Skip to main content

Module accept

Module accept 

Source
Expand description

Which predicates a verifier accepts: the configuration that turns a well-formed VSC into a meaningful one.

A VSC whose signature and status verify is not thereby meaningful. DTG Core Credentials §Predicate Handling requires a verifier to reject a statement whose predicate is not in a vocabulary it has been configured to accept, and gives rejection as the only conforming outcome:

  • Exact match. A predicate is compared byte for byte with the IRIs configured here. There is no prefix, namespace or case-insensitive match.
  • No equivalence. An owl:sameAs, skos:exactMatch or similar assertion published by anyone is not followed. Whether two predicates are treated alike is a governance decision, and it is made by putting both in the list.
  • Never from the credential. The list is the verifier’s; nothing a credential carries adds to it.

A well-formed statement under an unrecognized predicate is the intended shape of an attack that names authority, membership or personhood in a string, so PredicateAcceptList::accept fails closed: anything it cannot positively accept is an error.

§Two ways to build one

  • PredicateAcceptList::from_iris, from a list of IRIs the verifier’s governance names.
  • PredicateAcceptList::from_registry_json, from the machine-readable accept-list.json the DTG VSC Predicate Registry publishes, keeping the entries whose status the verifier admits. Entries carry the profile’s machine-checkable constraints — permitted object kinds, whether taskContext is required, a minimum issuerScope, REQUIRED additional members — and accept applies them.

Structs§

AcceptListEntry
One predicate’s entry in the registry’s accept-list: its status and machine-checkable constraints.
AdditionalMember
An additional credentialSubject member a profile defines.
PredicateAcceptList
The predicates a verifier accepts. See the module docs.
RegistryAcceptList
The registry’s accept-list.json, per its meta/accept-list.schema.json.

Enums§

PredicateStatus
A predicate’s lifecycle status in the registry.