Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: accept header #253

Open
wants to merge 27 commits into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from 15 commits
Commits
Show all changes
27 commits
Select commit Hold shift + click to select a range
8635d5a
accept-profile auth/jwz modes
volodymyr-basiuk Aug 8, 2024
d9b5ee9
final accept profile format
volodymyr-basiuk Aug 9, 2024
60b1dbd
fix no accept header
volodymyr-basiuk Aug 9, 2024
bf19cb8
add accept in req unit tests
volodymyr-basiuk Aug 12, 2024
e0882d4
getEnvelop and isSupported on Packer
volodymyr-basiuk Aug 20, 2024
ec1dc46
fix protocol version check
volodymyr-basiuk Aug 20, 2024
939ffb2
allow no alg specified
volodymyr-basiuk Aug 20, 2024
23673b8
algSupported refactor
volodymyr-basiuk Aug 20, 2024
8d673ff
Merge branch 'main' into feat/accept-header
volodymyr-basiuk Aug 25, 2024
3dbf2ca
bump patch version
volodymyr-basiuk Aug 25, 2024
1f6d6cd
getEnvelope and isProfileSupported
volodymyr-basiuk Aug 29, 2024
babd7d3
Merge branch 'main' into feat/accept-header
volodymyr-basiuk Aug 29, 2024
245260e
feat: add support of submitZKPResponseCrossChain (#254)
volodymyr-basiuk Sep 4, 2024
b982bc6
bump version
volodymyr-basiuk Sep 4, 2024
7d8667b
resolve conflict
volodymyr-basiuk Sep 4, 2024
e775a41
resolve comments
volodymyr-basiuk Sep 19, 2024
fb82622
format
volodymyr-basiuk Sep 19, 2024
0bed0ba
fix submit typo in supported enum (#262)
volodymyr-basiuk Sep 5, 2024
b6d7084
feat: add optional displayMethod to CredentialRequest (#263)
volodymyr-basiuk Sep 5, 2024
e3161bd
fix: credential context order (#266)
volodymyr-basiuk Sep 6, 2024
189e973
Update README.md
0xpulkit Sep 6, 2024
936acba
ability to replace auth bjj with another status (#264)
vmidyllic Sep 9, 2024
fbd0026
update profile nonce, so it can be number or string (#268)
vmidyllic Sep 10, 2024
684292b
feat: add cspell (#267)
volodymyr-basiuk Sep 11, 2024
2185278
update js-iden3-core, js-jwz (#270)
daveroga Sep 16, 2024
1c34e2d
bump to 1.21.0
volodymyr-basiuk Sep 19, 2024
dcd9a6b
merge
volodymyr-basiuk Sep 19, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@0xpolygonid/js-sdk",
"version": "1.18.0",
"version": "1.18.1",
"description": "SDK to work with Polygon ID",
"main": "dist/node/cjs/index.js",
"module": "dist/node/esm/index.js",
Expand Down
27 changes: 27 additions & 0 deletions src/iden3comm/constants.ts
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
import { AcceptProfile } from './types';

const IDEN3_PROTOCOL = 'https://iden3-communication.io/';
/**
* Constants for Iden3 protocol
Expand Down Expand Up @@ -79,5 +81,30 @@ export const SUPPORTED_PUBLIC_KEY_TYPES = {
]
};

export enum ProtocolVersion {
v1 = 'iden3comm/v1'
}

export enum AcceptAuthCircuits {
authV2 = 'authV2',
authV3 = 'authV3'
}

export enum AcceptJwzAlgorithms {
groth16 = 'groth16'
}

export enum AcceptJwsAlgorithms {
ES256K = 'ES256K',
ES256KR = 'ES256K-R'
}

export const defaultAcceptProfile: AcceptProfile = {
protocolVersion: ProtocolVersion.v1,
env: MediaType.ZKPMessage,
circuits: [AcceptAuthCircuits.authV2],
alg: [AcceptJwzAlgorithms.groth16]
};

export const DEFAULT_PROOF_VERIFY_DELAY = 1 * 60 * 60 * 1000; // 1 hour
export const DEFAULT_AUTH_VERIFY_DELAY = 5 * 60 * 1000; // 5 minutes
40 changes: 36 additions & 4 deletions src/iden3comm/handlers/auth.ts
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
import { MediaType } from '../constants';
import { MediaType, ProtocolVersion } from '../constants';
import { IProofService } from '../../proof/proof-service';
import { PROTOCOL_MESSAGE_TYPE } from '../constants';

