Skip to main content

PresentationVerdict

Enum PresentationVerdict 

Source
pub enum PresentationVerdict {
    Valid {
        issuer: IdentityDID,
        subject: CanonicalDid,
        subject_root: CanonicalDid,
        caps: Vec<Capability>,
        role: Option<String>,
        expires_at: Option<DateTime<Utc>>,
        freshness: Freshness,
        as_of: u128,
    },
    HolderNotCurrentKey,
    WrongAudience,
    NonceMismatchOrConsumed,
    Expired,
    SubjectKelInvalid,
    CredentialNotValid(CredentialVerdict),
}
Expand description

The distinguishable outcome of verify_presentation.

Every failure names why the presentation was not honored. A possessed credential alone never yields PresentationVerdict::Valid; current-control proof is mandatory.

Variants§

§

Valid

Holder-binding proven: the credential is valid (F.5) AND the presentation was signed by the subject AID’s current signing-time key for the expected audience and nonce/TTL. Carries the grant facts so the F.6 authority bridge can build a policy context from the verified presentation, never from a raw ACDC.

Fields

§issuer: IdentityDID

The issuer AID (did:keri:) that granted the now-bound credential.

§subject: CanonicalDid

The subject (holder) AID (did:keri:) whose current key signed the presentation.

§subject_root: CanonicalDid

The subject’s proven root: for a delegated subject (dip-rooted KEL) the delegator AID whose anchoring seal the replay verified; for a root subject, the subject itself. Relying parties credit accounts to THIS identity — never to a delegator parsed out of unverified input.

§caps: Vec<Capability>

The capabilities the now-bound credential grants (a.capability).

§role: Option<String>

The optional informational role claim (a.role).

§expires_at: Option<DateTime<Utc>>

The optional credential expiry (a.expiry), as carried in the ACDC attributes.

§freshness: Freshness

How fresh this honored verdict is under the relying party’s freshness policy (ADR 009). A possessed-but-offline credential slice yields Freshness::Unknown; the verdict is never a bare Valid, so a relying party can tell Valid(Fresh) from Valid(Unknown) and apply a stricter policy. The gate already refused Stale/ policy-failing freshness, so this is Fresh or (tolerated) Unknown.

§as_of: u128

The issuer-KEL position the bound credential was verified as-of: the tip (seq) of the given issuer KEL (ADR 009, the {as_of, freshness} pair). Carried through from the inner credential verdict so a relying party can see how current the slice is, not just the freshness grade — Unknown as-of which position.

§

HolderNotCurrentKey

The presentation signature did not verify against the subject KEL’s current key — the presenter does not currently control a.i (bearer / stale-key rejection).

§

WrongAudience

The presentation was bound to a different audience than expected.

§

NonceMismatchOrConsumed

Challenge path: the presented nonce did not match the verifier’s challenge, or the challenge was already consumed (single-use replay protection).

§

Expired

TTL path: the non-interactive presentation’s not_after has passed (now >= not_after).

§

SubjectKelInvalid

The subject’s KEL could not be replayed (missing/forked/invalid) — no current key to bind against.

§

CredentialNotValid(CredentialVerdict)

The credential itself is not valid (chains F.5): revoked, expired, unanchored, schema/SAID mismatch, etc. A presentation of an invalid credential binds nothing.

Implementations§

Source§

impl PresentationVerdict

Source

pub fn is_honored(&self) -> bool

Whether the presentation is honored (Valid).

Source

pub fn freshness(&self) -> Option<Freshness>

The freshness of an honored verdict (ADR 009), or None when the presentation was not honored. An honored verdict always names its freshness — it is never a bare Valid — so a relying party can distinguish Valid(Fresh) from a tolerated Valid(Unknown).

Source

pub fn as_of(&self) -> Option<u128>

The issuer-KEL position an honored verdict was verified as-of (the {as_of, freshness} pair, ADR 009), or None when the presentation was not honored.

Trait Implementations§

Source§

impl Clone for PresentationVerdict

Source§

fn clone(&self) -> PresentationVerdict

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for PresentationVerdict

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for PresentationVerdict

Source§

impl PartialEq for PresentationVerdict

Source§

fn eq(&self, other: &PresentationVerdict) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for PresentationVerdict

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.