iam

package
v6.2.13 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: GPL-3.0 Imports: 57 Imported by: 0

Documentation

Overview

Package iam provides primitives to interact with the openapi HTTP API.

Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.4.1 DO NOT EDIT.

Package iam is a generated GoMock package.

Index

Constants

View Source
const (
	AccessTokenTypeBearer = "Bearer"
	AccessTokenTypeDPoP   = "DPoP"
)
View Source
const (
	JwtBearerAuthScopes = "jwtBearerAuth.Scopes"
)

Variables

This section is empty.

Functions

func RegisterHandlers

func RegisterHandlers(router EchoRouter, si ServerInterface)

RegisterHandlers adds each server route to the EchoRouter.

func RegisterHandlersWithBaseURL

func RegisterHandlersWithBaseURL(router EchoRouter, si ServerInterface, baseURL string)

Registers handlers, and prepends BaseURL to the paths, so that the paths can be served under a prefix.

Types

type AccessToken

type AccessToken struct {
	// DPoP is the proof-of-possession of the key for the DID of the entity requesting the access token.
	DPoP *dpop.DPoP `json:"dpop"`
	// Token is the access token
	Token string `json:"token"`
	// Issuer and Subject of a token are always the same.
	Issuer string `json:"issuer"`
	// TODO: should client_id be extracted to the PDPMap using the presentation definition?
	// ClientId is the DID of the entity requesting the access token. The Client needs to proof its id through proof-of-possession of the key for the DID.
	ClientId string `json:"client_id"`
	// IssuedAt is the time the token is issued
	IssuedAt time.Time `json:"issued_at"`
	// Expiration is the time the token expires
	Expiration time.Time `json:"expiration"`
	// Scope the token grants access to. Not necessarily the same as the requested scope
	Scope string `json:"scope"`
	// InputDescriptorConstraintIdMap maps the ID field of a PresentationDefinition input descriptor constraint to the value provided in the VPToken for the constraint.
	// The Policy Decision Point can use this map to make decisions without having to deal with PEX/VCs/VPs/SignatureValidation
	InputDescriptorConstraintIdMap map[string]any `json:"inputdescriptor_constraint_id_map,omitempty"`

	// VPToken contains the VPs provided in the 'assertion' field of the s2s AT request.
	VPToken []VerifiablePresentation `json:"vp_token,omitempty"`
	// PresentationSubmissions as provided in by the wallet to fulfill the required Presentation Definition(s).
	PresentationSubmissions map[string]pe.PresentationSubmission `json:"presentation_submissions,omitempty"`
	// PresentationDefinitions that were required by the verifier to fulfill the request.
	PresentationDefinitions pe.WalletOwnerMapping `json:"presentation_definitions,omitempty"`
}

type Callback302Response

type Callback302Response struct {
	Headers Callback302ResponseHeaders
}

func (Callback302Response) VisitCallbackResponse

func (response Callback302Response) VisitCallbackResponse(w http.ResponseWriter) error

type Callback302ResponseHeaders

type Callback302ResponseHeaders struct {
	Location string
}

type CallbackParams

type CallbackParams struct {
	// Code The authorization code received from the authorization server.
	Code *string `form:"code,omitempty" json:"code,omitempty"`

	// State The client state.
	State *string `form:"state,omitempty" json:"state,omitempty"`

	// Error The error code.
	Error *string `form:"error,omitempty" json:"error,omitempty"`

	// ErrorDescription The error description.
	ErrorDescription *string `form:"error_description,omitempty" json:"error_description,omitempty"`
}

CallbackParams defines parameters for Callback.

type CallbackRequestObject

type CallbackRequestObject struct {
	SubjectID string `json:"subjectID"`
	Params    CallbackParams
}

type CallbackResponseObject

type CallbackResponseObject interface {
	VisitCallbackResponse(w http.ResponseWriter) error
}

type CallbackdefaultApplicationProblemPlusJSONResponse

type CallbackdefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (CallbackdefaultApplicationProblemPlusJSONResponse) VisitCallbackResponse

type Cnf

type Cnf struct {
	// Jkt JWK thumbprint
	Jkt string `json:"jkt"`
}

Cnf The 'confirmation' claim is used in JWTs to proof the possession of a key.

type CreateDPoPProof200JSONResponse

type CreateDPoPProof200JSONResponse DPoPResponse

func (CreateDPoPProof200JSONResponse) VisitCreateDPoPProofResponse

func (response CreateDPoPProof200JSONResponse) VisitCreateDPoPProofResponse(w http.ResponseWriter) error

type CreateDPoPProof401Response

type CreateDPoPProof401Response struct {
}

func (CreateDPoPProof401Response) VisitCreateDPoPProofResponse

func (response CreateDPoPProof401Response) VisitCreateDPoPProofResponse(w http.ResponseWriter) error

type CreateDPoPProofJSONRequestBody

type CreateDPoPProofJSONRequestBody = DPoPRequest

CreateDPoPProofJSONRequestBody defines body for CreateDPoPProof for application/json ContentType.

type CreateDPoPProofRequestObject

type CreateDPoPProofRequestObject struct {
	Kid  string `json:"kid"`
	Body *CreateDPoPProofJSONRequestBody
}

type CreateDPoPProofResponseObject

type CreateDPoPProofResponseObject interface {
	VisitCreateDPoPProofResponse(w http.ResponseWriter) error
}

type DIDDocument

type DIDDocument = did.Document

DIDDocument is an alias

type DIDDocumentMetadata

type DIDDocumentMetadata = resolver.DocumentMetadata

DIDDocumentMetadata is an alias

type DPoPRequest

type DPoPRequest struct {
	// Htm The HTTP method for which the DPoP proof is requested.
	Htm string `json:"htm"`

	// Htu The URL for which the DPoP proof is requested. Query params and fragments are ignored during validation.
	Htu string `json:"htu"`

	// Token The access token for which the DPoP proof is requested.
	Token string `json:"token"`
}

DPoPRequest defines model for DPoPRequest.

type DPoPResponse

type DPoPResponse struct {
	// Dpop The DPoP proof as specified by https://datatracker.ietf.org/doc/html/rfc9449 for resource requests
	Dpop string `json:"dpop"`
}

DPoPResponse defines model for DPoPResponse.

type DPoPValidateRequest

type DPoPValidateRequest struct {
	// DpopProof The DPoP Proof as specified by https://datatracker.ietf.org/doc/html/rfc9449 for resource requests
	DpopProof string `json:"dpop_proof"`

	// Method The HTTP method against which the DPoP proof is validated.
	Method string `json:"method"`

	// Thumbprint The thumbprint of the public key used to sign the DPoP proof. Base64url encoded, no padding.
	Thumbprint string `json:"thumbprint"`

	// Token The access token against which the DPoP proof is validated.
	Token string `json:"token"`

	// Url The URL against which the DPoP proof is validated. Query params and fragments are ignored during validation.
	Url string `json:"url"`
}

DPoPValidateRequest defines model for DPoPValidateRequest.

type DPoPValidateResponse

type DPoPValidateResponse struct {
	// Reason The reason why the DPoP Proof header is invalid.
	Reason *string `json:"reason,omitempty"`

	// Valid True if the DPoP Proof header is valid for the access token and HTTP request, false if it is not.
	Valid bool `json:"valid"`
}

DPoPValidateResponse defines model for DPoPValidateResponse.

type EchoRouter

type EchoRouter interface {
	CONNECT(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	DELETE(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	GET(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	HEAD(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	OPTIONS(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	PATCH(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	POST(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	PUT(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
	TRACE(path string, h echo.HandlerFunc, m ...echo.MiddlewareFunc) *echo.Route
}

This is a simple interface which specifies echo.Route addition functions which are present on both echo.Echo and echo.Group, since we want to allow using either of them for path registration

type ErrorResponse

type ErrorResponse = oauth.OAuth2Error

ErrorResponse is an alias

type ExtendedTokenIntrospectionResponse

type ExtendedTokenIntrospectionResponse struct {
	// Active True if the token is active, false if the token is expired, malformed etc. Required per RFC7662
	Active bool `json:"active"`

	// Aud RFC7662 - Service-specific string identifier or list of string identifiers representing the intended audience for this token, as defined in JWT [RFC7519].
	Aud *string `json:"aud,omitempty"`

