iam

package
v6.2.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 32 Imported by: 0

Documentation

Overview

Package iam is a generated GoMock package.

Index

Constants

This section is empty.

Variables

View Source
var ErrBadGateway = errors.New("upstream returned unexpected result")

ErrBadGateway is returned when the node makes a http call as client and the upstream returns an unexpected result.

View Source
var ErrInvalidClientCall = errors.New("invalid client call")

ErrInvalidClientCall is returned when the node makes a http call as client based on wrong information passed by the client.

View Source
var ErrPreconditionFailed = errors.New("precondition failed")

ErrPreconditionFailed is returned when a precondition is not met.

Functions

This section is empty.

Types

type Client

type Client interface {
	// AccessToken requests an access token at the oauth2 token endpoint.
	// The token endpoint can be a regular OAuth2 token endpoint or OpenID4VCI-related endpoint.
	// The response will be unmarshalled into the given tokenResponseOut parameter.
	AccessToken(ctx context.Context, code string, tokenURI, callbackURI string, subject string, clientID string, codeVerifier string, useDPoP bool) (*oauth.TokenResponse, error)
	// AuthorizationServerMetadata returns the metadata of the remote wallet.
	// oauthIssuer is the URL of the issuer as specified by RFC 8414 (OAuth 2.0 Authorization Server Metadata).
	// For client_id's used by Nuts nodes, these are constructed as https://example.com/oauth2/<subject>
	AuthorizationServerMetadata(ctx context.Context, oauthIssuer string) (*oauth.AuthorizationServerMetadata, error)
	// ClientMetadata returns the metadata of the remote verifier.
	ClientMetadata(ctx context.Context, endpoint string) (*oauth.OAuthClientMetadata, error)
	// PostError posts an error to the verifier. If it fails, an error is returned.
	PostError(ctx context.Context, auth2Error oauth.OAuth2Error, verifierResponseURI string, verifierClientState string) (string, error)
	// PostAuthorizationResponse posts the authorization response to the verifier. If it fails, an error is returned.
	PostAuthorizationResponse(ctx context.Context, vp vc.VerifiablePresentation, presentationSubmission pe.PresentationSubmission, verifierResponseURI string, state string) (string, error)
	// PresentationDefinition returns the presentation definition from the given endpoint.
	PresentationDefinition(ctx context.Context, endpoint string) (*pe.PresentationDefinition, error)
	// RequestRFC021AccessToken is called by the local EHR node to request an access token from a remote OAuth2 Authorization Server using Nuts RFC021.
	RequestRFC021AccessToken(ctx context.Context, clientID string, subjectDID string, authServerURL string, scopes string, useDPoP bool,
		credentials []vc.VerifiableCredential) (*oauth.TokenResponse, error)

	// OpenIdCredentialIssuerMetadata returns the metadata of the remote credential issuer.
	// oauthIssuer is the URL of the issuer as specified by RFC 8414 (OAuth 2.0 Authorization Server Metadata).
	OpenIdCredentialIssuerMetadata(ctx context.Context, oauthIssuerURI string) (*oauth.OpenIDCredentialIssuerMetadata, error)
	// OpenIDConfiguration returns the OpenID Configuration of the remote wallet.
	OpenIDConfiguration(ctx context.Context, issuer string) (*oauth.OpenIDConfiguration, error)
	// VerifiableCredentials requests Verifiable Credentials from the issuer at the given endpoint.
	VerifiableCredentials(ctx context.Context, credentialEndpoint string, accessToken string, proofJWT string) (*CredentialResponse, error)
	// RequestObjectByGet retrieves the RequestObjectByGet from the authorization request's 'request_uri' endpoint using a GET method as defined in RFC9101/OpenID4VP.
	// This method is used when there is no 'request_uri_method', or its value is 'get'.
	RequestObjectByGet(ctx context.Context, requestURI string) (string, error)
	// RequestObjectByPost retrieves the RequestObjectByGet from the authorization request's 'request_uri' endpoint using a POST method as defined in RFC9101/OpenID4VP.
	// This method is used when the 'request_uri_method' is 'post'.
	RequestObjectByPost(ctx context.Context, requestURI string, walletMetadata oauth.AuthorizationServerMetadata) (string, error)
}

Client defines OpenID4VP client methods using the IAM OpenAPI Spec.

type CredentialRequest

type CredentialRequest struct {
	Proof CredentialRequestProof `json:"proof"`
}

CredentialRequest represents ths request to fetch a credential, the JSON object holds the proof as CredentialRequestProof.

