Skip to main content

libid_contracts/bindings/
login.rs

1//! Bindings for the login stack: `Registry`, `WebWallet`, `WalletFactory`,
2//! `NotaryRegistry`, and the X ZK verifier. Mirrors
3//! `solidity/contracts/login/`.
4
5/// Bindings for `login/Registry.sol`.
6///
7/// `register_session` has many parameters by design (matching the Solidity
8/// contract interface), so the too_many_arguments lint is suppressed.
9#[allow(clippy::too_many_arguments, unused_attributes)]
10mod registry_inner {
11    use alloy::sol;
12
13    sol! {
14        #[sol(rpc)]
15        interface Registry {
16            #[derive(Debug, serde::Serialize, serde::Deserialize)]
17            struct FullTlsProof {
18                bytes notarySignature;
19                bytes backendSignature;
20                address userAddress;
21                address walletAddress;
22                bytes32 domainHash;
23                bytes32 clientRandom;
24                bytes32 serverRandom;
25                bytes serverEphemeralKey;
26                bytes32 transcriptRoot;
27                uint256 timestamp;
28                bytes32[] domainPath;
29                bytes32[] usernamePath;
30                bytes32[] endpointPath;
31                bytes32[] idPath;
32            }
33
34            function register_session(
35                FullTlsProof calldata proof,
36                string calldata domain,
37                string calldata username,
38                string calldata userId,
39                string calldata endpoint
40            ) external;
41
42            /// OIDC variant — caller provides ABI-encoded `UserProof` bytes
43            /// understood by the configured `IOidcVerifier` for `platform`.
44            function register_session_oidc(
45                string calldata platform,
46                bytes calldata oidcProof
47            ) external;
48
49            function register_session_zk(
50                string calldata platform,
51                bytes calldata zkProof
52            ) external;
53
54            function link_identity_zk(
55                string calldata platform,
56                bytes calldata zkProof
57            ) external;
58
59            function link_identity_oidc(
60                string calldata platform,
61                bytes calldata oidcProof,
62                address sessionAddr
63            ) external;
64
65            function linkIdentity(
66                string calldata platform,
67                string calldata handle,
68                string calldata userId,
69                FullTlsProof calldata proof,
70                string calldata endpoint
71            ) external;
72
73            function resolve(string calldata platform, string calldata handle) external view returns (address);
74            function resolveById(string calldata platform, string calldata id) external view returns (address);
75            function handleHint(string calldata platform, string calldata handle) external view returns (string memory);
76            function getHandles(address wallet) external view returns (string[] memory platforms, string[] memory handles);
77            function getCurrentHandles(address wallet) external view returns (string[] memory platforms, string[] memory handles);
78            function getUserIds(address wallet) external view returns (string[] memory platforms, string[] memory userIds);
79            function getPlatform(string calldata domain) external view returns (string memory endpoint, string memory handlePrefix);
80            function zkVerifierOf(string calldata domain) external view returns (address);
81            function oidcVerifierOf(string calldata platform) external view returns (address);
82            function notary() external view returns (address);
83            function backend() external view returns (address);
84            function walletFactory() external view returns (address);
85
86            event HandleRegistered(string platform, string handle, address indexed owner);
87            event SessionRegistered(string platform, string handle, address indexed wallet, address sessionAddr);
88            event IdentityLinked(string platform, string handle, address indexed wallet);
89            event HandleChanged(string platform, string userId, string handle);
90        }
91    }
92}
93
94pub use registry_inner::Registry;
95
96/// Owner/deploy-time surface of the Registry: `initialize` (ABI-encoded into
97/// the ERC1967 proxy init data) and configuration setters.