	// ClientId The client identity the access token was issued to. Since the Verifiable Presentation is used to grant access, the client_id reflects the client_id in the access token request.
	ClientId *string `json:"client_id,omitempty"`

	// Cnf The 'confirmation' claim is used in JWTs to proof the possession of a key.
	Cnf *Cnf `json:"cnf,omitempty"`

	// Exp Expiration date in seconds since UNIX epoch
	Exp *int `json:"exp,omitempty"`

	// Iat Issuance time in seconds since UNIX epoch
	Iat *int `json:"iat,omitempty"`

	// Iss Issuer URL of the authorizer.
	Iss *string `json:"iss,omitempty"`

	// PresentationDefinitions Presentation Definitions, as described in Presentation Exchange specification, fulfilled to obtain the access token
	// The map key is the wallet owner (user/organization)
	PresentationDefinitions *RequiredPresentationDefinitions `json:"presentation_definitions,omitempty"`

	// PresentationSubmissions Mapping of Presentation Definition IDs that were fulfilled to Presentation Submissions.
	PresentationSubmissions *map[string]PresentationSubmission `json:"presentation_submissions,omitempty"`

	// Scope granted scopes
	Scope                *string                   `json:"scope,omitempty"`
	Vps                  *[]VerifiablePresentation `json:"vps,omitempty"`
	AdditionalProperties map[string]interface{}    `json:"-"`
}

ExtendedTokenIntrospectionResponse defines model for ExtendedTokenIntrospectionResponse.

func (ExtendedTokenIntrospectionResponse) Get

func (a ExtendedTokenIntrospectionResponse) Get(fieldName string) (value interface{}, found bool)

Getter for additional properties for ExtendedTokenIntrospectionResponse. Returns the specified element and whether it was found

func (ExtendedTokenIntrospectionResponse) MarshalJSON

func (a ExtendedTokenIntrospectionResponse) MarshalJSON() ([]byte, error)

Override default JSON handling for ExtendedTokenIntrospectionResponse to handle AdditionalProperties

func (*ExtendedTokenIntrospectionResponse) Set

func (a *ExtendedTokenIntrospectionResponse) Set(fieldName string, value interface{})

Setter for additional properties for ExtendedTokenIntrospectionResponse

func (*ExtendedTokenIntrospectionResponse) UnmarshalJSON

func (a *ExtendedTokenIntrospectionResponse) UnmarshalJSON(b []byte) error

Override default JSON handling for ExtendedTokenIntrospectionResponse to handle AdditionalProperties

type HandleAuthorizeRequest200TexthtmlResponse

type HandleAuthorizeRequest200TexthtmlResponse struct {
	Body          io.Reader
	ContentLength int64
}

func (HandleAuthorizeRequest200TexthtmlResponse) VisitHandleAuthorizeRequestResponse

func (response HandleAuthorizeRequest200TexthtmlResponse) VisitHandleAuthorizeRequestResponse(w http.ResponseWriter) error

type HandleAuthorizeRequest302Response

type HandleAuthorizeRequest302Response struct {
	Headers HandleAuthorizeRequest302ResponseHeaders
}

func (HandleAuthorizeRequest302Response) VisitHandleAuthorizeRequestResponse

func (response HandleAuthorizeRequest302Response) VisitHandleAuthorizeRequestResponse(w http.ResponseWriter) error

type HandleAuthorizeRequest302ResponseHeaders

type HandleAuthorizeRequest302ResponseHeaders struct {
	Location string
}

type HandleAuthorizeRequestParams

type HandleAuthorizeRequestParams struct {
	Params *map[string]string `form:"params,omitempty" json:"params,omitempty"`
}

HandleAuthorizeRequestParams defines parameters for HandleAuthorizeRequest.

type HandleAuthorizeRequestRequestObject

type HandleAuthorizeRequestRequestObject struct {
	SubjectID string `json:"subjectID"`
	Params    HandleAuthorizeRequestParams
}

type HandleAuthorizeRequestResponseObject

type HandleAuthorizeRequestResponseObject interface {
	VisitHandleAuthorizeRequestResponse(w http.ResponseWriter) error
}

type HandleAuthorizeResponse200JSONResponse

type HandleAuthorizeResponse200JSONResponse RedirectResponse

func (HandleAuthorizeResponse200JSONResponse) VisitHandleAuthorizeResponseResponse

func (response HandleAuthorizeResponse200JSONResponse) VisitHandleAuthorizeResponseResponse(w http.ResponseWriter) error

type HandleAuthorizeResponseFormdataBody

type HandleAuthorizeResponseFormdataBody struct {
	// Error error code as defined by the OAuth2 specification
	Error *string `form:"error,omitempty" json:"error,omitempty"`

	// ErrorDescription error description as defined by the OAuth2 specification
	ErrorDescription       *string `form:"error_description,omitempty" json:"error_description,omitempty"`
	PresentationSubmission *string `form:"presentation_submission,omitempty" json:"presentation_submission,omitempty"`

	// State the client state for the verifier
	State *string `form:"state,omitempty" json:"state,omitempty"`

	// VpToken A Verifiable Presentation in either JSON-LD or JWT format.
	VpToken *string `form:"vp_token,omitempty" json:"vp_token,omitempty"`
}

HandleAuthorizeResponseFormdataBody defines parameters for HandleAuthorizeResponse.

type HandleAuthorizeResponseFormdataRequestBody

type HandleAuthorizeResponseFormdataRequestBody HandleAuthorizeResponseFormdataBody

HandleAuthorizeResponseFormdataRequestBody defines body for HandleAuthorizeResponse for application/x-www-form-urlencoded ContentType.

type HandleAuthorizeResponseRequestObject

type HandleAuthorizeResponseRequestObject struct {
	SubjectID string `json:"subjectID"`
	Body      *HandleAuthorizeResponseFormdataRequestBody
}

type HandleAuthorizeResponseResponseObject

type HandleAuthorizeResponseResponseObject interface {
	VisitHandleAuthorizeResponseResponse(w http.ResponseWriter) error
}

type HandleTokenRequest200JSONResponse

type HandleTokenRequest200JSONResponse TokenResponse

func (HandleTokenRequest200JSONResponse) VisitHandleTokenRequestResponse

func (response HandleTokenRequest200JSONResponse) VisitHandleTokenRequestResponse(w http.ResponseWriter) error

type HandleTokenRequestFormdataBody

type HandleTokenRequestFormdataBody struct {
	Assertion              *string `form:"assertion,omitempty" json:"assertion,omitempty"`
	ClientId               *string `form:"client_id,omitempty" json:"client_id,omitempty"`
	Code                   *string `form:"code,omitempty" json:"code,omitempty"`
	CodeVerifier           *string `form:"code_verifier,omitempty" json:"code_verifier,omitempty"`
	GrantType              string  `form:"grant_type" json:"grant_type"`
	PresentationSubmission *string `form:"presentation_submission,omitempty" json:"presentation_submission,omitempty"`
	Scope                  *string `form:"scope,omitempty" json:"scope,omitempty"`
}

HandleTokenRequestFormdataBody defines parameters for HandleTokenRequest.

type HandleTokenRequestFormdataRequestBody

type HandleTokenRequestFormdataRequestBody HandleTokenRequestFormdataBody

HandleTokenRequestFormdataRequestBody defines body for HandleTokenRequest for application/x-www-form-urlencoded ContentType.

type HandleTokenRequestRequestObject

type HandleTokenRequestRequestObject struct {
	SubjectID string `json:"subjectID"`
	Body      *HandleTokenRequestFormdataRequestBody
}

type HandleTokenRequestResponseObject

type HandleTokenRequestResponseObject interface {
	VisitHandleTokenRequestResponse(w http.ResponseWriter) error
}

type HandleTokenRequestdefaultJSONResponse

type HandleTokenRequestdefaultJSONResponse struct {
	Body       ErrorResponse
	StatusCode int
}

func (HandleTokenRequestdefaultJSONResponse) VisitHandleTokenRequestResponse

func (response HandleTokenRequestdefaultJSONResponse) VisitHandleTokenRequestResponse(w http.ResponseWriter) error

type IntrospectAccessToken200JSONResponse

type IntrospectAccessToken200JSONResponse TokenIntrospectionResponse

func (IntrospectAccessToken200JSONResponse) MarshalJSON

func (r IntrospectAccessToken200JSONResponse) MarshalJSON() ([]byte, error)

func (IntrospectAccessToken200JSONResponse) VisitIntrospectAccessTokenResponse

func (response IntrospectAccessToken200JSONResponse) VisitIntrospectAccessTokenResponse(w http.ResponseWriter) error

type IntrospectAccessToken401Response

type IntrospectAccessToken401Response struct {
}

func (IntrospectAccessToken401Response) VisitIntrospectAccessTokenResponse

func (response IntrospectAccessToken401Response) VisitIntrospectAccessTokenResponse(w http.ResponseWriter) error

type IntrospectAccessTokenExtended200JSONResponse

type IntrospectAccessTokenExtended200JSONResponse ExtendedTokenIntrospectionResponse

func (IntrospectAccessTokenExtended200JSONResponse) VisitIntrospectAccessTokenExtendedResponse

func (response IntrospectAccessTokenExtended200JSONResponse) VisitIntrospectAccessTokenExtendedResponse(w http.ResponseWriter) error

type IntrospectAccessTokenExtended401Response

type IntrospectAccessTokenExtended401Response struct {
}

func (IntrospectAccessTokenExtended401Response) VisitIntrospectAccessTokenExtendedResponse

func (response IntrospectAccessTokenExtended401Response) VisitIntrospectAccessTokenExtendedResponse(w http.ResponseWriter) error

type IntrospectAccessTokenExtendedFormdataRequestBody

type IntrospectAccessTokenExtendedFormdataRequestBody = TokenIntrospectionRequest

IntrospectAccessTokenExtendedFormdataRequestBody defines body for IntrospectAccessTokenExtended for application/x-www-form-urlencoded ContentType.

type IntrospectAccessTokenExtendedRequestObject

type IntrospectAccessTokenExtendedRequestObject struct {
	Body *IntrospectAccessTokenExtendedFormdataRequestBody
}

type IntrospectAccessTokenExtendedResponseObject

type IntrospectAccessTokenExtendedResponseObject interface {
	VisitIntrospectAccessTokenExtendedResponse(w http.ResponseWriter) error
}

type IntrospectAccessTokenFormdataRequestBody

type IntrospectAccessTokenFormdataRequestBody = TokenIntrospectionRequest

IntrospectAccessTokenFormdataRequestBody defines body for IntrospectAccessToken for application/x-www-form-urlencoded ContentType.

type IntrospectAccessTokenRequestObject

type IntrospectAccessTokenRequestObject struct {
	Body *IntrospectAccessTokenFormdataRequestBody
}

type IntrospectAccessTokenResponseObject

type IntrospectAccessTokenResponseObject interface {
	VisitIntrospectAccessTokenResponse(w http.ResponseWriter) error
}

type JAR

type JAR interface {
	// Create an unsigned request object.
	// By default, it adds the following parameters:
	//  - client_id
	//  - iss
	//  - aud (if not nil)
	// the request_uri_method is determined by the presence of an audience (get) or not (post)
	Create(client did.DID, clientID string, audience string, modifier requestObjectModifier) jarRequest
	// Sign the jarRequest, which is available on jarRequest.Token.
	// Returns an error if the jarRequest already contains a signed JWT.
	// TODO: check if signature type of client is supported by the AS/wallet.
	Sign(ctx context.Context, claims oauthParameters) (string, error)
	// Parse and validate an incoming authorization request.
	// Requests that do not conform to RFC9101 or OpenID4VP result in an error.
	// The ownMetadata parameter is used when the request contains a request_uri, and it is fetched using HTTP POST;
	// in that case, the metadata is posted to the Authorization Server.
	Parse(ctx context.Context, ownMetadata oauth.AuthorizationServerMetadata, q url.Values) (oauthParameters, error)
}

type MockJAR

type MockJAR struct {
	// contains filtered or unexported fields
}

MockJAR is a mock of JAR interface.

func NewMockJAR

func NewMockJAR(ctrl *gomock.Controller) *MockJAR

NewMockJAR creates a new mock instance.

func (*MockJAR) Create

func (m *MockJAR) Create(client did.DID, clientID, audience string, modifier requestObjectModifier) jarRequest

Create mocks base method.

func (*MockJAR) EXPECT

func (m *MockJAR) EXPECT() *MockJARMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockJAR) Parse

func (m *MockJAR) Parse(ctx context.Context, ownMetadata oauth.AuthorizationServerMetadata, q url.Values) (oauthParameters, error)

Parse mocks base method.

func (*MockJAR) Sign

func (m *MockJAR) Sign(ctx context.Context, claims oauthParameters) (string, error)

Sign mocks base method.

type MockJARMockRecorder

type MockJARMockRecorder struct {
	// contains filtered or unexported fields
}

MockJARMockRecorder is the mock recorder for MockJAR.

func (*MockJARMockRecorder) Create

func (mr *MockJARMockRecorder) Create(client, clientID, audience, modifier any) *gomock.Call

Create indicates an expected call of Create.

func (*MockJARMockRecorder) Parse

func (mr *MockJARMockRecorder) Parse(ctx, ownMetadata, q any) *gomock.Call

Parse indicates an expected call of Parse.

func (*MockJARMockRecorder) Sign

func (mr *MockJARMockRecorder) Sign(ctx, claims any) *gomock.Call

Sign indicates an expected call of Sign.

type OAuthAuthorizationServerMetadata

type OAuthAuthorizationServerMetadata = oauth.AuthorizationServerMetadata

OAuthAuthorizationServerMetadata is an alias

type OAuthAuthorizationServerMetadata200JSONResponse

type OAuthAuthorizationServerMetadata200JSONResponse OAuthAuthorizationServerMetadata

func (OAuthAuthorizationServerMetadata200JSONResponse) VisitOAuthAuthorizationServerMetadataResponse

func (response OAuthAuthorizationServerMetadata200JSONResponse) VisitOAuthAuthorizationServerMetadataResponse(w http.ResponseWriter) error

type OAuthAuthorizationServerMetadataRequestObject

type OAuthAuthorizationServerMetadataRequestObject struct {
	SubjectID string `json:"subjectID"`
}

type OAuthAuthorizationServerMetadataResponseObject

type OAuthAuthorizationServerMetadataResponseObject interface {
	VisitOAuthAuthorizationServerMetadataResponse(w http.ResponseWriter) error
}

type OAuthAuthorizationServerMetadatadefaultApplicationProblemPlusJSONResponse

type OAuthAuthorizationServerMetadatadefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (OAuthAuthorizationServerMetadatadefaultApplicationProblemPlusJSONResponse) VisitOAuthAuthorizationServerMetadataResponse

func (response OAuthAuthorizationServerMetadatadefaultApplicationProblemPlusJSONResponse) VisitOAuthAuthorizationServerMetadataResponse(w http.ResponseWriter) error

type OAuthClientMetadata

type OAuthClientMetadata = oauth.OAuthClientMetadata

OAuthClientMetadata is an alias

type OAuthClientMetadata200JSONResponse

type OAuthClientMetadata200JSONResponse OAuthClientMetadata

func (OAuthClientMetadata200JSONResponse) VisitOAuthClientMetadataResponse

func (response OAuthClientMetadata200JSONResponse) VisitOAuthClientMetadataResponse(w http.ResponseWriter) error

type OAuthClientMetadataRequestObject

type OAuthClientMetadataRequestObject struct {
	SubjectID string `json:"subjectID"`
}

type OAuthClientMetadataResponseObject

type OAuthClientMetadataResponseObject interface {
	VisitOAuthClientMetadataResponse(w http.ResponseWriter) error
}

type OAuthClientMetadatadefaultApplicationProblemPlusJSONResponse

type OAuthClientMetadatadefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (OAuthClientMetadatadefaultApplicationProblemPlusJSONResponse) VisitOAuthClientMetadataResponse

func (response OAuthClientMetadatadefaultApplicationProblemPlusJSONResponse) VisitOAuthClientMetadataResponse(w http.ResponseWriter) error

type OAuthSession

type OAuthSession struct {
	AuthorizationServerMetadata *oauth.AuthorizationServerMetadata `json:"authorization_server_metadata,omitempty"`
	ClientFlow                  oauthClientFlow                    `json:"client_flow,omitempty"`
	ClientID                    string                             `json:"client_id,omitempty"`
	ClientState                 string                             `json:"client_state,omitempty"`
	OpenID4VPVerifier           *PEXConsumer                       `json:"openid4vp_verifier,omitempty"`
	OwnSubject                  *string                            `json:"own_subject,omitempty"`
	// OwnDID is the DID of the entity that owns this session, which must be a DID of the subject (OwnSubject).
	// It is used in OpenID4VCI to select the target wallet.
	OwnDID        *did.DID   `json:"own_did,omitempty"`
	OtherDID      *did.DID   `json:"other_did,omitempty"`
	PKCEParams    PKCEParams `json:"pkce_params"`
	RedirectURI   string     `json:"redirect_uri,omitempty"`
	Scope         string     `json:"scope,omitempty"`
	SessionID     string     `json:"session_id,omitempty"`
	TokenEndpoint string     `json:"token_endpoint,omitempty"`
	// IssuerURL is the URL that identifies the OAuth2 Authorization Server according to RFC 8414 (Authorization Server Metadata).
	IssuerURL string `json:"issuer_url,omitempty"`
	UseDPoP   bool   `json:"use_dpop,omitempty"`
	// IssuerCredentialEndpoint: endpoint to exchange the access_token for a credential in the OpenID4VCI flow
	IssuerCredentialEndpoint string `json:"issuer_credential_endpoint,omitempty"`
}

OAuthSession is the session object that is used to store information about the OAuth request. The client state (and nonce/redirectToken as well) is used to refer to this session. Both the client and the server use this session to store information about the request.

func (OAuthSession) CreateRedirectURI

func (s OAuthSession) CreateRedirectURI(params map[string]string) string

type OpenIDConfiguration

type OpenIDConfiguration = map[string]interface{}

OpenIDConfiguration OpenID entity configuration Contain properties from several specifications and may grow over time

type OpenIDConfiguration200ApplicationentityStatementJwtResponse

type OpenIDConfiguration200ApplicationentityStatementJwtResponse struct {
	Body          io.Reader
	ContentLength int64
}

func (OpenIDConfiguration200ApplicationentityStatementJwtResponse) VisitOpenIDConfigurationResponse

func (response OpenIDConfiguration200ApplicationentityStatementJwtResponse) VisitOpenIDConfigurationResponse(w http.ResponseWriter) error

type OpenIDConfigurationRequestObject

type OpenIDConfigurationRequestObject struct {
	SubjectID string `json:"subjectID"`
}

type OpenIDConfigurationResponseObject

type OpenIDConfigurationResponseObject interface {
	VisitOpenIDConfigurationResponse(w http.ResponseWriter) error
}

type OpenIDConfigurationdefaultJSONResponse

type OpenIDConfigurationdefaultJSONResponse struct {
	Body       ErrorResponse
	StatusCode int
}

func (OpenIDConfigurationdefaultJSONResponse) VisitOpenIDConfigurationResponse

func (response OpenIDConfigurationdefaultJSONResponse) VisitOpenIDConfigurationResponse(w http.ResponseWriter) error

type PEXConsumer

type PEXConsumer struct {
	RequiredPresentationDefinitions pe.WalletOwnerMapping `json:"required_presentations"`
	// Submissions tracks which Submissions have been submitted through OpenID4VP
	Submissions map[string]pe.PresentationSubmission `json:"submissions"`
	// SubmittedEnvelopes tracks the Presentation Exchange Envelopes that were submitted.
	// They correspond to the submissions.
	SubmittedEnvelopes map[string]pe.Envelope `json:"submitted_envelopes"`
}

PEXConsumer consumes Presentation Submissions, according to https://identity.foundation/presentation-exchange/ This is a component of a OpenID4VP Verifier. It can track multiple required Presentation Definitions.

type PKCEParams

type PKCEParams struct {
	Challenge       string
	ChallengeMethod string
	Verifier        string
}

PKCEParams contains the PKCE parameters so they can be stored in both the client and server side session.

type PresentationDefinition

type PresentationDefinition = pe.PresentationDefinition

PresentationDefinition is an alias

type PresentationDefinition200JSONResponse

type PresentationDefinition200JSONResponse PresentationDefinition

func (PresentationDefinition200JSONResponse) VisitPresentationDefinitionResponse

func (response PresentationDefinition200JSONResponse) VisitPresentationDefinitionResponse(w http.ResponseWriter) error

type PresentationDefinitionParams

type PresentationDefinitionParams struct {
	Scope           string           `form:"scope" json:"scope"`
	WalletOwnerType *WalletOwnerType `form:"wallet_owner_type,omitempty" json:"wallet_owner_type,omitempty"`
}

PresentationDefinitionParams defines parameters for PresentationDefinition.

type PresentationDefinitionRequestObject

type PresentationDefinitionRequestObject struct {
	SubjectID string `json:"subjectID"`
	Params    PresentationDefinitionParams
}

type PresentationDefinitionResponseObject

type PresentationDefinitionResponseObject interface {
	VisitPresentationDefinitionResponse(w http.ResponseWriter) error
}

type PresentationDefinitiondefaultJSONResponse

type PresentationDefinitiondefaultJSONResponse struct {
	Body       ErrorResponse
	StatusCode int
}

func (PresentationDefinitiondefaultJSONResponse) VisitPresentationDefinitionResponse

func (response PresentationDefinitiondefaultJSONResponse) VisitPresentationDefinitionResponse(w http.ResponseWriter) error

type PresentationSubmission

type PresentationSubmission = pe.PresentationSubmission

PresentationSubmission is an alias

type RedirectResponse

type RedirectResponse = oauth.Redirect

type RedirectResponseWithID

type RedirectResponseWithID struct {
	// RedirectUri The URL to which the user-agent will be redirected after the authorization request.
	RedirectUri string `json:"redirect_uri"`

	// SessionId The session ID that can be used to retrieve the access token by the calling application.
	SessionId string `json:"session_id"`
}

RedirectResponseWithID defines model for RedirectResponseWithID.

type RedirectSession

type RedirectSession struct {
	AccessTokenRequest RequestUserAccessTokenRequestObject
	// SessionID is used by the calling app to get the access token later on
	SessionID string
	SubjectID string
}

RedirectSession is the session object that is used to redirect the user to a Nuts node website. It stores information from the internal API call that started the request access token. The key to this session is passed to the user via a 302 redirect.

type RequestJWTByGet200ApplicationoauthAuthzReqJwtResponse

type RequestJWTByGet200ApplicationoauthAuthzReqJwtResponse struct {
	Body          io.Reader
	ContentLength int64
}

func (RequestJWTByGet200ApplicationoauthAuthzReqJwtResponse) VisitRequestJWTByGetResponse

func (response RequestJWTByGet200ApplicationoauthAuthzReqJwtResponse) VisitRequestJWTByGetResponse(w http.ResponseWriter) error

type RequestJWTByGetRequestObject

type RequestJWTByGetRequestObject struct {
	SubjectID string `json:"subjectID"`
	Id        string `json:"id"`
}

type RequestJWTByGetResponseObject

type RequestJWTByGetResponseObject interface {
	VisitRequestJWTByGetResponse(w http.ResponseWriter) error
}

type RequestJWTByGetdefaultApplicationProblemPlusJSONResponse

type RequestJWTByGetdefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RequestJWTByGetdefaultApplicationProblemPlusJSONResponse) VisitRequestJWTByGetResponse

func (response RequestJWTByGetdefaultApplicationProblemPlusJSONResponse) VisitRequestJWTByGetResponse(w http.ResponseWriter) error

type RequestJWTByPost200ApplicationoauthAuthzReqJwtResponse

type RequestJWTByPost200ApplicationoauthAuthzReqJwtResponse struct {
	Body          io.Reader
	ContentLength int64
}

func (RequestJWTByPost200ApplicationoauthAuthzReqJwtResponse) VisitRequestJWTByPostResponse

func (response RequestJWTByPost200ApplicationoauthAuthzReqJwtResponse) VisitRequestJWTByPostResponse(w http.ResponseWriter) error

type RequestJWTByPostFormdataBody

type RequestJWTByPostFormdataBody struct {
	// WalletMetadata OAuth2 Authorization Server Metadata
	// Contain properties from several specifications and may grow over time
	WalletMetadata *OAuthAuthorizationServerMetadata `form:"wallet_metadata,omitempty" json:"wallet_metadata,omitempty"`

