFinder
NewMockDocFinder creates a new mock instance.
func (*MockDocFinder) EXPECT ¶
func (m *MockDocFinder) EXPECT() *MockDocFinderMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
type MockDocFinderMockRecorder ¶
type MockDocFinderMockRecorder struct {
// contains filtered or unexported fields
}
MockDocFinderMockRecorder is the mock recorder for MockDocFinder.
type MockKeyResolver ¶
type MockKeyResolver struct {
// contains filtered or unexported fields
}
MockKeyResolver is a mock of KeyResolver interface.
func NewMockKeyResolver ¶
func NewMockKeyResolver(ctrl *gomock.Controller) *MockKeyResolver
NewMockKeyResolver creates a new mock instance.
func (*MockKeyResolver) EXPECT ¶
func (m *MockKeyResolver) EXPECT() *MockKeyResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockKeyResolver) ResolveKey ¶
func (m *MockKeyResolver) ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)
ResolveKey mocks base method.
func (*MockKeyResolver) ResolveKeyByID ¶
func (m *MockKeyResolver) ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)
ResolveKeyByID mocks base method.
type MockKeyResolverMockRecorder ¶
type MockKeyResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockKeyResolverMockRecorder is the mock recorder for MockKeyResolver.
func (*MockKeyResolverMockRecorder) ResolveKey ¶
func (mr *MockKeyResolverMockRecorder) ResolveKey(id, validAt, relationType any) *gomock.Call
ResolveKey indicates an expected call of ResolveKey.
func (*MockKeyResolverMockRecorder) ResolveKeyByID ¶
func (mr *MockKeyResolverMockRecorder) ResolveKeyByID(keyID, metadata, relationType any) *gomock.Call
ResolveKeyByID indicates an expected call of ResolveKeyByID.
type MockNutsKeyResolver ¶
type MockNutsKeyResolver struct {
// contains filtered or unexported fields
}
MockNutsKeyResolver is a mock of NutsKeyResolver interface.
func NewMockNutsKeyResolver ¶
func NewMockNutsKeyResolver(ctrl *gomock.Controller) *MockNutsKeyResolver
NewMockNutsKeyResolver creates a new mock instance.
func (*MockNutsKeyResolver) EXPECT ¶
func (m *MockNutsKeyResolver) EXPECT() *MockNutsKeyResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockNutsKeyResolver) ResolvePublicKey ¶
func (m *MockNutsKeyResolver) ResolvePublicKey(kid string, sourceTransactionsRefs []hash.SHA256Hash) (crypto.PublicKey, error)
ResolvePublicKey mocks base method.
type MockNutsKeyResolverMockRecorder ¶
type MockNutsKeyResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockNutsKeyResolverMockRecorder is the mock recorder for MockNutsKeyResolver.
func (*MockNutsKeyResolverMockRecorder) ResolvePublicKey ¶
func (mr *MockNutsKeyResolverMockRecorder) ResolvePublicKey(kid, sourceTransactionsRefs any) *gomock.Call
ResolvePublicKey indicates an expected call of ResolvePublicKey.
type MockPredicate ¶
type MockPredicate struct {
// contains filtered or unexported fields
}
MockPredicate is a mock of Predicate interface.
func NewMockPredicate ¶
func NewMockPredicate(ctrl *gomock.Controller) *MockPredicate
NewMockPredicate creates a new mock instance.
func (*MockPredicate) EXPECT ¶
func (m *MockPredicate) EXPECT() *MockPredicateMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockPredicate) Match ¶
func (m *MockPredicate) Match(arg0 did.Document, arg1 DocumentMetadata) bool
Match mocks base method.
type MockPredicateMockRecorder ¶
type MockPredicateMockRecorder struct {
// contains filtered or unexported fields
}
MockPredicateMockRecorder is the mock recorder for MockPredicate.
type MockServiceResolver ¶
type MockServiceResolver struct {
// contains filtered or unexported fields
}
MockServiceResolver is a mock of ServiceResolver interface.
func NewMockServiceResolver ¶
func NewMockServiceResolver(ctrl *gomock.Controller) *MockServiceResolver
NewMockServiceResolver creates a new mock instance.
func (*MockServiceResolver) EXPECT ¶
func (m *MockServiceResolver) EXPECT() *MockServiceResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
type MockServiceResolverMockRecorder ¶
type MockServiceResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockServiceResolverMockRecorder is the mock recorder for MockServiceResolver.
type NutsKeyResolver ¶
type NutsKeyResolver interface {
// ResolvePublicKey loads the key from a DID Document where the DID Document
// was created with one of the given tx refs
// It returns ErrKeyNotFound when the key could not be found in the DID Document.
// It returns ErrNotFound when the DID Document can't be found.
ResolvePublicKey(kid string, sourceTransactionsRefs []hash.SHA256Hash) (crypto.PublicKey, error)
}
NutsKeyResolver is the interface for resolving keys from Nuts DID Documents, supporting Nuts-specific DID resolution parameters.
type Predicate ¶
type Predicate interface {
// Match returns true if the given DID Document passes the predicate condition
Match(did.Document, DocumentMetadata) bool
}
Predicate is an interface for abstracting search options on DID documents
func ByServiceType ¶
ByServiceType returns a predicate that matches on service type it only matches on DID Documents with a concrete endpoint (not starting with "did")
type RelationType ¶
type RelationType uint
RelationType is the type that contains the different possible relationships between a DID Document and a VerificationMethod They are defined in the DID spec: https://www.w3.org/TR/did-core/#verification-relationships
const ( Authentication RelationType = iota AssertionMethod RelationType = iota KeyAgreement RelationType = iota CapabilityInvocation RelationType = iota CapabilityDelegation RelationType = iota )
type ResolveMetadata ¶
type ResolveMetadata struct {
// Resolve the version which is valid at this time
ResolveTime *time.Time
// if provided, use the version which matches this exact hash
Hash *hash.SHA256Hash
// SourceTransaction must match a TX hash from the metadata.SourceTransaction field, if provided
SourceTransaction *hash.SHA256Hash
// Allow DIDs which are deactivated
AllowDeactivated bool
// JWT protected headers
JwtProtectedHeaders map[string]interface{}
}
ResolveMetadata contains metadata for the resolver.
func (*ResolveMetadata) GetProtectedHeaderChain ¶
func (m *ResolveMetadata) GetProtectedHeaderChain(key string) (*cert.Chain, bool)
GetProtectedHeaderChain retrieves a certificate chain from JwtProtectedHeaders for the specified key. It returns the chain and a boolean indicating whether the key was found and its value was a certificate chain.
func (*ResolveMetadata) GetProtectedHeaderString ¶
func (m *ResolveMetadata) GetProtectedHeaderString(key string) (string, bool)
GetProtectedHeaderString retrieves the string value associated with the specified key from JwtProtectedHeaders. It returns the value as a string and a boolean indicating whether the key was found and its value was a string. If JwtProtectedHeaders is nil or the key is not found or its value is not a string, it returns an empty string and false.
type ServiceQueryError ¶
type ServiceQueryError struct {
Err error // cause
}
ServiceQueryError denies the query based on validation constraints.
func (ServiceQueryError) Error ¶
func (e ServiceQueryError) Error() string
Error implements the error interface.
func (ServiceQueryError) Unwrap ¶
func (e ServiceQueryError) Unwrap() error
Unwrap implements the errors.Unwrap convention.
type ServiceResolver ¶
type ServiceResolver interface {
// Resolve looks up the DID document of the specified query and then tries to find the service with the specified type.
// The query must be in the form of a service query, e.g. `did:nuts:12345/serviceEndpoint?type=some-type`.
// The maxDepth indicates how deep references are followed. If maxDepth = 0, no references are followed (and an error is returned if the given query resolves to a reference).
// If the DID document or service is not found, a reference can't be resolved or the references exceed maxDepth, an error is returned.
Resolve(query ssi.URI, maxDepth int) (did.Service, error)
// ResolveEx tries to resolve a DID service from the given endpoint URI, following references (URIs that begin with 'did:').
// When the endpoint is a reference it resolves it up until the (per spec) max reference depth. When resolving a reference it recursively calls itself with depth + 1.
// The documentCache map is used to avoid resolving the same document over and over again, which might be a (slightly more) expensive operation.
ResolveEx(endpoint ssi.URI, depth int, maxDepth int, documentCache map[string]*did.Document) (did.Service, error)
}
ServiceResolver allows looking up DID document services, following references.