resolver

package
v6.2.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: GPL-3.0 Imports: 12 Imported by: 0

Documentation

Overview

Package resolver is a generated GoMock package.

Package resolver is a generated GoMock package.

Package resolver is a generated GoMock package.

Package resolver is a generated GoMock package.

Index

Constants

View Source
const BaseURLServiceType = "node-http-services-baseurl"

BaseURLServiceType is type of the DID service which holds the base URL of the node's HTTP services, exposed to other Nuts nodes. E.g. OpenID4VCI or OAuth2 endpoints.

View Source
const DefaultMaxServiceReferenceDepth = 5

DefaultMaxServiceReferenceDepth holds the default max. allowed depth for DID service references.

View Source
const NutsSigningKeyType = AssertionMethod

NutsSigningKeyType defines the verification method relationship type for signing keys in Nuts DID Documents.

Variables

View Source
var ErrDIDMethodNotSupported = errors.New("DID method not supported")

ErrDIDMethodNotSupported is returned when a DID method is not supported by the DID resolver

View Source
var ErrDIDNotManagedByThisNode = errors.New("DID document not managed by this node")

ErrDIDNotManagedByThisNode is returned when an operation needs the private key and if is not found on this host

View Source
var ErrDeactivated = deactivatedError{/* contains filtered or unexported fields */}

ErrDeactivated signals rejection due to document deactivation.

View Source
var ErrDuplicateService = errors.New("service type is duplicate")

ErrDuplicateService is returned when a DID Document contains a multiple services with the same type

View Source
var ErrKeyNotFound = errors.New("key not found in DID document")

ErrKeyNotFound is returned when a particular key or type of key is not found.

View Source
var ErrNoActiveController = deactivatedError{/* contains filtered or unexported fields */}

ErrNoActiveController The DID supplied to the DID resolution does not have any active controllers.

View Source
var ErrNotFound = errors.New("unable to find the DID document")

ErrNotFound The DID resolver was unable to find the DID document resulting from this resolution request.

View Source
var ErrServiceNotFound = errors.New("service not found in DID Document")

ErrServiceNotFound is returned when the service is not found on a DID

View Source
var ErrServiceReferenceToDeep = errors.New("service references are nested to deeply before resolving to a non-reference")

ErrServiceReferenceToDeep is returned when a service reference is chain is nested too deeply.

Functions

func GetDIDFromURL

func GetDIDFromURL(didURL string) (did.DID, error)

GetDIDFromURL returns the DID from the given URL, stripping any query parameters, path segments and fragments.

func IsDeactivated

func IsDeactivated(document did.Document) bool

IsDeactivated returns true if the DID.Document has already been deactivated

func IsFunctionalResolveError

func IsFunctionalResolveError(target error) bool

IsFunctionalResolveError returns true if the given error indicates the DID or service not being found or invalid, e.g. because it is deactivated, referenced too deeply, etc.

func IsServiceReference

func IsServiceReference(endpoint string) bool

IsServiceReference checks whether the given endpoint string looks like a service reference (e.g. did:nuts:1234/serviceType?type=HelloWorld).

func MakeServiceReference

func MakeServiceReference(subjectDID did.DID, serviceType string) ssi.URI

MakeServiceReference creates a service reference, which can be used as query when looking up services.

func ValidateServiceReference

func ValidateServiceReference(endpointURI ssi.URI) error

ValidateServiceReference checks whether the given URI matches the format for a service reference.

Types

type ChainedDIDResolver

type ChainedDIDResolver struct {
	Resolvers []DIDResolver
}

ChainedDIDResolver is a DID resolver that tries to resolve the DID with multiple resolvers. E.g., it could first attempt a caching DID resolver, then a network DID resolver. If the first resolver returns ErrNotFound, the next resolver is tried. Other errors of the first resolver are returned immediately.

func (ChainedDIDResolver) Resolve

type DIDKeyResolver

type DIDKeyResolver struct {
	Resolver DIDResolver
}

DIDKeyResolver implements the DIDKeyResolver interface that uses keys from resolved DIDs.

func (DIDKeyResolver) ResolveKey

func (r DIDKeyResolver) ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)

func (DIDKeyResolver) ResolveKeyByID

func (r DIDKeyResolver) ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)

type DIDResolver

type DIDResolver interface {
	// Resolve returns a DID Document for the provided DID.
	// If metadata is not provided the latest version is returned.
	// If metadata is provided then the result is filtered or scoped on that metadata.
	// It returns ErrNotFound if there are no corresponding DID documents or when the DID Documents are disjoint with the provided ResolveMetadata
	// It returns ErrDeactivated if the DID Document has been deactivated and metadata is unset or metadata.AllowDeactivated is false.
	// It returns ErrNoActiveController if all of the DID Documents controllers have been deactivated and metadata is unset or metadata.AllowDeactivated is false.
	Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)
}

DIDResolver is the interface for DID resolvers: the process of getting the backing document of a DID.

type DIDResolverRouter

type DIDResolverRouter struct {
	// contains filtered or unexported fields
}

DIDResolverRouter is a DID resolver that can route to different DID resolvers based on the DID method

func (*DIDResolverRouter) Register

func (r *DIDResolverRouter) Register(method string, resolver DIDResolver)

Register registers a DID resolver for the given DID method.

func (*DIDResolverRouter) Resolve

func (r *DIDResolverRouter) Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)

Resolve looks up the right resolver for the given DID and delegates the resolution to it. If no resolver is registered for the given DID method, ErrDIDMethodNotSupported is returned.

type DIDServiceResolver

type DIDServiceResolver struct {
	Resolver DIDResolver
}

DIDServiceResolver is a wrapper around a DID store that allows resolving services, following references.

func (DIDServiceResolver) Resolve

func (s DIDServiceResolver) Resolve(query ssi.URI, maxDepth int) (did.Service, error)

func (DIDServiceResolver) ResolveEx

func (s DIDServiceResolver) ResolveEx(endpoint ssi.URI, depth int, maxDepth int, documentCache map[string]*did.Document) (did.Service, error)

type DocFinder

type DocFinder interface {
	Find(...Predicate) ([]did.Document, error)
}

DocFinder is the interface that groups all methods for finding DID documents based on search conditions

type DocIterator

type DocIterator func(doc did.Document, metadata DocumentMetadata) error

DocIterator is the function type for iterating over the all current DID Documents in the store

type DocumentMetadata

type DocumentMetadata struct {
	Created time.Time  `json:"created"`
	Updated *time.Time `json:"updated,omitempty"`
	// Hash of DID document bytes. Is equal to payloadHash in network layer.
	Hash hash.SHA256Hash `json:"hash"`
	// PreviousHash of the previous version of this DID document
	PreviousHash *hash.SHA256Hash `json:"previousHash,omitempty"`
	// SourceTransactions points to the transaction(s) that created the current version of this DID Document.
	// If multiple transactions are listed, the DID Document is conflicted
	SourceTransactions []hash.SHA256Hash `json:"txs"`
	// Deactivated indicates if the document is deactivated
	Deactivated bool `json:"deactivated"`
}

DocumentMetadata holds the metadata of a DID document

func (DocumentMetadata) Copy

Copy creates a deep copy of DocumentMetadata

func (DocumentMetadata) IsConflicted

func (m DocumentMetadata) IsConflicted() bool

IsConflicted returns if a DID Document is conflicted

type KeyResolver

type KeyResolver interface {
	// ResolveKeyByID looks up a specific key of the given RelationType and returns it as crypto.PublicKey.
	// If multiple keys are valid, the first one is returned.
	// An ErrKeyNotFound is returned when no key (of the specified type) is found.
	ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)
	// ResolveKey looks for a valid key of the given RelationType for the given DID, and returns its ID as string and the public key.
	// If multiple keys are valid, the first one is returned.
	// An ErrKeyNotFound is returned when no key (of the specified type) is found.
	ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)
}

KeyResolver is the interface for resolving keys. This can be used for checking if a signing key is valid at a point in time or to just find a valid key for signing.

type MockDIDResolver

type MockDIDResolver struct {
	// contains filtered or unexported fields
}

MockDIDResolver is a mock of DIDResolver interface.

func NewMockDIDResolver

func NewMockDIDResolver(ctrl *gomock.Controller) *MockDIDResolver

NewMockDIDResolver creates a new mock instance.

func (*MockDIDResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockDIDResolver) Resolve

func (m *MockDIDResolver) Resolve(id did.DID, metadata *ResolveMetadata) (*did.Document, *DocumentMetadata, error)

Resolve mocks base method.

type MockDIDResolverMockRecorder

type MockDIDResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockDIDResolverMockRecorder is the mock recorder for MockDIDResolver.

func (*MockDIDResolverMockRecorder) Resolve

func (mr *MockDIDResolverMockRecorder) Resolve(id, metadata any) *gomock.Call

Resolve indicates an expected call of Resolve.

type MockDocFinder

type MockDocFinder struct {
	// contains filtered or unexported fields
}

MockDocFinder is a mock of DocFinder interface.

func NewMockDocFinder

func NewMockDocFinder(ctrl *gomock.Controller) *MockDocFinder

NewMockDocFinder creates a new mock instance.

func (*MockDocFinder) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockDocFinder) Find

func (m *MockDocFinder) Find(arg0 ...Predicate) ([]did.Document, error)

Find mocks base method.

type MockDocFinderMockRecorder

type MockDocFinderMockRecorder struct {
	// contains filtered or unexported fields
}

MockDocFinderMockRecorder is the mock recorder for MockDocFinder.

func (*MockDocFinderMockRecorder) Find

func (mr *MockDocFinderMockRecorder) Find(arg0 ...any) *gomock.Call

Find indicates an expected call of Find.

type MockKeyResolver

type MockKeyResolver struct {
	// contains filtered or unexported fields
}

MockKeyResolver is a mock of KeyResolver interface.

func NewMockKeyResolver

func NewMockKeyResolver(ctrl *gomock.Controller) *MockKeyResolver

NewMockKeyResolver creates a new mock instance.

func (*MockKeyResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockKeyResolver) ResolveKey

func (m *MockKeyResolver) ResolveKey(id did.DID, validAt *time.Time, relationType RelationType) (string, crypto.PublicKey, error)

ResolveKey mocks base method.

func (*MockKeyResolver) ResolveKeyByID

func (m *MockKeyResolver) ResolveKeyByID(keyID string, metadata *ResolveMetadata, relationType RelationType) (crypto.PublicKey, error)

ResolveKeyByID mocks base method.

type MockKeyResolverMockRecorder

type MockKeyResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockKeyResolverMockRecorder is the mock recorder for MockKeyResolver.

func (*MockKeyResolverMockRecorder) ResolveKey

func (mr *MockKeyResolverMockRecorder) ResolveKey(id, validAt, relationType any) *gomock.Call

ResolveKey indicates an expected call of ResolveKey.

func (*MockKeyResolverMockRecorder) ResolveKeyByID

func (mr *MockKeyResolverMockRecorder) ResolveKeyByID(keyID, metadata, relationType any) *gomock.Call

ResolveKeyByID indicates an expected call of ResolveKeyByID.

type MockNutsKeyResolver

type MockNutsKeyResolver struct {
	// contains filtered or unexported fields
}

MockNutsKeyResolver is a mock of NutsKeyResolver interface.

func NewMockNutsKeyResolver

func NewMockNutsKeyResolver(ctrl *gomock.Controller) *MockNutsKeyResolver

NewMockNutsKeyResolver creates a new mock instance.

func (*MockNutsKeyResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockNutsKeyResolver) ResolvePublicKey

func (m *MockNutsKeyResolver) ResolvePublicKey(kid string, sourceTransactionsRefs []hash.SHA256Hash) (crypto.PublicKey, error)

ResolvePublicKey mocks base method.

type MockNutsKeyResolverMockRecorder

type MockNutsKeyResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockNutsKeyResolverMockRecorder is the mock recorder for MockNutsKeyResolver.

func (*MockNutsKeyResolverMockRecorder) ResolvePublicKey

func (mr *MockNutsKeyResolverMockRecorder) ResolvePublicKey(kid, sourceTransactionsRefs any) *gomock.Call

ResolvePublicKey indicates an expected call of ResolvePublicKey.

type MockPredicate

type MockPredicate struct {
	// contains filtered or unexported fields
}

MockPredicate is a mock of Predicate interface.

func NewMockPredicate

func NewMockPredicate(ctrl *gomock.Controller) *MockPredicate

NewMockPredicate creates a new mock instance.

func (*MockPredicate) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockPredicate) Match

func (m *MockPredicate) Match(arg0 did.Document, arg1 DocumentMetadata) bool

Match mocks base method.

type MockPredicateMockRecorder

type MockPredicateMockRecorder struct {
	// contains filtered or unexported fields
}

MockPredicateMockRecorder is the mock recorder for MockPredicate.

func (*MockPredicateMockRecorder) Match

func (mr *MockPredicateMockRecorder) Match(arg0, arg1 any) *gomock.Call

Match indicates an expected call of Match.

type MockServiceResolver

type MockServiceResolver struct {
	// contains filtered or unexported fields
}

MockServiceResolver is a mock of ServiceResolver interface.

func NewMockServiceResolver

func NewMockServiceResolver(ctrl *gomock.Controller) *MockServiceResolver

NewMockServiceResolver creates a new mock instance.

func (*MockServiceResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockServiceResolver) Resolve

func (m *MockServiceResolver) Resolve(query ssi.URI, maxDepth int) (did.Service, error)

Resolve mocks base method.

func (*MockServiceResolver) ResolveEx

func (m *MockServiceResolver) ResolveEx(endpoint ssi.URI, depth, maxDepth int, documentCache map[string]*did.Document) (did.Service, error)

ResolveEx mocks base method.

type MockServiceResolverMockRecorder

type MockServiceResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockServiceResolverMockRecorder is the mock recorder for MockServiceResolver.

func (*MockServiceResolverMockRecorder) Resolve

func (mr *MockServiceResolverMockRecorder) Resolve(query, maxDepth any) *gomock.Call

Resolve indicates an expected call of Resolve.

func (*MockServiceResolverMockRecorder) ResolveEx

func (mr *MockServiceResolverMockRecorder) ResolveEx(endpoint, depth, maxDepth, documentCache any) *gomock.Call

ResolveEx indicates an expected call of ResolveEx.

type NutsKeyResolver

type NutsKeyResolver interface {
	// ResolvePublicKey loads the key from a DID Document where the DID Document
	// was created with one of the given tx refs
	// It returns ErrKeyNotFound when the key could not be found in the DID Document.
	// It returns ErrNotFound when the DID Document can't be found.
	ResolvePublicKey(kid string, sourceTransactionsRefs []hash.SHA256Hash) (crypto.PublicKey, error)
}

NutsKeyResolver is the interface for resolving keys from Nuts DID Documents, supporting Nuts-specific DID resolution parameters.

type Predicate

type Predicate interface {
	// Match returns true if the given DID Document passes the predicate condition
	Match(did.Document, DocumentMetadata) bool
}

Predicate is an interface for abstracting search options on DID documents

func ByServiceType

func ByServiceType(serviceType string) Predicate

ByServiceType returns a predicate that matches on service type it only matches on DID Documents with a concrete endpoint (not starting with "did")

func IsActive

func IsActive() Predicate

IsActive returns a predicate that matches DID Documents that are not deactivated.

func ValidAt

func ValidAt(at time.Time) Predicate

ValidAt returns a predicate that matches on validity period.

type RelationType

type RelationType uint

RelationType is the type that contains the different possible relationships between a DID Document and a VerificationMethod They are defined in the DID spec: https://www.w3.org/TR/did-core/#verification-relationships

const (
	Authentication       RelationType = iota
	AssertionMethod      RelationType = iota
	KeyAgreement         RelationType = iota
	CapabilityInvocation RelationType = iota
	CapabilityDelegation RelationType = iota
)

type ResolveMetadata

type ResolveMetadata struct {
	// Resolve the version which is valid at this time
	ResolveTime *time.Time
	// if provided, use the version which matches this exact hash
	Hash *hash.SHA256Hash
	// SourceTransaction must match a TX hash from the metadata.SourceTransaction field, if provided
	SourceTransaction *hash.SHA256Hash
	// Allow DIDs which are deactivated
	AllowDeactivated bool
	// JWT protected headers
	JwtProtectedHeaders map[string]interface{}
}

ResolveMetadata contains metadata for the resolver.

func (*ResolveMetadata) GetProtectedHeaderChain

func (m *ResolveMetadata) GetProtectedHeaderChain(key string) (*cert.Chain, bool)

GetProtectedHeaderChain retrieves a certificate chain from JwtProtectedHeaders for the specified key. It returns the chain and a boolean indicating whether the key was found and its value was a certificate chain.

func (*ResolveMetadata) GetProtectedHeaderString

func (m *ResolveMetadata) GetProtectedHeaderString(key string) (string, bool)

GetProtectedHeaderString retrieves the string value associated with the specified key from JwtProtectedHeaders. It returns the value as a string and a boolean indicating whether the key was found and its value was a string. If JwtProtectedHeaders is nil or the key is not found or its value is not a string, it returns an empty string and false.

type ServiceQueryError

type ServiceQueryError struct {
	Err error // cause
}

ServiceQueryError denies the query based on validation constraints.

func (ServiceQueryError) Error

func (e ServiceQueryError) Error() string

Error implements the error interface.

func (ServiceQueryError) Unwrap

func (e ServiceQueryError) Unwrap() error

Unwrap implements the errors.Unwrap convention.

type ServiceResolver

type ServiceResolver interface {
	// Resolve looks up the DID document of the specified query and then tries to find the service with the specified type.
	// The query must be in the form of a service query, e.g. `did:nuts:12345/serviceEndpoint?type=some-type`.
	// The maxDepth indicates how deep references are followed. If maxDepth = 0, no references are followed (and an error is returned if the given query resolves to a reference).
	// If the DID document or service is not found, a reference can't be resolved or the references exceed maxDepth, an error is returned.
	Resolve(query ssi.URI, maxDepth int) (did.Service, error)

	// ResolveEx tries to resolve a DID service from the given endpoint URI, following references (URIs that begin with 'did:').
	// When the endpoint is a reference it resolves it up until the (per spec) max reference depth. When resolving a reference it recursively calls itself with depth + 1.
	// The documentCache map is used to avoid resolving the same document over and over again, which might be a (slightly more) expensive operation.
	ResolveEx(endpoint ssi.URI, depth int, maxDepth int, documentCache map[string]*did.Document) (did.Service, error)
}

ServiceResolver allows looking up DID document services, following references.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL