Documentation
¶
Overview ¶
Package openid4vci is a generated GoMock package.
Package openid4vci is a generated GoMock package.
Package openid4vci is a generated GoMock package.
Index ¶
- Constants
- Variables
- func CreateIdentifier(baseURL string, id did.DID) string
- func SetTLSIdentifierResolverPort(t testing.TB, port int)
- func ValidateDefinitionWithCredential(credential vc.VerifiableCredential, definition CredentialDefinition) error
- type Config
- type CredentialDefinition
- type CredentialIssuerMetadata
- type CredentialOffer
- type CredentialOfferResponse
- type CredentialOfferStatus
- type CredentialRequest
- type CredentialRequestProof
- type CredentialResponse
- type DIDIdentifierResolver
- type Error
- type ErrorCode
- type IdentifierResolver
- type IssuerAPIClient
- type MockIdentifierResolver
- type MockIdentifierResolverMockRecorder
- type MockIssuerAPIClient
- func (m *MockIssuerAPIClient) EXPECT() *MockIssuerAPIClientMockRecorder
- func (m *MockIssuerAPIClient) Metadata() CredentialIssuerMetadata
- func (m *MockIssuerAPIClient) RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)
- func (m *MockIssuerAPIClient) RequestCredential(ctx context.Context, request CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
- type MockIssuerAPIClientMockRecorder
- type MockOAuth2Client
- type MockOAuth2ClientMockRecorder
- type MockWalletAPIClient
- type MockWalletAPIClientMockRecorder
- type NoopIdentifierResolver
- type OAuth2Client
- type OAuth2ClientMetadata
- type OfferedCredential
- type ProviderMetadata
- type WalletAPIClient
Constants ¶
const CredentialIssuerMetadataWellKnownPath = "/.well-known/openid-credential-issuer"
CredentialIssuerMetadataWellKnownPath defines the well-known path for retrieving OpenID4VCI CredentialIssuerMetadata Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-issuer-metadata-
const JWTTypeOpenID4VCIProof = "openid4vci-proof+jwt"
JWTTypeOpenID4VCIProof defines the OpenID4VCI JWT-subtype (used as typ claim in the JWT).
const PreAuthorizedCodeGrant = "urn:ietf:params:oauth:grant-type:pre-authorized_code"
PreAuthorizedCodeGrant is the grant type used for pre-authorized code grant from the OpenID4VCI specification. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-pre-authorized-code-flow
const ProofTypeJWT = "jwt"
ProofTypeJWT defines the Credential Request proof type for JWTs.
const ProviderMetadataWellKnownPath = "/.well-known/oauth-authorization-server"
ProviderMetadataWellKnownPath defines the well-known path for retrieving OpenID ProviderMetadata Specified by https://www.rfc-editor.org/rfc/rfc8414.html#section-3
const WalletMetadataWellKnownPath = "/.well-known/openid-credential-wallet"
WalletMetadataWellKnownPath defines the well-known path for OpenID4VCI Wallet Metadata. It is NOT specified by the OpenID4VCI specification, we just use it to be consistent with the other well-known paths.
Variables ¶
var ErrIdentifierNotConfigured = errors.New("no OpenID4VCI identifier configured for DID")
ErrIdentifierNotConfigured is returned by callers wrapping an IdentifierResolver when resolution completed without error but yielded an empty identifier, meaning the DID isn't (yet) usable over OpenID4VCI (e.g. it's missing its node-http-services-baseurl service).
var HttpClientTrace *httptrace.ClientTrace = nil
Functions ¶
func SetTLSIdentifierResolverPort ¶
SetTLSIdentifierResolverPort sets the port used by the TLS identifier resolver to the given port, and restores the original port when the test is done.
func ValidateDefinitionWithCredential ¶
func ValidateDefinitionWithCredential(credential vc.VerifiableCredential, definition CredentialDefinition) error
ValidateDefinitionWithCredential confirms that the vc.VerifiableCredential is defined by the CredentialDefinition. CredentialDefinition is assumed to be valid, see ValidateCredentialDefinition.
Types ¶
type Config ¶
type Config struct {
// DefinitionsDIR defines the directory where the additional credential definitions are stored
DefinitionsDIR string `koanf:"definitionsdir"`
// Enabled indicates if issuing and receiving credentials over OpenID4VCI is enabled
Enabled bool `koanf:"enabled"`
// Timeout defines the timeout for HTTP client operations
Timeout time.Duration `koanf:"timeout"`
}
Config holds the config for the OpenID4VCI credential issuer and wallet
type CredentialDefinition ¶
type CredentialDefinition struct {
Context []ssi.URI `json:"@context"`
Type []ssi.URI `json:"type"`
CredentialSubject *map[string]interface{} `json:"credentialSubject,omitempty"` // optional and currently not used
}
CredentialDefinition defines the 'credential_definition' for Format VerifiableCredentialJSONLDFormat Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-vc-secured-using-data-integ
func (*CredentialDefinition) Validate ¶
func (cd *CredentialDefinition) Validate(isOffer bool) error
Validate the CredentialDefinition according to the VerifiableCredentialJSONLDFormat format
type CredentialIssuerMetadata ¶
type CredentialIssuerMetadata struct {
// CredentialIssuer defines the identifier of the credential issuer.
CredentialIssuer string `json:"credential_issuer"`
// CredentialEndpoint defines where the wallet can send a request to retrieve a credential.
CredentialEndpoint string `json:"credential_endpoint"`
// CredentialsSupported defines metadata about which credential types the credential issuer can issue.
CredentialsSupported []map[string]interface{} `json:"credentials_supported"`
}
CredentialIssuerMetadata defines the OpenID4VCI Credential Issuer Metadata. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-issuer-metadata
type CredentialOffer ¶
type CredentialOffer struct {
// CredentialIssuer defines the identifier of the credential issuer.
CredentialIssuer string `json:"credential_issuer"`
// Credentials defines the credentials offered by the issuer to the wallet.
Credentials []OfferedCredential `json:"credentials"`
// Grants defines the grants offered by the issuer to the wallet.
Grants map[string]interface{} `json:"grants"`
}
CredentialOffer defines credentials offered by the issuer to the wallet. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-offer-parameters
type CredentialOfferResponse ¶
type CredentialOfferResponse struct {
// Status defines the status of the credential offer.
Status CredentialOfferStatus `json:"status"`
}
CredentialOfferResponse defines the response for credential offer requests. It is an extension to the OpenID4VCI specification to better support server-to-server issuance.
type CredentialOfferStatus ¶
type CredentialOfferStatus string
CredentialOfferStatus defines the status of a credential offer flow.
const CredentialOfferStatusReceived CredentialOfferStatus = "credential_received"
CredentialOfferStatusReceived indicates that the wallet has received the credential.
type CredentialRequest ¶
type CredentialRequest struct {
Format string `json:"format"`
CredentialDefinition *CredentialDefinition `json:"credential_definition,omitempty"`
Proof *CredentialRequestProof `json:"proof,omitempty"`
}
CredentialRequest defines the credential request sent by the wallet to the issuer. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-request.
type CredentialRequestProof ¶
CredentialRequestProof defines the proof of possession of key material when requesting a Credential. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-proof-types
type CredentialResponse ¶
type CredentialResponse struct {
Format string `json:"format,omitempty"`
Credential *map[string]interface{} `json:"credential,omitempty"`
CNonce *string `json:"c_nonce,omitempty"`
}
CredentialResponse defines the response for credential requests. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-response
type DIDIdentifierResolver ¶
type DIDIdentifierResolver struct {
ServiceResolver resolver.ServiceResolver
}
DIDIdentifierResolver is a IdentifierResolver that resolves identifiers from DID documents.
type Error ¶
type Error struct {
// CNonce is a random string that the client must send in the next credential request.
CNonce *string `json:"c_nonce,omitempty"`
// CNonceExpiresIn is the number of seconds until the c_nonce expires.
CNonceExpiresIn *int `json:"c_nonce_expires_in,omitempty"`
// Code is the error code as defined by the OpenID4VCI spec.
Code ErrorCode `json:"error"`
// Err is the underlying error, may be omitted. It is not intended to be returned to the client.
Err error `json:"-"`
// StatusCode is the HTTP status code that should be returned to the client.
StatusCode int `json:"-"`
}
Error is an error that signals the error was (probably) caused by the client (e.g. bad request), or that the client can recover from the error (e.g. retry). Errors are specified by the OpenID4VCI specification. Invalid proof errors may also add a new c_nonce that the client must use in the next credential request.
type ErrorCode ¶
type ErrorCode string
ErrorCode specifies error codes as defined by the OpenID4VCI spec.
const ( // InvalidRequest is returned when: // - the Authorization Server does not expect a PIN in the pre-authorized flow but the client provides a PIN // - the Authorization Server expects a PIN in the pre-authorized flow but the client does not provide a PIN // - Credential Request was malformed. One or more of the parameters (i.e. format, proof) are missing or malformed. InvalidRequest ErrorCode = "invalid_request" // InvalidClient is returned when: // - the client tried to send a Token Request with a Pre-Authorized Code without Client ID but the Authorization Server does not support anonymous access InvalidClient ErrorCode = "invalid_client" // InvalidGrant is returned when (in addition to cases defined by OAuth2): // - the Authorization Server expects a PIN in the pre-authorized flow but the client provides the wrong PIN // - the End-User provides the wrong Pre-Authorized Code or the Pre-Authorized Code has expired InvalidGrant ErrorCode = "invalid_grant" // InvalidToken is returned when (in addition to cases defined by OAuth2): // - Credential Request contains the wrong Access Token or the Access Token is missing InvalidToken ErrorCode = "invalid_token" // UnsupportedGrantType is returned when the Authorization Server does not support the requested grant type. UnsupportedGrantType ErrorCode = "unsupported_grant_type" // ServerError is returned when the Authorization Server encounters an unexpected condition that prevents it from fulfilling the request. ServerError ErrorCode = "server_error" // UnsupportedCredentialType is returned when the credential issuer does not support the requested credential type. UnsupportedCredentialType ErrorCode = "unsupported_credential_type" // UnsupportedCredentialFormat is returned when the credential issuer does not support the requested credential format. UnsupportedCredentialFormat ErrorCode = "unsupported_credential_format" // InvalidProof is returned when the Credential Request did not contain a proof, // or proof was invalid, i.e. it was not bound to a Credential Issuer provided nonce InvalidProof ErrorCode = "invalid_proof" )
type IdentifierResolver ¶
IdentifierResolver defines the interface for resolving OpenID4VCI identifiers (of wallet and issuer). The identifier is the base URL of the issuer or wallet, at which well-known endpoints can be found.
func NewTLSIdentifierResolver ¶
func NewTLSIdentifierResolver(underlying IdentifierResolver, config *tls.Config) IdentifierResolver
NewTLSIdentifierResolver creates a IdentifierResolver that tries to derive the identifier from the TLS certificate if it can't be resolved using the DID document. It does so by constructing the identifier from the CommonName and SubjectAlternativeNames of the certificate and requesting metadata.
type IssuerAPIClient ¶
type IssuerAPIClient interface {
OAuth2Client
// Metadata returns the Credential Issuer Metadata.
Metadata() CredentialIssuerMetadata
// RequestCredential requests a credential from the issuer.
RequestCredential(ctx context.Context, request CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
}
IssuerAPIClient defines the API client used by the wallet to communicate with the credential issuer.
func NewIssuerAPIClient ¶
func NewIssuerAPIClient(ctx context.Context, httpClient core.HTTPRequestDoer, credentialIssuerIdentifier string) (IssuerAPIClient, error)
NewIssuerAPIClient resolves the Credential Issuer Metadata from the well-known endpoint and returns a client that can be used to communicate with the issuer.
type MockIdentifierResolver ¶
type MockIdentifierResolver struct {
// contains filtered or unexported fields
}
MockIdentifierResolver is a mock of IdentifierResolver interface.
func NewMockIdentifierResolver ¶
func NewMockIdentifierResolver(ctrl *gomock.Controller) *MockIdentifierResolver
NewMockIdentifierResolver creates a new mock instance.
func (*MockIdentifierResolver) EXPECT ¶
func (m *MockIdentifierResolver) EXPECT() *MockIdentifierResolverMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
type MockIdentifierResolverMockRecorder ¶
type MockIdentifierResolverMockRecorder struct {
// contains filtered or unexported fields
}
MockIdentifierResolverMockRecorder is the mock recorder for MockIdentifierResolver.
type MockIssuerAPIClient ¶
type MockIssuerAPIClient struct {
// contains filtered or unexported fields
}
MockIssuerAPIClient is a mock of IssuerAPIClient interface.
func NewMockIssuerAPIClient ¶
func NewMockIssuerAPIClient(ctrl *gomock.Controller) *MockIssuerAPIClient
NewMockIssuerAPIClient creates a new mock instance.
func (*MockIssuerAPIClient) EXPECT ¶
func (m *MockIssuerAPIClient) EXPECT() *MockIssuerAPIClientMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockIssuerAPIClient) Metadata ¶
func (m *MockIssuerAPIClient) Metadata() CredentialIssuerMetadata
Metadata mocks base method.
func (*MockIssuerAPIClient) RequestAccessToken ¶
func (m *MockIssuerAPIClient) RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)
RequestAccessToken mocks base method.
func (*MockIssuerAPIClient) RequestCredential ¶
func (m *MockIssuerAPIClient) RequestCredential(ctx context.Context, request CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
RequestCredential mocks base method.
type MockIssuerAPIClientMockRecorder ¶
type MockIssuerAPIClientMockRecorder struct {
// contains filtered or unexported fields
}
MockIssuerAPIClientMockRecorder is the mock recorder for MockIssuerAPIClient.
func (*MockIssuerAPIClientMockRecorder) Metadata ¶
func (mr *MockIssuerAPIClientMockRecorder) Metadata() *gomock.Call
Metadata indicates an expected call of Metadata.
func (*MockIssuerAPIClientMockRecorder) RequestAccessToken ¶
func (mr *MockIssuerAPIClientMockRecorder) RequestAccessToken(grantType, params any) *gomock.Call
RequestAccessToken indicates an expected call of RequestAccessToken.
func (*MockIssuerAPIClientMockRecorder) RequestCredential ¶
func (mr *MockIssuerAPIClientMockRecorder) RequestCredential(ctx, request, accessToken any) *gomock.Call
RequestCredential indicates an expected call of RequestCredential.
type MockOAuth2Client ¶
type MockOAuth2Client struct {
// contains filtered or unexported fields
}
MockOAuth2Client is a mock of OAuth2Client interface.
func NewMockOAuth2Client ¶
func NewMockOAuth2Client(ctrl *gomock.Controller) *MockOAuth2Client
NewMockOAuth2Client creates a new mock instance.
func (*MockOAuth2Client) EXPECT ¶
func (m *MockOAuth2Client) EXPECT() *MockOAuth2ClientMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockOAuth2Client) RequestAccessToken ¶
func (m *MockOAuth2Client) RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)
RequestAccessToken mocks base method.
type MockOAuth2ClientMockRecorder ¶
type MockOAuth2ClientMockRecorder struct {
// contains filtered or unexported fields
}
MockOAuth2ClientMockRecorder is the mock recorder for MockOAuth2Client.
func (*MockOAuth2ClientMockRecorder) RequestAccessToken ¶
func (mr *MockOAuth2ClientMockRecorder) RequestAccessToken(grantType, params any) *gomock.Call
RequestAccessToken indicates an expected call of RequestAccessToken.
type MockWalletAPIClient ¶
type MockWalletAPIClient struct {
// contains filtered or unexported fields
}
MockWalletAPIClient is a mock of WalletAPIClient interface.
func NewMockWalletAPIClient ¶
func NewMockWalletAPIClient(ctrl *gomock.Controller) *MockWalletAPIClient
NewMockWalletAPIClient creates a new mock instance.
func (*MockWalletAPIClient) EXPECT ¶
func (m *MockWalletAPIClient) EXPECT() *MockWalletAPIClientMockRecorder
EXPECT returns an object that allows the caller to indicate expected use.
func (*MockWalletAPIClient) Metadata ¶
func (m *MockWalletAPIClient) Metadata() OAuth2ClientMetadata
Metadata mocks base method.
func (*MockWalletAPIClient) OfferCredential ¶
func (m *MockWalletAPIClient) OfferCredential(ctx context.Context, offer CredentialOffer) error
OfferCredential mocks base method.
type MockWalletAPIClientMockRecorder ¶
type MockWalletAPIClientMockRecorder struct {
// contains filtered or unexported fields
}
MockWalletAPIClientMockRecorder is the mock recorder for MockWalletAPIClient.
func (*MockWalletAPIClientMockRecorder) Metadata ¶
func (mr *MockWalletAPIClientMockRecorder) Metadata() *gomock.Call
Metadata indicates an expected call of Metadata.
func (*MockWalletAPIClientMockRecorder) OfferCredential ¶
func (mr *MockWalletAPIClientMockRecorder) OfferCredential(ctx, offer any) *gomock.Call
OfferCredential indicates an expected call of OfferCredential.
type NoopIdentifierResolver ¶
type NoopIdentifierResolver struct{}
type OAuth2Client ¶
type OAuth2Client interface {
// RequestAccessToken requests an access token from the Authorization Server.
RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)
}
OAuth2Client defines a generic OAuth2 client.
type OAuth2ClientMetadata ¶
type OAuth2ClientMetadata struct {
// CredentialOfferEndpoint defines URL of the verifiable credential wallet's offer endpoint
CredentialOfferEndpoint string `json:"credential_offer_endpoint"`
}
OAuth2ClientMetadata defines the OAuth2 Client Metadata, extended with OpenID4VCI parameters. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-client-metadata.
type OfferedCredential ¶
type OfferedCredential struct {
// Format specifies the credential format.
Format string `json:"format"`
// CredentialDefinition contains the 'credential_definition' for the Verifiable Credential Format flows.
CredentialDefinition *CredentialDefinition `json:"credential_definition,omitempty"`
}
OfferedCredential defines a single entry in the credentials array of a CredentialOffer. We currently do not support 'JSON string' offers. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-offer-parameters and https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-vc-secured-using-data-integ
type ProviderMetadata ¶
type ProviderMetadata struct {
// Issuer defines the authorization server's identifier, which is a URL that uses the "https" scheme and has no query or fragment components.
Issuer string `json:"issuer"`
// TokenEndpoint defines the URL of the authorization server's token endpoint [RFC6749].
TokenEndpoint string `json:"token_endpoint"`
// PreAuthorizedGrantAnonymousAccessSupported indicates whether anonymous access (requests without client_id)
// for pre-authorized code grant flows.
// See https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-oauth-20-authorization-serv
PreAuthorizedGrantAnonymousAccessSupported bool `json:"pre-authorized_grant_anonymous_access_supported"`
}
ProviderMetadata defines the OpenID Connect Provider metadata. Specified by https://www.rfc-editor.org/rfc/rfc8414.txt
type WalletAPIClient ¶
type WalletAPIClient interface {
// Metadata returns the OAuth2 client metadata of the remote wallet.
Metadata() OAuth2ClientMetadata
// OfferCredential sends a credential offer to the remote wallet.
OfferCredential(ctx context.Context, offer CredentialOffer) error
}
WalletAPIClient defines a client interface for communicating with a remote wallet over OpenID4VCI.
func NewWalletAPIClient ¶
func NewWalletAPIClient(ctx context.Context, httpClient core.HTTPRequestDoer, walletMetadataURL string) (WalletAPIClient, error)
NewWalletAPIClient resolves the OAuth2 credential client metadata from the given URL.