Expand All @@ -21,6 +21,7 @@ import { byteDecoder, byteEncoder } from '../../utils';
import { processZeroKnowledgeProofRequests } from './common';
import { CircuitId } from '../../circuits';
import { AbstractMessageHandler, IProtocolMessageHandler } from './message-handler';
import { parseAcceptProfile } from '../utils';

/**
* createAuthorizationRequest is a function to create protocol authorization request
Expand Down Expand Up @@ -231,13 +232,44 @@ export class AuthHandler

// override sender did if it's explicitly specified in the auth request
const to = authRequest.to ? DID.parse(authRequest.to) : ctx.senderDid;
const mediaType = ctx.mediaType || MediaType.ZKPMessage;
const guid = uuid.v4();

if (!authRequest.from) {
throw new Error('auth request should contain from field');
}

const responseType = PROTOCOL_MESSAGE_TYPE.AUTHORIZATION_RESPONSE_MESSAGE_TYPE;
let mediaType: MediaType;
if (authRequest.body.accept?.length) {
const supportedMediaTypes: MediaType[] = [];
for (const acceptProfile of authRequest.body.accept || []) {
// 1. check protocol version
const { protocolVersion, env } = parseAcceptProfile(acceptProfile);
const responseTypeVersion = Number(responseType.split('/').at(-2));
if (
protocolVersion === ProtocolVersion.v1 &&
(responseTypeVersion < 1 || responseTypeVersion >= 2)
) {
continue;
}
// 2. check packer support
if (this._packerMgr.isSupported(env, acceptProfile)) {
supportedMediaTypes.push(env);
}
}

if (!supportedMediaTypes.length) {
throw new Error('no profile meets `access` header requirements');
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

throw new Error('no packer with profile which meets access header requirements');
Comment

}

mediaType = supportedMediaTypes[0];
if (ctx.mediaType && supportedMediaTypes.includes(ctx.mediaType)) {
mediaType = ctx.mediaType;
}
} else {
mediaType = ctx.mediaType || MediaType.ZKPMessage;
}

const from = DID.parse(authRequest.from);

const responseScope = await processZeroKnowledgeProofRequests(
Expand All @@ -250,8 +282,8 @@ export class AuthHandler

return {
id: guid,
typ: ctx.mediaType,
type: PROTOCOL_MESSAGE_TYPE.AUTHORIZATION_RESPONSE_MESSAGE_TYPE,
typ: mediaType,
type: responseType,
thid: authRequest.thid ?? guid,
body: {
message: authRequest?.body?.message,
Expand Down
1 change: 1 addition & 0 deletions src/iden3comm/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ export * from './packers';
export * from './types';
export * from './handlers';
export * from './utils/did';
export * from './utils/accept-profile';

import * as PROTOCOL_CONSTANTS from './constants';
export { PROTOCOL_CONSTANTS };
15 changes: 15 additions & 0 deletions src/iden3comm/packageManager.ts
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,21 @@ export class PackageManager implements IPackageManager {
this.packers = new Map<MediaType, IPacker>();
}

/** {@inheritDoc IPackageManager.isSupported} */
isSupported(mediaType: MediaType, profile: string): boolean {
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you should rename interface method to isProfileSupported too

const p = this.packers.get(mediaType);
if (!p) {
return false;
}

return p.isProfileSupported(profile);
}

/** {@inheritDoc IPackageManager.getSupportedMediaTypes} */
getSupportedMediaTypes(): MediaType[] {
return [...this.packers.keys()];
}

/** {@inheritDoc IPackageManager.registerPackers} */
registerPackers(packers: Array<IPacker>): void {
packers.forEach((p) => {
Expand Down
35 changes: 34 additions & 1 deletion src/iden3comm/packers/jws.ts
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
import { BasicMessage, IPacker, JWSPackerParams } from '../types';
import { MediaType, SUPPORTED_PUBLIC_KEY_TYPES } from '../constants';
import { AcceptJwsAlgorithms, MediaType, SUPPORTED_PUBLIC_KEY_TYPES } from '../constants';
import { extractPublicKeyBytes, resolveVerificationMethods } from '../utils/did';
import { keyPath, KMS } from '../../kms/';

Expand All @@ -13,6 +13,7 @@ import {
decodeBase64url,
encodeBase64url
} from '../../utils';
import { parseAcceptProfile } from '../utils';

/**
* Packer that can pack message to JWZ token,
Expand Down Expand Up @@ -102,6 +103,38 @@ export class JWSPacker implements IPacker {
return MediaType.SignedMessage;
}

/** {@inheritDoc IPacker.getEnvelope} */
getEnvelope(): string {
return `env=${this.mediaType()}&alg=${this.getSupportedAlgorithms().join(',')}`;
}

/** {@inheritDoc IPacker.isProfileSupported} */
isProfileSupported(profile: string) {
const { env, circuits, alg } = parseAcceptProfile(profile);
if (env !== this.mediaType()) {
return false;
}

if (circuits) {
throw new Error(`Circuits are not supported for ${env} media type`);
}

let algSupported = !alg?.length;
const supportedAlgs = this.getSupportedAlgorithms();
for (const a of alg || []) {
if (supportedAlgs.includes(a as AcceptJwsAlgorithms)) {
algSupported = true;
break;
}
}

return algSupported;
}

private getSupportedAlgorithms(): AcceptJwsAlgorithms[] {
return [AcceptJwsAlgorithms.ES256K, AcceptJwsAlgorithms.ES256KR];
}

private async resolveDidDoc(from: string) {
let didDocument: DIDDocument;
try {
Expand Down
24 changes: 24 additions & 0 deletions src/iden3comm/packers/plain.ts
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
import { BasicMessage, IPacker } from '../types';
import { MediaType } from '../constants';
import { byteDecoder, byteEncoder } from '../../utils';
import { parseAcceptProfile } from '../utils';

/**
* Plain packer just serializes bytes to JSON and adds media type
Expand Down Expand Up @@ -53,4 +54,27 @@ export class PlainPacker implements IPacker {
mediaType(): MediaType {
return MediaType.PlainMessage;
}

/** {@inheritDoc IPacker.getEnvelope} */
getEnvelope(): string {
return `env=${this.mediaType()}`;
}

/** {@inheritDoc IPacker.isProfileSupported} */
isProfileSupported(profile: string) {
const { env, circuits, alg } = parseAcceptProfile(profile);
if (env !== this.mediaType()) {
return false;
}

if (circuits) {
throw new Error(`Circuits are not supported for ${env} media type`);
}

if (alg) {
throw new Error(`Algorithms are not supported for ${env} media type`);
}

return true;
}
}
46 changes: 45 additions & 1 deletion src/iden3comm/packers/zkp.ts
Original file line number Diff line number Diff line change
Expand Up @@ -20,9 +20,10 @@ import {
ErrStateVerificationFailed,
ErrUnknownCircuitID
} from '../errors';
import { MediaType } from '../constants';
import { AcceptAuthCircuits, AcceptJwzAlgorithms, MediaType } from '../constants';
import { byteDecoder, byteEncoder } from '../../utils';
import { DEFAULT_AUTH_VERIFY_DELAY } from '../constants';
import { parseAcceptProfile } from '../utils';

const { getProvingMethod } = proving;

Expand Down Expand Up @@ -174,6 +175,49 @@ export class ZKPPacker implements IPacker {
mediaType(): MediaType {
return MediaType.ZKPMessage;
}