type CredentialRequestProof

type CredentialRequestProof struct {
	ProofType string `json:"proof_type"`
	Jwt       string `json:"jwt"`
}

CredentialRequestProof holds the ProofType and Jwt for a credential request

type CredentialResponse

type CredentialResponse struct {
	Credential string `json:"credential"`
}

CredentialResponse represents the response of a verifiable credential request. It contains the Format and the actual Credential in JSON format.

type HTTPClient

type HTTPClient struct {
	// contains filtered or unexported fields
}

HTTPClient holds the server address and other basic settings for the http client

func (HTTPClient) AccessToken

func (hb HTTPClient) AccessToken(ctx context.Context, tokenEndpoint string, data url.Values, dpopHeader string) (oauth.TokenResponse, error)

func (HTTPClient) ClientMetadata

func (hb HTTPClient) ClientMetadata(ctx context.Context, endpoint string) (*oauth.OAuthClientMetadata, error)

ClientMetadata retrieves the client metadata from the client metadata endpoint given in the authorization request. We use the AuthorizationServerMetadata struct since it overlaps greatly with the client metadata.

func (HTTPClient) KeyProvider

func (hb HTTPClient) KeyProvider() jws.KeyProviderFunc

func (HTTPClient) OAuthAuthorizationServerMetadata

func (hb HTTPClient) OAuthAuthorizationServerMetadata(ctx context.Context, oauthIssuer string) (*oauth.AuthorizationServerMetadata, error)

OAuthAuthorizationServerMetadata retrieves the OAuth authorization server metadata for the given oauth issuer. oauthIssuer is the oauth.AuthorizationServerMetadata.Issuer from which the metadata endpoint is derived.

func (HTTPClient) OpenIDConfiguration

func (hb HTTPClient) OpenIDConfiguration(ctx context.Context, issuerURL string) (*oauth.OpenIDConfiguration, error)

func (HTTPClient) OpenIdCredentialIssuerMetadata

func (hb HTTPClient) OpenIdCredentialIssuerMetadata(ctx context.Context, oauthIssuerURI string) (*oauth.OpenIDCredentialIssuerMetadata, error)

func (HTTPClient) PostAuthorizationResponse

func (hb HTTPClient) PostAuthorizationResponse(ctx context.Context, vp vc.VerifiablePresentation, presentationSubmission pe.PresentationSubmission, verifierResponseURI url.URL, state string) (string, error)

PostAuthorizationResponse posts the authorization response to the verifier response URL and returns the callback URL.

func (HTTPClient) PostError

func (hb HTTPClient) PostError(ctx context.Context, err oauth.OAuth2Error, verifierCallbackURL url.URL) (string, error)

PostError posts an OAuth error to the redirect URL and returns the redirect URL with the error as query parameter.

func (HTTPClient) PresentationDefinition

func (hb HTTPClient) PresentationDefinition(ctx context.Context, presentationDefinitionURL url.URL) (*pe.PresentationDefinition, error)

PresentationDefinition retrieves the presentation definition from the presentation definition endpoint (as specified by RFC021) for the given scope.

func (HTTPClient) RequestObjectByGet

func (hb HTTPClient) RequestObjectByGet(ctx context.Context, requestURI string) (string, error)

RequestObjectByGet retrieves the Authorization Request Object from the requestURI using the GET method

func (HTTPClient) RequestObjectByPost

func (hb HTTPClient) RequestObjectByPost(ctx context.Context, requestURI string, form url.Values) (string, error)

RequestObjectByPost retrieves the Authorization Request Object from the requestURI using the POST method. additional request parameters (wallet_metadata and wallet_nonce) are provided as url.Values.

func (HTTPClient) VerifiableCredentials

func (hb HTTPClient) VerifiableCredentials(ctx context.Context, credentialEndpoint string, accessToken string, proofJwt string) (*CredentialResponse, error)

type MockClient

type MockClient struct {
	// contains filtered or unexported fields
}

MockClient is a mock of Client interface.

func NewMockClient

func NewMockClient(ctrl *gomock.Controller) *MockClient

NewMockClient creates a new mock instance.

func (*MockClient) AccessToken

func (m *MockClient) AccessToken(ctx context.Context, code, tokenURI, callbackURI, subject, clientID, codeVerifier string, useDPoP bool) (*oauth.TokenResponse, error)

AccessToken mocks base method.

func (*MockClient) AuthorizationServerMetadata

func (m *MockClient) AuthorizationServerMetadata(ctx context.Context, oauthIssuer string) (*oauth.AuthorizationServerMetadata, error)

AuthorizationServerMetadata mocks base method.

func (*MockClient) ClientMetadata

func (m *MockClient) ClientMetadata(ctx context.Context, endpoint string) (*oauth.OAuthClientMetadata, error)

ClientMetadata mocks base method.

func (*MockClient) EXPECT

func (m *MockClient) EXPECT() *MockClientMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockClient) OpenIDConfiguration

func (m *MockClient) OpenIDConfiguration(ctx context.Context, issuer string) (*oauth.OpenIDConfiguration, error)

OpenIDConfiguration mocks base method.

func (*MockClient) OpenIdCredentialIssuerMetadata

func (m *MockClient) OpenIdCredentialIssuerMetadata(ctx context.Context, oauthIssuerURI string) (*oauth.OpenIDCredentialIssuerMetadata, error)

OpenIdCredentialIssuerMetadata mocks base method.

func (*MockClient) PostAuthorizationResponse

func (m *MockClient) PostAuthorizationResponse(ctx context.Context, vp vc.VerifiablePresentation, presentationSubmission pe.PresentationSubmission, verifierResponseURI, state string) (string, error)

PostAuthorizationResponse mocks base method.

func (*MockClient) PostError

func (m *MockClient) PostError(ctx context.Context, auth2Error oauth.OAuth2Error, verifierResponseURI, verifierClientState string) (string, error)

PostError mocks base method.

func (*MockClient) PresentationDefinition

func (m *MockClient) PresentationDefinition(ctx context.Context, endpoint string) (*pe.PresentationDefinition, error)

PresentationDefinition mocks base method.

func (*MockClient) RequestObjectByGet

func (m *MockClient) RequestObjectByGet(ctx context.Context, requestURI string) (string, error)

RequestObjectByGet mocks base method.

func (*MockClient) RequestObjectByPost

func (m *MockClient) RequestObjectByPost(ctx context.Context, requestURI string, walletMetadata oauth.AuthorizationServerMetadata) (string, error)

RequestObjectByPost mocks base method.

func (*MockClient) RequestRFC021AccessToken

func (m *MockClient) RequestRFC021AccessToken(ctx context.Context, clientID, subjectDID, authServerURL, scopes string, useDPoP bool, credentials []vc.VerifiableCredential) (*oauth.TokenResponse, error)

RequestRFC021AccessToken mocks base method.

func (*MockClient) VerifiableCredentials

func (m *MockClient) VerifiableCredentials(ctx context.Context, credentialEndpoint, accessToken, proofJWT string) (*CredentialResponse, error)

VerifiableCredentials mocks base method.

type MockClientMockRecorder

type MockClientMockRecorder struct {
	// contains filtered or unexported fields
}

MockClientMockRecorder is the mock recorder for MockClient.

func (*MockClientMockRecorder) AccessToken

func (mr *MockClientMockRecorder) AccessToken(ctx, code, tokenURI, callbackURI, subject, clientID, codeVerifier, useDPoP any) *gomock.Call

AccessToken indicates an expected call of AccessToken.

func (*MockClientMockRecorder) AuthorizationServerMetadata

func (mr *MockClientMockRecorder) AuthorizationServerMetadata(ctx, oauthIssuer any) *gomock.Call

AuthorizationServerMetadata indicates an expected call of AuthorizationServerMetadata.

func (*MockClientMockRecorder) ClientMetadata

func (mr *MockClientMockRecorder) ClientMetadata(ctx, endpoint any) *gomock.Call

ClientMetadata indicates an expected call of ClientMetadata.

func (*MockClientMockRecorder) OpenIDConfiguration

func (mr *MockClientMockRecorder) OpenIDConfiguration(ctx, issuer any) *gomock.Call

OpenIDConfiguration indicates an expected call of OpenIDConfiguration.

func (*MockClientMockRecorder) OpenIdCredentialIssuerMetadata

func (mr *MockClientMockRecorder) OpenIdCredentialIssuerMetadata(ctx, oauthIssuerURI any) *gomock.Call

OpenIdCredentialIssuerMetadata indicates an expected call of OpenIdCredentialIssuerMetadata.

func (*MockClientMockRecorder) PostAuthorizationResponse

func (mr *MockClientMockRecorder) PostAuthorizationResponse(ctx, vp, presentationSubmission, verifierResponseURI, state any) *gomock.Call

PostAuthorizationResponse indicates an expected call of PostAuthorizationResponse.

func (*MockClientMockRecorder) PostError

func (mr *MockClientMockRecorder) PostError(ctx, auth2Error, verifierResponseURI, verifierClientState any) *gomock.Call

PostError indicates an expected call of PostError.

func (*MockClientMockRecorder) PresentationDefinition

func (mr *MockClientMockRecorder) PresentationDefinition(ctx, endpoint any) *gomock.Call

PresentationDefinition indicates an expected call of PresentationDefinition.

func (*MockClientMockRecorder) RequestObjectByGet

func (mr *MockClientMockRecorder) RequestObjectByGet(ctx, requestURI any) *gomock.Call

RequestObjectByGet indicates an expected call of RequestObjectByGet.

func (*MockClientMockRecorder) RequestObjectByPost

func (mr *MockClientMockRecorder) RequestObjectByPost(ctx, requestURI, walletMetadata any) *gomock.Call

RequestObjectByPost indicates an expected call of RequestObjectByPost.

func (*MockClientMockRecorder) RequestRFC021AccessToken

func (mr *MockClientMockRecorder) RequestRFC021AccessToken(ctx, clientID, subjectDID, authServerURL, scopes, useDPoP, credentials any) *gomock.Call

RequestRFC021AccessToken indicates an expected call of RequestRFC021AccessToken.

func (*MockClientMockRecorder) VerifiableCredentials

func (mr *MockClientMockRecorder) VerifiableCredentials(ctx, credentialEndpoint, accessToken, proofJWT any) *gomock.Call

VerifiableCredentials indicates an expected call of VerifiableCredentials.

type OpenID4VPClient

type OpenID4VPClient struct {
	// contains filtered or unexported fields
}

func NewClient

func NewClient(wallet holder.Wallet, keyResolver resolver.KeyResolver, subjectManager didsubject.Manager, jwtSigner nutsCrypto.JWTSigner,
	ldDocumentLoader ld.DocumentLoader, strictMode bool, httpClientTimeout time.Duration) *OpenID4VPClient

NewClient returns an implementation of Holder

func (*OpenID4VPClient) AccessToken

func (c *OpenID4VPClient) AccessToken(ctx context.Context, code string, tokenEndpoint string, callbackURI string, subject string, clientID string, codeVerifier string, useDPoP bool) (*oauth.TokenResponse, error)

func (*OpenID4VPClient) AuthorizationServerMetadata

func (c *OpenID4VPClient) AuthorizationServerMetadata(ctx context.Context, oauthIssuer string) (*oauth.AuthorizationServerMetadata, error)

func (*OpenID4VPClient) ClientMetadata

func (c *OpenID4VPClient) ClientMetadata(ctx context.Context, endpoint string) (*oauth.OAuthClientMetadata, error)

func (*OpenID4VPClient) OpenIDConfiguration

func (c *OpenID4VPClient) OpenIDConfiguration(ctx context.Context, issuer string) (*oauth.OpenIDConfiguration, error)

func (*OpenID4VPClient) OpenIdCredentialIssuerMetadata

func (c *OpenID4VPClient) OpenIdCredentialIssuerMetadata(ctx context.Context, oauthIssuerURI string) (*oauth.OpenIDCredentialIssuerMetadata, error)

func (*OpenID4VPClient) PostAuthorizationResponse

func (c *OpenID4VPClient) PostAuthorizationResponse(ctx context.Context, vp vc.VerifiablePresentation, presentationSubmission pe.PresentationSubmission, verifierResponseURI string, state string) (string, error)

func (*OpenID4VPClient) PostError

func (c *OpenID4VPClient) PostError(ctx context.Context, auth2Error oauth.OAuth2Error, verifierResponseURI string, verifierClientState string) (string, error)

func (*OpenID4VPClient) PresentationDefinition

func (c *OpenID4VPClient) PresentationDefinition(ctx context.Context, endpoint string) (*pe.PresentationDefinition, error)

func (*OpenID4VPClient) RequestObjectByGet

func (c *OpenID4VPClient) RequestObjectByGet(ctx context.Context, requestURI string) (string, error)

func (*OpenID4VPClient) RequestObjectByPost

func (c *OpenID4VPClient) RequestObjectByPost(ctx context.Context, requestURI string, walletMetadata oauth.AuthorizationServerMetadata) (string, error)

func (*OpenID4VPClient) RequestRFC021AccessToken

func (c *OpenID4VPClient) RequestRFC021AccessToken(ctx context.Context, clientID string, subjectID string, authServerURL string, scopes string,
	useDPoP bool, additionalCredentials []vc.VerifiableCredential) (*oauth.TokenResponse, error)

func (*OpenID4VPClient) VerifiableCredentials

func (c *OpenID4VPClient) VerifiableCredentials(ctx context.Context, credentialEndpoint string, accessToken string, proofJWT string) (*CredentialResponse, error)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL