1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
use serde::{Deserialize, Serialize};
use ockam_vault::PublicKey;
use crate::change_history::ProfileChangeHistory;
use crate::profile::Profile;
use crate::{EventIdentifier, KeyAttributes, ProfileChangeEvent, ProfileIdentifier, ProfileVault};
use ockam_core::{allow, deny};
#[derive(Serialize, Deserialize, Clone, Debug)]
pub struct Contact {
identifier: ProfileIdentifier,
change_history: ProfileChangeHistory,
}
impl Contact {
pub fn identifier(&self) -> &ProfileIdentifier {
&self.identifier
}
pub fn change_events(&self) -> &[ProfileChangeEvent] {
self.change_history.as_ref()
}
}
impl Contact {
pub fn new(identifier: ProfileIdentifier, change_events: Vec<ProfileChangeEvent>) -> Self {
Contact {
identifier,
change_history: ProfileChangeHistory::new(change_events),
}
}
}
impl Contact {
pub fn verify(&self, vault: &mut impl ProfileVault) -> ockam_core::Result<bool> {
if !ProfileChangeHistory::check_consistency(&[], self.change_events()) {
return deny();
}
if !self.change_history.verify_all_existing_events(vault)? {
return deny();
}
let root_public_key = self.change_history.get_first_root_public_key()?;
let root_key_id = vault.compute_key_id_for_public_key(&root_public_key)?;
let profile_id = ProfileIdentifier::from_key_id(root_key_id);
if &profile_id != self.identifier() {
return deny();
}
allow()
}
pub fn verify_and_update<C: AsRef<[ProfileChangeEvent]>>(
&mut self,
change_events: C,
vault: &mut impl ProfileVault,
) -> ockam_core::Result<bool> {
if !ProfileChangeHistory::check_consistency(self.change_events(), change_events.as_ref()) {
return deny();
}
for event in change_events.as_ref().iter() {
if !ProfileChangeHistory::verify_event(self.change_events(), event, vault)? {
return deny();
}
self.change_history.push_event(event.clone());
}
allow()
}
}
impl Contact {
pub fn get_profile_update_public_key(&self) -> ockam_core::Result<PublicKey> {
ProfileChangeHistory::get_current_profile_update_public_key(self.change_events())
}
pub fn get_public_key(&self, key_attributes: &KeyAttributes) -> ockam_core::Result<PublicKey> {
self.change_history.get_public_key(key_attributes)
}
pub fn get_last_event_id(&self) -> ockam_core::Result<EventIdentifier> {
self.change_history.get_last_event_id()
}
pub fn get_signing_public_key(&self) -> ockam_core::Result<PublicKey> {
self.get_public_key(&KeyAttributes::new(Profile::CREDENTIALS_ISSUE.to_string()))
}
}