/** {@inheritDoc IPacker.getEnvelope} */
getEnvelope(): string {
Copy link
Collaborator

@vmidyllic vmidyllic Sep 9, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

and in future I guess we will have potentially an array of strings even for one media type, maybe we should return an array of strings and rename methods to getSupportedProfiles()

return `env=${this.mediaType()}&alg=${this.getSupportedAlgorithms().join(
','
)}&circuitIds=${this.getSupportedCircuitIds().join(',')}`;
}

/** {@inheritDoc IPacker.isProfileSupported} */
isProfileSupported(profile: string) {
const { env, circuits, alg } = parseAcceptProfile(profile);
if (env !== this.mediaType()) {
return false;
}

let circuitIdSupported = !circuits?.length;
const supportedCircuitIds = this.getSupportedCircuitIds();
for (const c of circuits || []) {
if (supportedCircuitIds.includes(c)) {
circuitIdSupported = true;
break;
}
}

let algSupported = !alg?.length;
const supportedAlgs = this.getSupportedAlgorithms();
for (const a of alg || []) {
if (supportedAlgs.includes(a as AcceptJwzAlgorithms)) {
algSupported = true;
break;
}
}

return algSupported && circuitIdSupported;
}

private getSupportedAlgorithms(): AcceptJwzAlgorithms[] {
return [AcceptJwzAlgorithms.groth16];
}

private getSupportedCircuitIds(): AcceptAuthCircuits[] {
return [AcceptAuthCircuits.authV2];
}
}

const verifySender = async (token: Token, msg: BasicMessage): Promise<void> => {
Expand Down
1 change: 1 addition & 0 deletions src/iden3comm/types/index.ts
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@ export * from './protocol/revocation';
export * from './protocol/contract-request';
export * from './protocol/proposal-request';
export * from './protocol/payment';
export * from './protocol/accept-profile';

export * from './packer';
export * from './models';
Expand Down
15 changes: 15 additions & 0 deletions src/iden3comm/types/packageManager.ts
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,21 @@ export interface IPackageManager {
* @returns MediaType
*/
getMediaType(envelope: string): MediaType;

/**
* gets supported media type by packer manager
*
* @returns MediaType[]
*/
getSupportedMediaTypes(): MediaType[];

/**
* gets if media type and algorithms supported by packer manager
*
* @param {MediaType} mediaType
* @returns AcceptJwzAlgorithms[] | AcceptJwsAlgorithms[]
*/
isSupported(mediaType: MediaType, profile: string): boolean;
}
/**
* EnvelopeStub is used to stub the jwt based envelops
Expand Down
15 changes: 15 additions & 0 deletions src/iden3comm/types/packer.ts
Original file line number Diff line number Diff line change
Expand Up @@ -137,6 +137,21 @@ export interface IPacker {
* @returns The media type as a MediaType.
*/
mediaType(): MediaType;

/**
* gets packer envelope with options
*
* @returns {string}
*/
getEnvelope(): string;

/**
* returns true if profile is supported by packer
*
* @param {string} profile
* @returns {boolean}
*/
isProfileSupported(profile: string): boolean;
}
/**
* Params for verification of auth circuit public signals
Expand Down
14 changes: 14 additions & 0 deletions src/iden3comm/types/protocol/accept-profile.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
import {
AcceptAuthCircuits,
AcceptJwsAlgorithms,
AcceptJwzAlgorithms,
MediaType,
ProtocolVersion
} from '../../constants';

export type AcceptProfile = {
protocolVersion: ProtocolVersion;
env: MediaType;
circuits?: AcceptAuthCircuits[];
alg?: AcceptJwsAlgorithms[] | AcceptJwzAlgorithms[];
};
1 change: 1 addition & 0 deletions src/iden3comm/types/protocol/auth.ts
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ export type AuthorizationRequestMessageBody = {
callbackUrl: string;
reason?: string;
message?: string;
accept?: string[];
did_doc?: JsonDocumentObject;
scope: Array<ZeroKnowledgeProofRequest>;
};
Expand Down
Loading