Expand description
Which predicates a verifier accepts: the configuration that turns a well-formed VSC into a meaningful one.
A VSC whose signature and status verify is not thereby meaningful. DTG Core Credentials §Predicate Handling requires a verifier to reject a statement whose predicate is not in a vocabulary it has been configured to accept, and gives rejection as the only conforming outcome:
- Exact match. A predicate is compared byte for byte with the IRIs configured here. There is no prefix, namespace or case-insensitive match.
- No equivalence. An
owl:sameAs,skos:exactMatchor similar assertion published by anyone is not followed. Whether two predicates are treated alike is a governance decision, and it is made by putting both in the list. - Never from the credential. The list is the verifier’s; nothing a credential carries adds to it.
A well-formed statement under an unrecognized predicate is the intended shape of an attack that names authority, membership or personhood in a string, so PredicateAcceptList::accept fails closed: anything it cannot positively accept is an error.
§Two ways to build one
- PredicateAcceptList::from_iris, from a list of IRIs the verifier’s governance names.
- PredicateAcceptList::from_registry_json, from the machine-readable
accept-list.jsonthe DTG VSC Predicate Registry publishes, keeping the entries whose status the verifier admits. Entries carry the profile’s machine-checkable constraints — permittedobjectkinds, whethertaskContextis required, a minimumissuerScope, REQUIRED additional members — andacceptapplies them.
Structs§
- Accept
List Entry - One predicate’s entry in the registry’s accept-list: its status and machine-checkable constraints.
- Additional
Member - An additional
credentialSubjectmember a profile defines. - Predicate
Accept List - The predicates a verifier accepts. See the module docs.
- Registry
Accept List - The registry’s
accept-list.json, per itsmeta/accept-list.schema.json.
Enums§
- Predicate
Status - A predicate’s lifecycle status in the registry.