	// WalletNonce A String value used to mitigate replay attacks of the Authorization Request.
	// When received, the Verifier MUST use it as the wallet_nonce value in the signed authorization request object.
	WalletNonce *string `form:"wallet_nonce,omitempty" json:"wallet_nonce,omitempty"`
}

RequestJWTByPostFormdataBody defines parameters for RequestJWTByPost.

type RequestJWTByPostFormdataRequestBody

type RequestJWTByPostFormdataRequestBody RequestJWTByPostFormdataBody

RequestJWTByPostFormdataRequestBody defines body for RequestJWTByPost for application/x-www-form-urlencoded ContentType.

type RequestJWTByPostRequestObject

type RequestJWTByPostRequestObject struct {
	SubjectID string `json:"subjectID"`
	Id        string `json:"id"`
	Body      *RequestJWTByPostFormdataRequestBody
}

type RequestJWTByPostResponseObject

type RequestJWTByPostResponseObject interface {
	VisitRequestJWTByPostResponse(w http.ResponseWriter) error
}

type RequestJWTByPostdefaultApplicationProblemPlusJSONResponse

type RequestJWTByPostdefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RequestJWTByPostdefaultApplicationProblemPlusJSONResponse) VisitRequestJWTByPostResponse

func (response RequestJWTByPostdefaultApplicationProblemPlusJSONResponse) VisitRequestJWTByPostResponse(w http.ResponseWriter) error

type RequestObjectResponse

type RequestObjectResponse = string

RequestObjectResponse A JSON Web Token (JWT) whose JWT Claims Set holds the JSON-encoded OAuth 2.0 authorization request parameters.

type RequestOpenid4VCICredentialIssuance200JSONResponse

type RequestOpenid4VCICredentialIssuance200JSONResponse RedirectResponse

func (RequestOpenid4VCICredentialIssuance200JSONResponse) VisitRequestOpenid4VCICredentialIssuanceResponse

func (response RequestOpenid4VCICredentialIssuance200JSONResponse) VisitRequestOpenid4VCICredentialIssuanceResponse(w http.ResponseWriter) error

type RequestOpenid4VCICredentialIssuanceJSONBody

type RequestOpenid4VCICredentialIssuanceJSONBody struct {
	AuthorizationDetails []map[string]interface{} `json:"authorization_details"`

	// Issuer The OAuth Authorization Server's identifier, that issues the Verifiable Credentials, as specified in RFC 8414 (section 2),
	// used to locate the OAuth2 Authorization Server metadata.
	Issuer string `json:"issuer"`

	// RedirectUri The URL to which the user-agent will be redirected after the authorization request.
	RedirectUri string `json:"redirect_uri"`

	// WalletDid The DID to which the Verifiable Credential must be issued. Must be owned by the given subject.
	WalletDid string `json:"wallet_did"`
}

RequestOpenid4VCICredentialIssuanceJSONBody defines parameters for RequestOpenid4VCICredentialIssuance.

type RequestOpenid4VCICredentialIssuanceJSONRequestBody

type RequestOpenid4VCICredentialIssuanceJSONRequestBody RequestOpenid4VCICredentialIssuanceJSONBody

RequestOpenid4VCICredentialIssuanceJSONRequestBody defines body for RequestOpenid4VCICredentialIssuance for application/json ContentType.

type RequestOpenid4VCICredentialIssuanceRequestObject

type RequestOpenid4VCICredentialIssuanceRequestObject struct {
	SubjectID string `json:"subjectID"`
	Body      *RequestOpenid4VCICredentialIssuanceJSONRequestBody
}

type RequestOpenid4VCICredentialIssuanceResponseObject

type RequestOpenid4VCICredentialIssuanceResponseObject interface {
	VisitRequestOpenid4VCICredentialIssuanceResponse(w http.ResponseWriter) error
}

type RequestOpenid4VCICredentialIssuancedefaultApplicationProblemPlusJSONResponse

type RequestOpenid4VCICredentialIssuancedefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RequestOpenid4VCICredentialIssuancedefaultApplicationProblemPlusJSONResponse) VisitRequestOpenid4VCICredentialIssuanceResponse

func (response RequestOpenid4VCICredentialIssuancedefaultApplicationProblemPlusJSONResponse) VisitRequestOpenid4VCICredentialIssuanceResponse(w http.ResponseWriter) error

type RequestServiceAccessToken200JSONResponse

type RequestServiceAccessToken200JSONResponse TokenResponse

func (RequestServiceAccessToken200JSONResponse) VisitRequestServiceAccessTokenResponse

func (response RequestServiceAccessToken200JSONResponse) VisitRequestServiceAccessTokenResponse(w http.ResponseWriter) error

type RequestServiceAccessTokenJSONRequestBody

type RequestServiceAccessTokenJSONRequestBody = ServiceAccessTokenRequest

RequestServiceAccessTokenJSONRequestBody defines body for RequestServiceAccessToken for application/json ContentType.

type RequestServiceAccessTokenParams

type RequestServiceAccessTokenParams struct {
	// CacheControl Access tokens are cached by the Nuts node, specify Cache-Control: no-cache to bypass the cache.
	// This forces the Nuts node to request a new access token from the authorizer.
	//
	// A valid use case for this is when the Resource Server rejects the access token with 401 Unauthorized.
	// It could be that the Authorization Server lost the access token due to a server restart,
	// in combination with (non-recommended) usage of in-memory session storage.
	// The local Nuts node then still considers the token valid, while the Authorization Server does not.
	//
	// Note that this should not be used under normal circumstances, as it will increase round trip time and load on both the requester and authorizer.
	CacheControl *string `json:"Cache-Control,omitempty"`
}

RequestServiceAccessTokenParams defines parameters for RequestServiceAccessToken.

type RequestServiceAccessTokenRequestObject

type RequestServiceAccessTokenRequestObject struct {
	SubjectID string `json:"subjectID"`
	Params    RequestServiceAccessTokenParams
	Body      *RequestServiceAccessTokenJSONRequestBody
}

type RequestServiceAccessTokenResponseObject

type RequestServiceAccessTokenResponseObject interface {
	VisitRequestServiceAccessTokenResponse(w http.ResponseWriter) error
}

type RequestServiceAccessTokendefaultApplicationProblemPlusJSONResponse

type RequestServiceAccessTokendefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RequestServiceAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRequestServiceAccessTokenResponse

func (response RequestServiceAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRequestServiceAccessTokenResponse(w http.ResponseWriter) error

type RequestUserAccessToken200JSONResponse

type RequestUserAccessToken200JSONResponse RedirectResponseWithID

func (RequestUserAccessToken200JSONResponse) VisitRequestUserAccessTokenResponse

func (response RequestUserAccessToken200JSONResponse) VisitRequestUserAccessTokenResponse(w http.ResponseWriter) error

type RequestUserAccessTokenJSONRequestBody

type RequestUserAccessTokenJSONRequestBody = UserAccessTokenRequest

RequestUserAccessTokenJSONRequestBody defines body for RequestUserAccessToken for application/json ContentType.

type RequestUserAccessTokenRequestObject

type RequestUserAccessTokenRequestObject struct {
	SubjectID string `json:"subjectID"`
	Body      *RequestUserAccessTokenJSONRequestBody
}

type RequestUserAccessTokenResponseObject

type RequestUserAccessTokenResponseObject interface {
	VisitRequestUserAccessTokenResponse(w http.ResponseWriter) error
}

type RequestUserAccessTokendefaultApplicationProblemPlusJSONResponse

type RequestUserAccessTokendefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RequestUserAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRequestUserAccessTokenResponse

func (response RequestUserAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRequestUserAccessTokenResponse(w http.ResponseWriter) error

type RequiredPresentationDefinitions

type RequiredPresentationDefinitions = pe.WalletOwnerMapping

RequiredPresentationDefinitions is an alias

type RetrieveAccessToken200JSONResponse

type RetrieveAccessToken200JSONResponse TokenResponse

func (RetrieveAccessToken200JSONResponse) VisitRetrieveAccessTokenResponse

func (response RetrieveAccessToken200JSONResponse) VisitRetrieveAccessTokenResponse(w http.ResponseWriter) error

type RetrieveAccessTokenRequestObject

type RetrieveAccessTokenRequestObject struct {
	SessionID string `json:"sessionID"`
}

type RetrieveAccessTokenResponseObject

type RetrieveAccessTokenResponseObject interface {
	VisitRetrieveAccessTokenResponse(w http.ResponseWriter) error
}

type RetrieveAccessTokendefaultApplicationProblemPlusJSONResponse

type RetrieveAccessTokendefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (RetrieveAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRetrieveAccessTokenResponse

func (response RetrieveAccessTokendefaultApplicationProblemPlusJSONResponse) VisitRetrieveAccessTokenResponse(w http.ResponseWriter) error

type ServerInterface

type ServerInterface interface {
	// Get the OAuth2 Authorization Server metadata for the specified subject.
	// (GET /.well-known/oauth-authorization-server/oauth2/{subjectID})
	OAuthAuthorizationServerMetadata(ctx echo.Context, subjectID string) error
	// Get the OpenID entity configuration for the specified subject. Required for OpenID4VP.
	// (GET /.well-known/openid-configuration/oauth2/{subjectID})
	OpenIDConfiguration(ctx echo.Context, subjectID string) error
	// Introspection endpoint to retrieve information from an Access Token as described by RFC7662.
	// It returns fields derived from the credentials that were used during authentication.
	// (POST /internal/auth/v2/accesstoken/introspect)
	IntrospectAccessToken(ctx echo.Context) error
	// Introspection endpoint to retrieve information from an Access Token as described by RFC7662.
	// It returns the same information as the non-extended API call, but with the Presentation Definitions,
	// Presentation Submissions and Verifiable Presentations added.
	// (POST /internal/auth/v2/accesstoken/introspect_extended)
	IntrospectAccessTokenExtended(ctx echo.Context) error
	// Get the access token from the Nuts node that was requested through /request-user-access-token.
	// (GET /internal/auth/v2/accesstoken/{sessionID})
	RetrieveAccessToken(ctx echo.Context, sessionID string) error
	// Handle some of the validation of a DPoP proof as specified by RFC9449.
	// (POST /internal/auth/v2/dpop/validate)
	ValidateDPoPProof(ctx echo.Context) error
	// Create a DPoP proof as specified by RFC9449 for a given access token. It is to be used as HTTP header when accessing resources.
	// (POST /internal/auth/v2/dpop/{kid})
	CreateDPoPProof(ctx echo.Context, kid string) error
	// EXPERIMENTAL Start the Oid4VCI authorization flow.
	// (POST /internal/auth/v2/{subjectID}/request-credential)
	RequestOpenid4VCICredentialIssuance(ctx echo.Context, subjectID string) error
	// Start the authorization flow to get an access token from a remote authorization server.
	// (POST /internal/auth/v2/{subjectID}/request-service-access-token)
	RequestServiceAccessToken(ctx echo.Context, subjectID string, params RequestServiceAccessTokenParams) error
	// EXPERIMENTAL Start the authorization code flow to get an access token from a remote authorization server when user context is required.
	// (POST /internal/auth/v2/{subjectID}/request-user-access-token)
	RequestUserAccessToken(ctx echo.Context, subjectID string) error
	// Used by resource owners (the browser) to initiate the authorization code flow.
	// (GET /oauth2/{subjectID}/authorize)
	HandleAuthorizeRequest(ctx echo.Context, subjectID string, params HandleAuthorizeRequestParams) error
	// The OAuth2 callback endpoint of the client.
	// (GET /oauth2/{subjectID}/callback)
	Callback(ctx echo.Context, subjectID string, params CallbackParams) error
	// Get the OAuth2 Client metadata
	// (GET /oauth2/{subjectID}/oauth-client)
	OAuthClientMetadata(ctx echo.Context, subjectID string) error
	// Used by relying parties to obtain a presentation definition for desired scopes as specified by Nuts RFC021.
	// (GET /oauth2/{subjectID}/presentation_definition)
	PresentationDefinition(ctx echo.Context, subjectID string, params PresentationDefinitionParams) error
	// Get Request Object referenced in an authorization request to the Authorization Server.
	// (GET /oauth2/{subjectID}/request.jwt/{id})
	RequestJWTByGet(ctx echo.Context, subjectID string, id string) error
	// Provide missing information to Client to finish Authorization request's Request Object, which is then returned.
	// (POST /oauth2/{subjectID}/request.jwt/{id})
	RequestJWTByPost(ctx echo.Context, subjectID string, id string) error
	// Used by wallets to post the authorization response or error to.
	// (POST /oauth2/{subjectID}/response)
	HandleAuthorizeResponse(ctx echo.Context, subjectID string) error
	// Used by the OAuth2 client (backend, not the browser) to request access- or refresh tokens.
	// (POST /oauth2/{subjectID}/token)
	HandleTokenRequest(ctx echo.Context, subjectID string) error
	// Get the StatusList2021Credential for the given DID and page
	// (GET /statuslist/{did}/{page})
	StatusList(ctx echo.Context, did string, page int) error
}

ServerInterface represents all server handlers.

func NewStrictHandler

func NewStrictHandler(ssi StrictServerInterface, middlewares []StrictMiddlewareFunc) ServerInterface

type ServerInterfaceWrapper

type ServerInterfaceWrapper struct {
	Handler ServerInterface
}

ServerInterfaceWrapper converts echo contexts to parameters.

func (*ServerInterfaceWrapper) Callback

func (w *ServerInterfaceWrapper) Callback(ctx echo.Context) error

Callback converts echo context to params.

func (*ServerInterfaceWrapper) CreateDPoPProof

func (w *ServerInterfaceWrapper) CreateDPoPProof(ctx echo.Context) error

CreateDPoPProof converts echo context to params.

func (*ServerInterfaceWrapper) HandleAuthorizeRequest

func (w *ServerInterfaceWrapper) HandleAuthorizeRequest(ctx echo.Context) error

HandleAuthorizeRequest converts echo context to params.

func (*ServerInterfaceWrapper) HandleAuthorizeResponse

func (w *ServerInterfaceWrapper) HandleAuthorizeResponse(ctx echo.Context) error

HandleAuthorizeResponse converts echo context to params.

func (*ServerInterfaceWrapper) HandleTokenRequest

func (w *ServerInterfaceWrapper) HandleTokenRequest(ctx echo.Context) error

HandleTokenRequest converts echo context to params.

func (*ServerInterfaceWrapper) IntrospectAccessToken

func (w *ServerInterfaceWrapper) IntrospectAccessToken(ctx echo.Context) error

IntrospectAccessToken converts echo context to params.

func (*ServerInterfaceWrapper) IntrospectAccessTokenExtended

func (w *ServerInterfaceWrapper) IntrospectAccessTokenExtended(ctx echo.Context) error

IntrospectAccessTokenExtended converts echo context to params.

func (*ServerInterfaceWrapper) OAuthAuthorizationServerMetadata

func (w *ServerInterfaceWrapper) OAuthAuthorizationServerMetadata(ctx echo.Context) error

OAuthAuthorizationServerMetadata converts echo context to params.

func (*ServerInterfaceWrapper) OAuthClientMetadata

func (w *ServerInterfaceWrapper) OAuthClientMetadata(ctx echo.Context) error

OAuthClientMetadata converts echo context to params.

func (*ServerInterfaceWrapper) OpenIDConfiguration

func (w *ServerInterfaceWrapper) OpenIDConfiguration(ctx echo.Context) error

OpenIDConfiguration converts echo context to params.

func (*ServerInterfaceWrapper) PresentationDefinition

func (w *ServerInterfaceWrapper) PresentationDefinition(ctx echo.Context) error

PresentationDefinition converts echo context to params.

func (*ServerInterfaceWrapper) RequestJWTByGet

func (w *ServerInterfaceWrapper) RequestJWTByGet(ctx echo.Context) error

RequestJWTByGet converts echo context to params.

func (*ServerInterfaceWrapper) RequestJWTByPost

func (w *ServerInterfaceWrapper) RequestJWTByPost(ctx echo.Context) error

RequestJWTByPost converts echo context to params.

func (*ServerInterfaceWrapper) RequestOpenid4VCICredentialIssuance

func (w *ServerInterfaceWrapper) RequestOpenid4VCICredentialIssuance(ctx echo.Context) error

RequestOpenid4VCICredentialIssuance converts echo context to params.

func (*ServerInterfaceWrapper) RequestServiceAccessToken

func (w *ServerInterfaceWrapper) RequestServiceAccessToken(ctx echo.Context) error

RequestServiceAccessToken converts echo context to params.

func (*ServerInterfaceWrapper) RequestUserAccessToken

func (w *ServerInterfaceWrapper) RequestUserAccessToken(ctx echo.Context) error

RequestUserAccessToken converts echo context to params.

func (*ServerInterfaceWrapper) RetrieveAccessToken

func (w *ServerInterfaceWrapper) RetrieveAccessToken(ctx echo.Context) error

RetrieveAccessToken converts echo context to params.

func (*ServerInterfaceWrapper) StatusList

func (w *ServerInterfaceWrapper) StatusList(ctx echo.Context) error

StatusList converts echo context to params.

func (*ServerInterfaceWrapper) ValidateDPoPProof

func (w *ServerInterfaceWrapper) ValidateDPoPProof(ctx echo.Context) error

ValidateDPoPProof converts echo context to params.

type ServerState

type ServerState struct {
	CredentialMap          map[string]vc.VerifiableCredential
	Presentations          []vc.VerifiablePresentation
	PresentationSubmission *pe.PresentationSubmission
}

ServerState is a convenience type for extracting different types of data from the session.

type ServiceAccessTokenRequest

type ServiceAccessTokenRequest struct {
	// AuthorizationServer The OAuth Authorization Server's identifier as specified in RFC 8414 (section 2),
	// used to locate the OAuth2 Authorization Server metadata.
	AuthorizationServer string `json:"authorization_server"`

	// Credentials Additional credentials to present (if required by the authorizer), in addition to those in the requester's wallet.
	// They must be in the form of a Verifiable Credential in JSON form.
	// The serialized form (JWT or JSON-LD) in the resulting Verifiable Presentation depends on the capability of the authorizing party.
	// A typical use case is to provide a self-attested credential to convey information about the user that initiated the request.
	//
	// The following credential fields are automatically filled (when not present), and may be omitted:
	// - issuer, credentialSubject.id (MUST be omitted; filled with the DID of the requester)
	// - issuanceDate (filled with the current date/time)
	// - id (filled with a UUID)
	// - proof/signature (MUST be omitted; integrity protection is covered by the VP's proof/signature)
	Credentials *[]VerifiableCredential `json:"credentials,omitempty"`

	// Scope The scope that will be the service for which this access token can be used.
	Scope string `json:"scope"`

	// TokenType The type of access token that is preferred, default: DPoP
	TokenType *ServiceAccessTokenRequestTokenType `json:"token_type,omitempty"`
}

ServiceAccessTokenRequest Request for an access token for a service.

type ServiceAccessTokenRequestTokenType

type ServiceAccessTokenRequestTokenType string

ServiceAccessTokenRequestTokenType The type of access token that is preferred, default: DPoP

const (
	ServiceAccessTokenRequestTokenTypeBearer ServiceAccessTokenRequestTokenType = "Bearer"
	ServiceAccessTokenRequestTokenTypeDPoP   ServiceAccessTokenRequestTokenType = "DPoP"
)

Defines values for ServiceAccessTokenRequestTokenType.

type StatusList200JSONResponse

type StatusList200JSONResponse VerifiableCredential

func (StatusList200JSONResponse) VisitStatusListResponse

func (response StatusList200JSONResponse) VisitStatusListResponse(w http.ResponseWriter) error

type StatusListRequestObject

type StatusListRequestObject struct {
	Did  string `json:"did"`
	Page int    `json:"page"`
}

type StatusListResponseObject

type StatusListResponseObject interface {
	VisitStatusListResponse(w http.ResponseWriter) error
}

type StatusListdefaultApplicationProblemPlusJSONResponse

type StatusListdefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (StatusListdefaultApplicationProblemPlusJSONResponse) VisitStatusListResponse

type StrictHandlerFunc

type StrictHandlerFunc = strictecho.StrictEchoHandlerFunc

type StrictMiddlewareFunc

type StrictMiddlewareFunc = strictecho.StrictEchoMiddlewareFunc

type StrictServerInterface

type StrictServerInterface interface {
	// Get the OAuth2 Authorization Server metadata for the specified subject.
	// (GET /.well-known/oauth-authorization-server/oauth2/{subjectID})
	OAuthAuthorizationServerMetadata(ctx context.Context, request OAuthAuthorizationServerMetadataRequestObject) (OAuthAuthorizationServerMetadataResponseObject, error)
	// Get the OpenID entity configuration for the specified subject. Required for OpenID4VP.
	// (GET /.well-known/openid-configuration/oauth2/{subjectID})
	OpenIDConfiguration(ctx context.Context, request OpenIDConfigurationRequestObject) (OpenIDConfigurationResponseObject, error)
	// Introspection endpoint to retrieve information from an Access Token as described by RFC7662.
	// It returns fields derived from the credentials that were used during authentication.
	// (POST /internal/auth/v2/accesstoken/introspect)
	IntrospectAccessToken(ctx context.Context, request IntrospectAccessTokenRequestObject) (IntrospectAccessTokenResponseObject, error)
	// Introspection endpoint to retrieve information from an Access Token as described by RFC7662.
	// It returns the same information as the non-extended API call, but with the Presentation Definitions,
	// Presentation Submissions and Verifiable Presentations added.
	// (POST /internal/auth/v2/accesstoken/introspect_extended)
	IntrospectAccessTokenExtended(ctx context.Context, request IntrospectAccessTokenExtendedRequestObject) (IntrospectAccessTokenExtendedResponseObject, error)
	// Get the access token from the Nuts node that was requested through /request-user-access-token.
	// (GET /internal/auth/v2/accesstoken/{sessionID})
	RetrieveAccessToken(ctx context.Context, request RetrieveAccessTokenRequestObject) (RetrieveAccessTokenResponseObject, error)
	// Handle some of the validation of a DPoP proof as specified by RFC9449.
	// (POST /internal/auth/v2/dpop/validate)
	ValidateDPoPProof(ctx context.Context, request ValidateDPoPProofRequestObject) (ValidateDPoPProofResponseObject, error)
	// Create a DPoP proof as specified by RFC9449 for a given access token. It is to be used as HTTP header when accessing resources.
	// (POST /internal/auth/v2/dpop/{kid})
	CreateDPoPProof(ctx context.Context, request CreateDPoPProofRequestObject) (CreateDPoPProofResponseObject, error)
	// EXPERIMENTAL Start the Oid4VCI authorization flow.
	// (POST /internal/auth/v2/{subjectID}/request-credential)
	RequestOpenid4VCICredentialIssuance(ctx context.Context, request RequestOpenid4VCICredentialIssuanceRequestObject) (RequestOpenid4VCICredentialIssuanceResponseObject, error)
	// Start the authorization flow to get an access token from a remote authorization server.
	// (POST /internal/auth/v2/{subjectID}/request-service-access-token)
	RequestServiceAccessToken(ctx context.Context, request RequestServiceAccessTokenRequestObject) (RequestServiceAccessTokenResponseObject, error)
	// EXPERIMENTAL Start the authorization code flow to get an access token from a remote authorization server when user context is required.
	// (POST /internal/auth/v2/{subjectID}/request-user-access-token)
	RequestUserAccessToken(ctx context.Context, request RequestUserAccessTokenRequestObject) (RequestUserAccessTokenResponseObject, error)
	// Used by resource owners (the browser) to initiate the authorization code flow.
	// (GET /oauth2/{subjectID}/authorize)
	HandleAuthorizeRequest(ctx context.Context, request HandleAuthorizeRequestRequestObject) (HandleAuthorizeRequestResponseObject, error)
	// The OAuth2 callback endpoint of the client.
	// (GET /oauth2/{subjectID}/callback)
	Callback(ctx context.Context, request CallbackRequestObject) (CallbackResponseObject, error)
	// Get the OAuth2 Client metadata
	// (GET /oauth2/{subjectID}/oauth-client)
	OAuthClientMetadata(ctx context.Context, request OAuthClientMetadataRequestObject) (OAuthClientMetadataResponseObject, error)
	// Used by relying parties to obtain a presentation definition for desired scopes as specified by Nuts RFC021.
	// (GET /oauth2/{subjectID}/presentation_definition)
	PresentationDefinition(ctx context.Context, request PresentationDefinitionRequestObject) (PresentationDefinitionResponseObject, error)
	// Get Request Object referenced in an authorization request to the Authorization Server.
	// (GET /oauth2/{subjectID}/request.jwt/{id})
	RequestJWTByGet(ctx context.Context, request RequestJWTByGetRequestObject) (RequestJWTByGetResponseObject, error)
	// Provide missing information to Client to finish Authorization request's Request Object, which is then returned.
	// (POST /oauth2/{subjectID}/request.jwt/{id})
	RequestJWTByPost(ctx context.Context, request RequestJWTByPostRequestObject) (RequestJWTByPostResponseObject, error)
	// Used by wallets to post the authorization response or error to.
	// (POST /oauth2/{subjectID}/response)
	HandleAuthorizeResponse(ctx context.Context, request HandleAuthorizeResponseRequestObject) (HandleAuthorizeResponseResponseObject, error)
	// Used by the OAuth2 client (backend, not the browser) to request access- or refresh tokens.
	// (POST /oauth2/{subjectID}/token)
	HandleTokenRequest(ctx context.Context, request HandleTokenRequestRequestObject) (HandleTokenRequestResponseObject, error)
	// Get the StatusList2021Credential for the given DID and page
	// (GET /statuslist/{did}/{page})
	StatusList(ctx context.Context, request StatusListRequestObject) (StatusListResponseObject, error)
}

StrictServerInterface represents all server handlers.

type TokenIntrospectionRequest

type TokenIntrospectionRequest struct {
	Token string `json:"token"`
}

TokenIntrospectionRequest Token introspection request as described in RFC7662 section 2.1 Alongside the defined properties, it can return values (additionalProperties) from the Verifiable Credentials that resulted from the Presentation Exchange.

type TokenIntrospectionResponse

type TokenIntrospectionResponse = ExtendedTokenIntrospectionResponse

type TokenResponse

type TokenResponse = oauth.TokenResponse

TokenResponse is an alias

type UserAccessTokenRequest

type UserAccessTokenRequest struct {
	// AuthorizationServer The OAuth Authorization Server's identifier as specified in RFC 8414 (section 2),
	// used to locate the OAuth2 Authorization Server metadata.
	AuthorizationServer string `json:"authorization_server"`

	// PreauthorizedUser Claims about the authorized user.
	PreauthorizedUser *UserDetails `json:"preauthorized_user,omitempty"`

	// RedirectUri The URL to which the user-agent will be redirected after the authorization request.
	// This is the URL of the calling application.
	// The OAuth2 flow will finish at the /callback URL of the node and the node will redirect the user to this redirect_uri.
	RedirectUri string `json:"redirect_uri"`

	// Scope The scope that will be the service for which this access token can be used.
	Scope string `json:"scope"`

	// TokenType The type of access token that is prefered. Supported values: [Bearer, DPoP], default: DPoP
	TokenType *UserAccessTokenRequestTokenType `json:"token_type,omitempty"`
}

UserAccessTokenRequest Request for an access token for a user.

type UserAccessTokenRequestTokenType

type UserAccessTokenRequestTokenType string

UserAccessTokenRequestTokenType The type of access token that is prefered. Supported values: [Bearer, DPoP], default: DPoP

const (
	UserAccessTokenRequestTokenTypeBearer UserAccessTokenRequestTokenType = "Bearer"
	UserAccessTokenRequestTokenTypeDPoP   UserAccessTokenRequestTokenType = "DPoP"
)

Defines values for UserAccessTokenRequestTokenType.

type UserDetails

type UserDetails struct {
	// Id Machine-readable identifier, uniquely identifying the user in the issuing system.
	Id string `json:"id"`

	// Name Human-readable name of the user.
	Name string `json:"name"`

	// Role Role of the user.
	Role string `json:"role"`
}

UserDetails Claims about the authorized user.

type ValidateDPoPProof200JSONResponse

type ValidateDPoPProof200JSONResponse DPoPValidateResponse

func (ValidateDPoPProof200JSONResponse) VisitValidateDPoPProofResponse

func (response ValidateDPoPProof200JSONResponse) VisitValidateDPoPProofResponse(w http.ResponseWriter) error

type ValidateDPoPProofJSONRequestBody

type ValidateDPoPProofJSONRequestBody = DPoPValidateRequest

ValidateDPoPProofJSONRequestBody defines body for ValidateDPoPProof for application/json ContentType.

type ValidateDPoPProofRequestObject

type ValidateDPoPProofRequestObject struct {
	Body *ValidateDPoPProofJSONRequestBody
}

type ValidateDPoPProofResponseObject

type ValidateDPoPProofResponseObject interface {
	VisitValidateDPoPProofResponse(w http.ResponseWriter) error
}

type ValidateDPoPProofdefaultApplicationProblemPlusJSONResponse

type ValidateDPoPProofdefaultApplicationProblemPlusJSONResponse struct {
	Body struct {
		// Detail A human-readable explanation specific to this occurrence of the problem.
		Detail string `json:"detail"`

		// Status HTTP statuscode
		Status float32 `json:"status"`

		// Title A short, human-readable summary of the problem type.
		Title string `json:"title"`
	}
	StatusCode int
}

func (ValidateDPoPProofdefaultApplicationProblemPlusJSONResponse) VisitValidateDPoPProofResponse

func (response ValidateDPoPProofdefaultApplicationProblemPlusJSONResponse) VisitValidateDPoPProofResponse(w http.ResponseWriter) error

type VerifiableCredential

type VerifiableCredential = vc.VerifiableCredential

VerifiableCredential is an alias

type VerifiablePresentation

type VerifiablePresentation = vc.VerifiablePresentation

VerifiablePresentation is an alias

type WalletOwnerType

type WalletOwnerType = pe.WalletOwnerType

WalletOwnerType is an alias

type Wrapper

type Wrapper struct {
	// contains filtered or unexported fields
}

Wrapper handles OAuth2 flows.

func New

func New(
	authInstance auth.AuthenticationServices, vcrInstance vcr.VCR, didKeyResolver resolver.DIDKeyResolver, subjectManager didsubject.Manager, storageEngine storage.Engine,
	policyBackend policy.PDPBackend, jwtSigner nutsCrypto.JWTSigner, jsonldManager jsonld.JSONLD) *Wrapper

func (Wrapper) Callback

func (Wrapper) HandleAuthorizeRequest

HandleAuthorizeRequest handles calls to the authorization endpoint for starting an authorization code flow.

func (Wrapper) HandleTokenRequest

HandleTokenRequest handles calls to the token endpoint for exchanging a grant (e.g authorization code or pre-authorized code) for an access token.

func (Wrapper) IntrospectAccessToken

IntrospectAccessToken allows the resource server (XIS/EHR) to introspect details of an access token issued by this node

func (Wrapper) IntrospectAccessTokenExtended

IntrospectAccessTokenExtended allows the resource server (XIS/EHR) to introspect details of an access token issued by this node. It returns the same information as IntrospectAccessToken, but with additional information.

func (Wrapper) OAuthAuthorizationServerMetadata

OAuthAuthorizationServerMetadata returns the Authorization Server's metadata

func (Wrapper) OAuthClientMetadata

OAuthClientMetadata returns the OAuth2 Client metadata for the request.Id if it is managed by this node.

func (Wrapper) RequestJWTByGet

RequestJWTByGet returns the Request Object referenced as 'request_uri' in an authorization request. RFC9101: The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR).

func (Wrapper) RequestJWTByPost

RequestJWTByPost returns the Request Object referenced as 'request_uri' in an authorization request. Extension of OpenID 4 Verifiable Presentations (OpenID4VP) on RFC9101: The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR).

func (Wrapper) ResolveStatusCode

func (r Wrapper) ResolveStatusCode(err error) int

ResolveStatusCode maps errors returned by this API to specific HTTP status codes.

func (Wrapper) Routes

func (r Wrapper) Routes(router core.EchoRouter)

func (Wrapper) StatusList

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL