dpp_vc/lib.rs
1//! `dpp-vc` — the trust layer: who may read a passport, and how that is proven.
2//!
3//! W3C Verifiable Credentials, `did:web` documents, Bitstring Status List
4//! revocation, and the JSON-LD context those are expressed in.
5//!
6//! Pure (no I/O, no network). Not a `wasm32-unknown-unknown` target: it depends
7//! on [`dpp_crypto`], whose RNG requires a platform entropy source.
8//!
9//! # Trust, not primitives, and not policy
10//!
11//! Three neighbouring concerns are deliberately **not** here:
12//!
13//! - **Cryptographic primitives** — JWS, keys, the keystore — are
14//! [`dpp_crypto`], which this crate depends on. Signing bytes is a different
15//! job from deciding whose signature means what.
16//! - **The disclosure contract** — `Audience`, `Disclosure`, the per-field
17//! disclosure map and the filter that applies it — describes what a passport
18//! *is*, not who is asking. It lives in `dpp-domain`.
19//! - **Projections** — GS1, AAS — render a passport for an ecosystem. They say
20//! nothing about trust.
21//!
22//! The seam this crate sits on: **a credential establishes which `Audience` a
23//! caller holds; the disclosure policy maps that `Audience` to fields.** Those
24//! are two questions and they are answered in two places.
25
26pub mod credential;
27pub mod did_builder;
28pub mod jsonld;
29pub mod local_service;
30pub mod passport_credential;
31pub mod sd_jwt_vc;
32pub mod snapshot;
33pub mod status_list;
34
35#[cfg(test)]
36mod test_support;
37#[cfg(test)]
38mod tests;
39
40pub use credential::{
41 AllowAllIssuers, Audience, CredentialBuilder, CredentialRole, CredentialStatus,
42 DppAccessCredential, DppCredentialSubject, RevocationOutcome, StaticTrustedIssuers,
43 TrustedIssuerRegistry, VerificationResult, check_revocation, verify_credential_claims,
44 verify_credential_claims_with_trust, verify_credential_with_revocation,
45 verify_credential_with_revocation_and_trust,
46};
47pub use did_builder::build_did_document;
48pub use jsonld::{REMOTE_CONTEXTS, context_value, frame_passport, passport_context, strip_context};
49pub use local_service::LocalIdentityService;
50pub use passport_credential::{PassportCredential, PassportCredentialSubject};
51pub use sd_jwt_vc::{SdJwtVcError, TYP as SD_JWT_VC_TYP, build_issuer_metadata, vct_for};
52pub use snapshot::{CLOCK_SKEW_TOLERANCE, SnapshotBound, verify_snapshot_bound};
53pub use status_list::StatusList;
54
55/// Compile-checks this crate's README examples.
56///
57/// A README example is a public claim about the API, and nothing else in the
58/// build compiles one. Without this, a README can advertise a function that
59/// does not exist — which is exactly what happened before this harness landed.
60#[cfg(doctest)]
61#[doc = include_str!("../README.md")]
62struct ReadmeDoctests;