98#[allow(clippy::too_many_arguments, unused_attributes)]
99mod registry_admin_inner {
100    use alloy::sol;
101
102    sol! {
103        #[sol(rpc)]
104        interface IRegistryAdmin {
105            function initialize(address _notary, address _backend, address _walletFactory, address _owner) external;
106            function setPlatform(
107                string calldata domain,
108                string calldata endpoint,
109                string calldata handlePrefix,
110                string calldata idPrefix,
111                string calldata idSuffix
112            ) external;
113            function removePlatform(string calldata domain) external;
114            function setZkVerifier(string calldata domain, address verifier) external;
115            function setOidcVerifier(string calldata platform, address verifier) external;
116            function setNotary(address _notary) external;
117            function setBackend(address _backend) external;
118            function pause() external;
119            function unpause() external;
120        }
121    }
122}
123
124pub use registry_admin_inner::IRegistryAdmin;
125
126/// Bindings for `login/zk/XZkVerifier.sol`.
127///
128/// The Registry calls this verifier through `IZkSessionVerifier`; a consumer
129/// uses these bindings to ABI-encode `XProof` (the opaque payload it forwards
130/// on `register_session_zk(platform, bytes)`) and to verify proofs via
131/// `eth_call` in pre-flight.
132#[allow(clippy::too_many_arguments, unused_attributes)]
133mod x_zk_verifier_inner {
134    use alloy::sol;
135
136    sol! {
137        #[sol(rpc)]
138        interface XZkVerifier {
139            #[derive(Debug, serde::Serialize, serde::Deserialize)]
140            struct TokenAttestation {
141                bytes32 bearerHash;
142                uint32  bearerRangeStart;
143                uint32  bearerRangeEnd;
144                bytes   sentRevealed;
145                uint64  timestamp;
146                bytes   notarySignature;
147            }
148
149            #[derive(Debug, serde::Serialize, serde::Deserialize)]
150            struct MeAttestation {
151                bytes32 bearerHash;
152                uint32  bearerRangeStart;
153                uint32  bearerRangeEnd;
154                bytes   sentRevealed;
155                uint32  sentPrefixEnd;
156                uint32  sentSuffixEnd;
157                bytes   recvRevealed;
158                string  handle;
159                string  userId;
160                address sessionAddr;
161                uint64  timestamp;
162                bytes   notarySignature;
163            }
164
165            #[derive(Debug, serde::Serialize, serde::Deserialize)]
166            struct XProof {
167                bytes proof;
168                bytes32[] publicInputs;
169                TokenAttestation tokenAttest;
170                MeAttestation meAttest;
171            }
172
173            function initialize(
174                address _owner,
175                address _notary,
176                address _honkVerifier,
177                bytes calldata _xClientId,
178                string calldata _endpoint,
179                string calldata _handlePrefix,
180                string calldata _platformName
181            ) external;
182
183            function verifyAndExtract(bytes calldata payload)
184                external view
185                returns (
186                    string memory handle,
187                    address sessionKey,
188                    address walletAddress,
189                    uint256 expiresAt,
190                    bytes32 nullifier,
191                    string memory userId
192                );
193
194            function platformName() external view returns (string memory);
195            function notary() external view returns (address);
196
197            /// client_id allowlist. An EMPTY allowlist denies every client_id;
198            /// `openClientIds` is the explicit opt-in to accept any app.
199            function isClientIdAllowed(bytes32 clientIdHash) external view returns (bool);
200            function openClientIds() external view returns (bool);
201            function clientIdCount() external view returns (uint256);
202            function clientIdAt(uint256 index) external view returns (bytes memory);
203
204            function addClientId(bytes calldata _id) external;
205            function removeClientId(bytes calldata _id) external;
206            function setOpenClientIds(bool _open) external;
207
208            event ClientIdAdded(bytes clientId);
209            event ClientIdRemoved(bytes clientId);
210            event OpenClientIdsSet(bool open);
211        }
212    }
213}
214
215pub use x_zk_verifier_inner::XZkVerifier;
216
217/// Bindings for `login/WebWallet.sol`.
218#[allow(clippy::too_many_arguments, unused_attributes)]
219mod wallet_inner {
220    use alloy::sol;
221
222    sol! {
223        #[sol(rpc)]
224        interface WebWallet {
225            function threshold() external view returns (uint8);
226            function nonce() external view returns (uint256);
227            function registry() external view returns (address);
228            function factory() external view returns (address);
229            function identityCount() external view returns (uint256);
230            function identityAt(uint256 index) external view returns (bytes32);
231            function isIdentity(bytes32 identityHash) external view returns (bool);
232            function sessionCount(bytes32 platformHandleKey) external view returns (uint256);
233            function sessionAt(bytes32 platformHandleKey, uint256 index) external view returns (address);
234            function isSession(address addr) external view returns (bool);
235            function sessionIdentity(address addr) external view returns (bytes32);
236            function execute(
237                address target,
238                uint256 value,
239                bytes calldata data,
240                bytes[] calldata sigs
241            ) external;
242            function executeBatch(
243                address[] calldata targets,
244                uint256[] calldata values,
245                bytes[] calldata datas,
246                bytes[] calldata sigs
247            ) external;
248            function upgradeToLatest() external;
249            function setThreshold(uint8 newThreshold) external;
250
251            event SessionRegistered(string platform, string handle, address indexed sessionAddr);
252            event SessionRevoked(string platform, string handle, address indexed sessionAddr);
253            event Executed(address indexed target, uint256 value, uint256 nonce);
254            event NativeReceived(address indexed from, uint256 amount);
255            event NativeSent(address indexed to, uint256 amount);
256        }
257    }
258}
259
260pub use wallet_inner::WebWallet;
261
262/// Bindings for `login/WalletFactory.sol`.
263#[allow(clippy::too_many_arguments, unused_attributes)]
264mod factory_inner {
265    use alloy::sol;
266
267    sol! {
268        #[sol(rpc)]
269        interface WalletFactory {
270            function initialize(address owner_, address walletImpl_, address registry_) external;
271            function setRegistry(address newRegistry) external;
272            function latestImplementation() external view returns (address);
273            function upgradeWalletImplementation(address newImplementation) external;
274
275            event WalletCreated(address indexed wallet, bytes32 indexed firstIdentity);
276            event WalletImplementationUpgraded(address indexed newImplementation);
277        }
278    }
279}
280
281pub use factory_inner::WalletFactory;
282
283/// Bindings for `login/NotaryRegistry.sol`.
284#[allow(clippy::too_many_arguments, unused_attributes)]
285mod notary_registry_inner {
286    use alloy::sol;
287
288    sol! {
289        #[sol(rpc)]
290        interface NotaryRegistry {
291            function initialize(address owner_, address initialNotary) external;
292            function addNotary(address notary) external;
293            function removeNotary(address notary) external;
294
295            event NotaryAdded(address indexed notary);
296            event NotaryRemoved(address indexed notary);
297        }
298    }
299}
300
301pub use notary_registry_inner::NotaryRegistry;
302
303/// Minimal ERC-20 surface (transfer event scanning + balances).
304#[allow(clippy::too_many_arguments, unused_attributes)]
305mod erc20_inner {
306    use alloy::sol;
307
308    sol! {
309        #[sol(rpc)]
310        interface IERC20 {
311            function balanceOf(address account) external view returns (uint256);
312            function transfer(address to, uint256 value) external returns (bool);
313            function approve(address spender, uint256 value) external returns (bool);
314            function allowance(address owner, address spender) external view returns (uint256);
315
316            event Transfer(address indexed from, address indexed to, uint256 value);
317            event Approval(address indexed owner, address indexed spender, uint256 value);
318        }
319    }
320}
321
322pub use erc20_inner::IERC20;
323
324/// UltraHonk verifier interface — matches the `IHonkVerifier` the login and
325/// identity verifiers call. Used off-chain in pre-flight to bounce bogus proof
326/// bytes before paying gas. View call only; no state mutation.
327#[allow(clippy::too_many_arguments, unused_attributes)]
328mod honk_verifier_inner {
329    use alloy::sol;
330
331    sol! {
332        #[sol(rpc)]
333        interface IHonkVerifier {
334            function verify(bytes calldata proof, bytes32[] calldata publicInputs) external view returns (bool);
335        }
336    }
337}
338
339pub use honk_verifier_inner::IHonkVerifier;