openid4vci

package
v6.2.13 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: GPL-3.0 Imports: 25 Imported by: 0

Documentation

Overview

Package openid4vci is a generated GoMock package.

Package openid4vci is a generated GoMock package.

Package openid4vci is a generated GoMock package.

Index

Constants

View Source
const CredentialIssuerMetadataWellKnownPath = "/.well-known/openid-credential-issuer"

CredentialIssuerMetadataWellKnownPath defines the well-known path for retrieving OpenID4VCI CredentialIssuerMetadata Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-issuer-metadata-

View Source
const JWTTypeOpenID4VCIProof = "openid4vci-proof+jwt"

JWTTypeOpenID4VCIProof defines the OpenID4VCI JWT-subtype (used as typ claim in the JWT).

View Source
const PreAuthorizedCodeGrant = "urn:ietf:params:oauth:grant-type:pre-authorized_code"

PreAuthorizedCodeGrant is the grant type used for pre-authorized code grant from the OpenID4VCI specification. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-pre-authorized-code-flow

View Source
const ProofTypeJWT = "jwt"

ProofTypeJWT defines the Credential Request proof type for JWTs.

View Source
const ProviderMetadataWellKnownPath = "/.well-known/oauth-authorization-server"

ProviderMetadataWellKnownPath defines the well-known path for retrieving OpenID ProviderMetadata Specified by https://www.rfc-editor.org/rfc/rfc8414.html#section-3

View Source
const WalletMetadataWellKnownPath = "/.well-known/openid-credential-wallet"

WalletMetadataWellKnownPath defines the well-known path for OpenID4VCI Wallet Metadata. It is NOT specified by the OpenID4VCI specification, we just use it to be consistent with the other well-known paths.

Variables

View Source
var ErrIdentifierNotConfigured = errors.New("no OpenID4VCI identifier configured for DID")

ErrIdentifierNotConfigured is returned by callers wrapping an IdentifierResolver when resolution completed without error but yielded an empty identifier, meaning the DID isn't (yet) usable over OpenID4VCI (e.g. it's missing its node-http-services-baseurl service).

View Source
var HttpClientTrace *httptrace.ClientTrace = nil

Functions

func CreateIdentifier

func CreateIdentifier(baseURL string, id did.DID) string

func SetTLSIdentifierResolverPort

func SetTLSIdentifierResolverPort(t testing.TB, port int)

SetTLSIdentifierResolverPort sets the port used by the TLS identifier resolver to the given port, and restores the original port when the test is done.

func ValidateDefinitionWithCredential

func ValidateDefinitionWithCredential(credential vc.VerifiableCredential, definition CredentialDefinition) error

ValidateDefinitionWithCredential confirms that the vc.VerifiableCredential is defined by the CredentialDefinition. CredentialDefinition is assumed to be valid, see ValidateCredentialDefinition.

Types

type Config

type Config struct {
	// DefinitionsDIR defines the directory where the additional credential definitions are stored
	DefinitionsDIR string `koanf:"definitionsdir"`
	// Enabled indicates if issuing and receiving credentials over OpenID4VCI is enabled
	Enabled bool `koanf:"enabled"`
	// Timeout defines the timeout for HTTP client operations
	Timeout time.Duration `koanf:"timeout"`
}

Config holds the config for the OpenID4VCI credential issuer and wallet

type CredentialDefinition

type CredentialDefinition struct {
	Context           []ssi.URI               `json:"@context"`
	Type              []ssi.URI               `json:"type"`
	CredentialSubject *map[string]interface{} `json:"credentialSubject,omitempty"` // optional and currently not used
}

CredentialDefinition defines the 'credential_definition' for Format VerifiableCredentialJSONLDFormat Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-vc-secured-using-data-integ

func (*CredentialDefinition) Validate

func (cd *CredentialDefinition) Validate(isOffer bool) error

Validate the CredentialDefinition according to the VerifiableCredentialJSONLDFormat format

type CredentialIssuerMetadata

type CredentialIssuerMetadata struct {
	// CredentialIssuer defines the identifier of the credential issuer.
	CredentialIssuer string `json:"credential_issuer"`

	// CredentialEndpoint defines where the wallet can send a request to retrieve a credential.
	CredentialEndpoint string `json:"credential_endpoint"`

	// CredentialsSupported defines metadata about which credential types the credential issuer can issue.
	CredentialsSupported []map[string]interface{} `json:"credentials_supported"`
}

CredentialIssuerMetadata defines the OpenID4VCI Credential Issuer Metadata. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-issuer-metadata

type CredentialOffer

type CredentialOffer struct {
	// CredentialIssuer defines the identifier of the credential issuer.
	CredentialIssuer string `json:"credential_issuer"`
	// Credentials defines the credentials offered by the issuer to the wallet.
	Credentials []OfferedCredential `json:"credentials"`
	// Grants defines the grants offered by the issuer to the wallet.
	Grants map[string]interface{} `json:"grants"`
}

CredentialOffer defines credentials offered by the issuer to the wallet. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-offer-parameters

type CredentialOfferResponse

type CredentialOfferResponse struct {
	// Status defines the status of the credential offer.
	Status CredentialOfferStatus `json:"status"`
}

CredentialOfferResponse defines the response for credential offer requests. It is an extension to the OpenID4VCI specification to better support server-to-server issuance.

type CredentialOfferStatus

type CredentialOfferStatus string

CredentialOfferStatus defines the status of a credential offer flow.

const CredentialOfferStatusReceived CredentialOfferStatus = "credential_received"

CredentialOfferStatusReceived indicates that the wallet has received the credential.

type CredentialRequest

type CredentialRequest struct {
	Format               string                  `json:"format"`
	CredentialDefinition *CredentialDefinition   `json:"credential_definition,omitempty"`
	Proof                *CredentialRequestProof `json:"proof,omitempty"`
}

CredentialRequest defines the credential request sent by the wallet to the issuer. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-request.

type CredentialRequestProof

type CredentialRequestProof struct {
	Jwt       string `json:"jwt"`
	ProofType string `json:"proof_type"`
}

CredentialRequestProof defines the proof of possession of key material when requesting a Credential. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-proof-types

type CredentialResponse

type CredentialResponse struct {
	Format     string                  `json:"format,omitempty"`
	Credential *map[string]interface{} `json:"credential,omitempty"`
	CNonce     *string                 `json:"c_nonce,omitempty"`
}

CredentialResponse defines the response for credential requests. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-response

type DIDIdentifierResolver

type DIDIdentifierResolver struct {
	ServiceResolver resolver.ServiceResolver
}

DIDIdentifierResolver is a IdentifierResolver that resolves identifiers from DID documents.

func (DIDIdentifierResolver) Resolve

func (i DIDIdentifierResolver) Resolve(id did.DID) (string, error)

type Error

type Error struct {
	// CNonce is a random string that the client must send in the next credential request.
	CNonce *string `json:"c_nonce,omitempty"`
	// CNonceExpiresIn is the number of seconds until the c_nonce expires.
	CNonceExpiresIn *int `json:"c_nonce_expires_in,omitempty"`
	// Code is the error code as defined by the OpenID4VCI spec.
	Code ErrorCode `json:"error"`
	// Err is the underlying error, may be omitted. It is not intended to be returned to the client.
	Err error `json:"-"`
	// StatusCode is the HTTP status code that should be returned to the client.
	StatusCode int `json:"-"`
}

Error is an error that signals the error was (probably) caused by the client (e.g. bad request), or that the client can recover from the error (e.g. retry). Errors are specified by the OpenID4VCI specification. Invalid proof errors may also add a new c_nonce that the client must use in the next credential request.

func (Error) Error

func (e Error) Error() string

Error returns the error message, which is either the underlying error or the code if there is no underlying error

func (Error) Unwrap

func (e Error) Unwrap() error

Unwrap returns the underlying error, allowing errors.Is/errors.As to match against it.

type ErrorCode

type ErrorCode string

ErrorCode specifies error codes as defined by the OpenID4VCI spec.

const (
	// InvalidRequest is returned when:
	// - the Authorization Server does not expect a PIN in the pre-authorized flow but the client provides a PIN
	// - the Authorization Server expects a PIN in the pre-authorized flow but the client does not provide a PIN
	// - Credential Request was malformed. One or more of the parameters (i.e. format, proof) are missing or malformed.
	InvalidRequest ErrorCode = "invalid_request"
	// InvalidClient is returned when:
	// - the client tried to send a Token Request with a Pre-Authorized Code without Client ID but the Authorization Server does not support anonymous access
	InvalidClient ErrorCode = "invalid_client"
	// InvalidGrant is returned when (in addition to cases defined by OAuth2):
	// - the Authorization Server expects a PIN in the pre-authorized flow but the client provides the wrong PIN
	// - the End-User provides the wrong Pre-Authorized Code or the Pre-Authorized Code has expired
	InvalidGrant ErrorCode = "invalid_grant"
	// InvalidToken is returned when (in addition to cases defined by OAuth2):
	// - Credential Request contains the wrong Access Token or the Access Token is missing
	InvalidToken ErrorCode = "invalid_token"
	// UnsupportedGrantType is returned when the Authorization Server does not support the requested grant type.
	UnsupportedGrantType ErrorCode = "unsupported_grant_type"
	// ServerError is returned when the Authorization Server encounters an unexpected condition that prevents it from fulfilling the request.
	ServerError ErrorCode = "server_error"
	// UnsupportedCredentialType is returned when the credential issuer does not support the requested credential type.
	UnsupportedCredentialType ErrorCode = "unsupported_credential_type"
	// UnsupportedCredentialFormat is returned when the credential issuer does not support the requested credential format.
	UnsupportedCredentialFormat ErrorCode = "unsupported_credential_format"
	// InvalidProof is returned when the Credential Request did not contain a proof,
	// or proof was invalid, i.e. it was not bound to a Credential Issuer provided nonce
	InvalidProof ErrorCode = "invalid_proof"
)

type IdentifierResolver

type IdentifierResolver interface {
	Resolve(id did.DID) (string, error)
}

IdentifierResolver defines the interface for resolving OpenID4VCI identifiers (of wallet and issuer). The identifier is the base URL of the issuer or wallet, at which well-known endpoints can be found.

func NewTLSIdentifierResolver

func NewTLSIdentifierResolver(underlying IdentifierResolver, config *tls.Config) IdentifierResolver

NewTLSIdentifierResolver creates a IdentifierResolver that tries to derive the identifier from the TLS certificate if it can't be resolved using the DID document. It does so by constructing the identifier from the CommonName and SubjectAlternativeNames of the certificate and requesting metadata.

type IssuerAPIClient

type IssuerAPIClient interface {
	OAuth2Client

	// Metadata returns the Credential Issuer Metadata.
	Metadata() CredentialIssuerMetadata
	// RequestCredential requests a credential from the issuer.
	RequestCredential(ctx context.Context, request CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)
}

IssuerAPIClient defines the API client used by the wallet to communicate with the credential issuer.

func NewIssuerAPIClient

func NewIssuerAPIClient(ctx context.Context, httpClient core.HTTPRequestDoer, credentialIssuerIdentifier string) (IssuerAPIClient, error)

NewIssuerAPIClient resolves the Credential Issuer Metadata from the well-known endpoint and returns a client that can be used to communicate with the issuer.

type MockIdentifierResolver

type MockIdentifierResolver struct {
	// contains filtered or unexported fields
}

MockIdentifierResolver is a mock of IdentifierResolver interface.

func NewMockIdentifierResolver

func NewMockIdentifierResolver(ctrl *gomock.Controller) *MockIdentifierResolver

NewMockIdentifierResolver creates a new mock instance.

func (*MockIdentifierResolver) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockIdentifierResolver) Resolve

func (m *MockIdentifierResolver) Resolve(id did.DID) (string, error)

Resolve mocks base method.

type MockIdentifierResolverMockRecorder

type MockIdentifierResolverMockRecorder struct {
	// contains filtered or unexported fields
}

MockIdentifierResolverMockRecorder is the mock recorder for MockIdentifierResolver.

func (*MockIdentifierResolverMockRecorder) Resolve

Resolve indicates an expected call of Resolve.

type MockIssuerAPIClient

type MockIssuerAPIClient struct {
	// contains filtered or unexported fields
}

MockIssuerAPIClient is a mock of IssuerAPIClient interface.

func NewMockIssuerAPIClient

func NewMockIssuerAPIClient(ctrl *gomock.Controller) *MockIssuerAPIClient

NewMockIssuerAPIClient creates a new mock instance.

func (*MockIssuerAPIClient) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockIssuerAPIClient) Metadata

Metadata mocks base method.

func (*MockIssuerAPIClient) RequestAccessToken

func (m *MockIssuerAPIClient) RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)

RequestAccessToken mocks base method.

func (*MockIssuerAPIClient) RequestCredential

func (m *MockIssuerAPIClient) RequestCredential(ctx context.Context, request CredentialRequest, accessToken string) (*vc.VerifiableCredential, error)

RequestCredential mocks base method.

type MockIssuerAPIClientMockRecorder

type MockIssuerAPIClientMockRecorder struct {
	// contains filtered or unexported fields
}

MockIssuerAPIClientMockRecorder is the mock recorder for MockIssuerAPIClient.

func (*MockIssuerAPIClientMockRecorder) Metadata

Metadata indicates an expected call of Metadata.

func (*MockIssuerAPIClientMockRecorder) RequestAccessToken

func (mr *MockIssuerAPIClientMockRecorder) RequestAccessToken(grantType, params any) *gomock.Call

RequestAccessToken indicates an expected call of RequestAccessToken.

func (*MockIssuerAPIClientMockRecorder) RequestCredential

func (mr *MockIssuerAPIClientMockRecorder) RequestCredential(ctx, request, accessToken any) *gomock.Call

RequestCredential indicates an expected call of RequestCredential.

type MockOAuth2Client

type MockOAuth2Client struct {
	// contains filtered or unexported fields
}

MockOAuth2Client is a mock of OAuth2Client interface.

func NewMockOAuth2Client

func NewMockOAuth2Client(ctrl *gomock.Controller) *MockOAuth2Client

NewMockOAuth2Client creates a new mock instance.

func (*MockOAuth2Client) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockOAuth2Client) RequestAccessToken

func (m *MockOAuth2Client) RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)

RequestAccessToken mocks base method.

type MockOAuth2ClientMockRecorder

type MockOAuth2ClientMockRecorder struct {
	// contains filtered or unexported fields
}

MockOAuth2ClientMockRecorder is the mock recorder for MockOAuth2Client.

func (*MockOAuth2ClientMockRecorder) RequestAccessToken

func (mr *MockOAuth2ClientMockRecorder) RequestAccessToken(grantType, params any) *gomock.Call

RequestAccessToken indicates an expected call of RequestAccessToken.

type MockWalletAPIClient

type MockWalletAPIClient struct {
	// contains filtered or unexported fields
}

MockWalletAPIClient is a mock of WalletAPIClient interface.

func NewMockWalletAPIClient

func NewMockWalletAPIClient(ctrl *gomock.Controller) *MockWalletAPIClient

NewMockWalletAPIClient creates a new mock instance.

func (*MockWalletAPIClient) EXPECT

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockWalletAPIClient) Metadata

Metadata mocks base method.

func (*MockWalletAPIClient) OfferCredential

func (m *MockWalletAPIClient) OfferCredential(ctx context.Context, offer CredentialOffer) error

OfferCredential mocks base method.

type MockWalletAPIClientMockRecorder

type MockWalletAPIClientMockRecorder struct {
	// contains filtered or unexported fields
}

MockWalletAPIClientMockRecorder is the mock recorder for MockWalletAPIClient.

func (*MockWalletAPIClientMockRecorder) Metadata

Metadata indicates an expected call of Metadata.

func (*MockWalletAPIClientMockRecorder) OfferCredential

func (mr *MockWalletAPIClientMockRecorder) OfferCredential(ctx, offer any) *gomock.Call

OfferCredential indicates an expected call of OfferCredential.

type NoopIdentifierResolver

type NoopIdentifierResolver struct{}

func (NoopIdentifierResolver) Resolve

func (n NoopIdentifierResolver) Resolve(id did.DID) (string, error)

type OAuth2Client

type OAuth2Client interface {
	// RequestAccessToken requests an access token from the Authorization Server.
	RequestAccessToken(grantType string, params map[string]string) (*oauth.TokenResponse, error)
}

OAuth2Client defines a generic OAuth2 client.

type OAuth2ClientMetadata

type OAuth2ClientMetadata struct {
	// CredentialOfferEndpoint defines URL of the verifiable credential wallet's offer endpoint
	CredentialOfferEndpoint string `json:"credential_offer_endpoint"`
}

OAuth2ClientMetadata defines the OAuth2 Client Metadata, extended with OpenID4VCI parameters. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-client-metadata.

type OfferedCredential

type OfferedCredential struct {
	// Format specifies the credential format.
	Format string `json:"format"`
	// CredentialDefinition contains the 'credential_definition' for the Verifiable Credential Format flows.
	CredentialDefinition *CredentialDefinition `json:"credential_definition,omitempty"`
}

OfferedCredential defines a single entry in the credentials array of a CredentialOffer. We currently do not support 'JSON string' offers. Specified by https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-credential-offer-parameters and https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-vc-secured-using-data-integ

type ProviderMetadata

type ProviderMetadata struct {
	// Issuer defines the authorization server's identifier, which is a URL that uses the "https" scheme and has no query or fragment components.
	Issuer string `json:"issuer"`

	// TokenEndpoint defines the URL of the authorization server's token endpoint [RFC6749].
	TokenEndpoint string `json:"token_endpoint"`

	// PreAuthorizedGrantAnonymousAccessSupported indicates whether anonymous access (requests without client_id)
	// for pre-authorized code grant flows.
	// See https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html#name-oauth-20-authorization-serv
	PreAuthorizedGrantAnonymousAccessSupported bool `json:"pre-authorized_grant_anonymous_access_supported"`
}

ProviderMetadata defines the OpenID Connect Provider metadata. Specified by https://www.rfc-editor.org/rfc/rfc8414.txt

type WalletAPIClient

type WalletAPIClient interface {
	// Metadata returns the OAuth2 client metadata of the remote wallet.
	Metadata() OAuth2ClientMetadata
	// OfferCredential sends a credential offer to the remote wallet.
	OfferCredential(ctx context.Context, offer CredentialOffer) error
}

WalletAPIClient defines a client interface for communicating with a remote wallet over OpenID4VCI.

func NewWalletAPIClient

func NewWalletAPIClient(ctx context.Context, httpClient core.HTTPRequestDoer, walletMetadataURL string) (WalletAPIClient, error)

NewWalletAPIClient resolves the OAuth2 credential client metadata from the given URL.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL