pub struct PredicateAcceptList { /* private fields */ }Expand description
The predicates a verifier accepts. See the module docs.
Implementations§
Source§impl PredicateAcceptList
impl PredicateAcceptList
Sourcepub fn from_iris<I, S>(iris: I) -> Result<Self, DTGCredentialError>
pub fn from_iris<I, S>(iris: I) -> Result<Self, DTGCredentialError>
An accept-list naming exactly these predicate IRIs.
No constraints beyond the match are attached, but a statement under a core predicate (crate::WITNESSED_V1 and the others) is still held to its profile, because that is checked whenever a VSC is parsed or validated.
§Errors
DTGCredentialError::InvalidPredicate for an entry that is not an absolute NFC IRI: a list containing one could never match a well-formed statement, and is more likely a configuration mistake than an intent.
Sourcepub fn from_registry(
list: &RegistryAcceptList,
statuses: &[PredicateStatus],
) -> Result<Self, DTGCredentialError>
pub fn from_registry( list: &RegistryAcceptList, statuses: &[PredicateStatus], ) -> Result<Self, DTGCredentialError>
An accept-list of the registry entries whose status is one of statuses, each
carrying its constraints.
statuses is the verifier’s floor, stated explicitly — &[Candidate, Standard] for
the registry’s recommended default. An empty slice accepts nothing.
§Errors
DTGCredentialError::InvalidPredicate for a key that is not an absolute NFC IRI.
Sourcepub fn from_registry_json(
json: &str,
statuses: &[PredicateStatus],
) -> Result<Self, DTGCredentialError>
pub fn from_registry_json( json: &str, statuses: &[PredicateStatus], ) -> Result<Self, DTGCredentialError>
PredicateAcceptList::from_registry over the registry’s accept-list.json text.
§Errors
DTGCredentialError::MalformedAcceptList if the document does not have the registry’s shape — including a member this library does not know — and the errors of PredicateAcceptList::from_registry.
Sourcepub fn contains(&self, predicate: &str) -> bool
pub fn contains(&self, predicate: &str) -> bool
Is predicate accepted, by exact byte comparison?
Sourcepub fn entry(&self, predicate: &str) -> Option<&AcceptListEntry>
pub fn entry(&self, predicate: &str) -> Option<&AcceptListEntry>
The registry constraints attached to predicate, if it is accepted and the list was
built from the registry.
Sourcepub fn accept<'a>(
&self,
vsc: &'a DTGCredential,
) -> Result<&'a str, DTGCredentialError>
pub fn accept<'a>( &self, vsc: &'a DTGCredential, ) -> Result<&'a str, DTGCredentialError>
Accepts vsc or says why not, failing closed. Returns the accepted predicate.
In order:
vscmust be aStatementCredential, else DTGCredentialError::WrongCredentialType.- It must pass DTGCredential::validate — well-formed predicate, the core profile where there is one, the window’s ordering and the JSON depth bound.
- Its
predicatemust be in this list, byte for byte, else DTGCredentialError::PredicateNotAccepted. - Where the entry carries registry constraints, they must hold: the
objectkind (DTGCredentialError::ProfileViolation),taskContextandtaskDigestMultibase(DTGCredentialError::MissingTaskContext, DTGCredentialError::MissingTaskDigest), the minimumissuerScope(DTGCredentialError::IssuerScopeTooNarrow) and every REQUIRED additional member (DTGCredentialError::ProfileViolation).
§What this does not check
The proof, whether the window contains the present instant, revocation, whether the issuer is one the verifier trusts for this predicate, and any subject–object rule needing the credential the object names — DTGCredential::witnesses_issuance_of and DTGCredential::witnesses_presentation_of are those. Nor does acceptance widen what a statement means: a VSC attests and never establishes, and a verifier MUST NOT draw a conclusion its profile does not state.