Skip to main content

libid_contracts/bindings/
login.rs

1//! Bindings for the login stack: `Registry`, `WebWallet`, `WalletFactory`,
2//! and the X ZK verifier. Mirrors `solidity/contracts/login/`.
3
4/// Bindings for `login/Registry.sol`.
5///
6/// `register_session` has many parameters by design (matching the Solidity
7/// contract interface), so the too_many_arguments lint is suppressed.
8#[allow(clippy::too_many_arguments, unused_attributes)]
9mod registry_inner {
10    use alloy::sol;
11
12    sol! {
13        #[sol(rpc)]
14        interface Registry {
15            #[derive(Debug, serde::Serialize, serde::Deserialize)]
16            struct FullTlsProof {
17                bytes notarySignature;
18                bytes backendSignature;
19                address userAddress;
20                address walletAddress;
21                bytes32 domainHash;
22                bytes32 clientRandom;
23                bytes32 serverRandom;
24                bytes serverEphemeralKey;
25                bytes32 transcriptRoot;
26                uint256 timestamp;
27                bytes32[] domainPath;
28                bytes32[] usernamePath;
29                bytes32[] endpointPath;
30                bytes32[] idPath;
31            }
32
33            function register_session(
34                FullTlsProof calldata proof,
35                string calldata domain,
36                string calldata username,
37                string calldata userId,
38                string calldata endpoint
39            ) external;
40
41            /// OIDC variant — caller provides ABI-encoded `UserProof` bytes
42            /// understood by the configured `IOidcVerifier` for `platform`.
43            function register_session_oidc(
44                string calldata platform,
45                bytes calldata oidcProof
46            ) external;
47
48            function register_session_zk(
49                string calldata platform,
50                bytes calldata zkProof
51            ) external;
52
53            function link_identity_zk(
54                string calldata platform,
55                bytes calldata zkProof
56            ) external;
57
58            function link_identity_oidc(
59                string calldata platform,
60                bytes calldata oidcProof,
61                address sessionAddr
62            ) external;
63
64            function linkIdentity(
65                string calldata platform,
66                string calldata handle,
67                string calldata userId,
68                FullTlsProof calldata proof,
69                string calldata endpoint
70            ) external;
71
72            function resolve(string calldata platform, string calldata handle) external view returns (address);
73            function resolveById(string calldata platform, string calldata id) external view returns (address);
74            function handleHint(string calldata platform, string calldata handle) external view returns (string memory);
75            function getHandles(address wallet) external view returns (string[] memory platforms, string[] memory handles);
76            function getCurrentHandles(address wallet) external view returns (string[] memory platforms, string[] memory handles);
77            function getUserIds(address wallet) external view returns (string[] memory platforms, string[] memory userIds);
78            function getPlatform(string calldata domain) external view returns (string memory endpoint, string memory handlePrefix);
79            function zkVerifierOf(string calldata domain) external view returns (address);
80            function oidcVerifierOf(string calldata platform) external view returns (address);
81            /// The shared Notary contract the Registry routes attestation checks through.
82            function notaryContract() external view returns (address);
83            /// The current notary signer, read through the Notary contract.
84            function notary() external view returns (address);
85            function backend() external view returns (address);
86            function walletFactory() external view returns (address);
87
88            event HandleRegistered(string platform, string handle, address indexed owner);
89            event SessionRegistered(string platform, string handle, address indexed wallet, address sessionAddr);
90            event IdentityLinked(string platform, string handle, address indexed wallet);
91            event HandleChanged(string platform, string userId, string handle);
92        }
93    }
94}
95
96pub use registry_inner::Registry;
97
98/// Owner/deploy-time surface of the Registry: `initialize` (ABI-encoded into
99/// the ERC1967 proxy init data) and configuration setters.
100#[allow(clippy::too_many_arguments, unused_attributes)]
101mod registry_admin_inner {
102    use alloy::sol;
103
104    sol! {
105        #[sol(rpc)]
106        interface IRegistryAdmin {
107            function initialize(address _notaryContract, address _backend, address _walletFactory, address _owner) external;
108            function setPlatform(
109                string calldata domain,
110                string calldata endpoint,
111                string calldata handlePrefix,
112                string calldata idPrefix,
113                string calldata idSuffix
114            ) external;
115            function removePlatform(string calldata domain) external;
116            function setZkVerifier(string calldata domain, address verifier) external;
117            function setOidcVerifier(string calldata platform, address verifier) external;
118            function setBackend(address _backend) external;
119            function pause() external;
120            function unpause() external;
121        }
122    }
123}
124
125pub use registry_admin_inner::IRegistryAdmin;
126
127/// Bindings for `login/zk/XZkVerifier.sol`.
128///
129/// The Registry calls this verifier through `IZkSessionVerifier`; a consumer
130/// uses these bindings to ABI-encode `XProof` (the opaque payload it forwards
131/// on `register_session_zk(platform, bytes)`) and to verify proofs via
132/// `eth_call` in pre-flight.
133#[allow(clippy::too_many_arguments, unused_attributes)]
134mod x_zk_verifier_inner {
135    use alloy::sol;
136
137    sol! {
138        #[sol(rpc)]
139        interface XZkVerifier {
140            #[derive(Debug, serde::Serialize, serde::Deserialize)]
141            struct TokenAttestation {
142                bytes32 bearerHash;
143                uint32  bearerRangeStart;
144                uint32  bearerRangeEnd;
145                bytes   sentRevealed;
146                uint64  timestamp;
147                bytes   notarySignature;
148            }
149
150            #[derive(Debug, serde::Serialize, serde::Deserialize)]
151            struct MeAttestation {
152                bytes32 bearerHash;
153                uint32  bearerRangeStart;
154                uint32  bearerRangeEnd;
155                bytes   sentRevealed;
156                uint32  sentPrefixEnd;
157                uint32  sentSuffixEnd;
158                bytes   recvRevealed;
159                string  handle;
160                string  userId;
161                address sessionAddr;
162                uint64  timestamp;
163                bytes   notarySignature;
164            }
165
166            #[derive(Debug, serde::Serialize, serde::Deserialize)]
167            struct XProof {
168                bytes proof;
169                bytes32[] publicInputs;
170                TokenAttestation tokenAttest;
171                MeAttestation meAttest;
172            }
173
174            function initialize(
175                address _owner,
176                address _notaryContract,
177                address _honkVerifier,
178                bytes calldata _xClientId,
179                string calldata _endpoint,
180                string calldata _handlePrefix,
181                string calldata _platformName
182            ) external;
183
184            function verifyAndExtract(bytes calldata payload)
185                external view
186                returns (
187                    string memory handle,
188                    address sessionKey,
189                    address walletAddress,
190                    uint256 expiresAt,
191                    bytes32 nullifier,
192                    string memory userId
193                );
194
195            function platformName() external view returns (string memory);
196            function notaryContract() external view returns (address);
197            function notary() external view returns (address);
198
199            /// client_id allowlist. An EMPTY allowlist denies every client_id;
200            /// `openClientIds` is the explicit opt-in to accept any app.
201            function isClientIdAllowed(bytes32 clientIdHash) external view returns (bool);
202            function openClientIds() external view returns (bool);
203            function clientIdCount() external view returns (uint256);
204            function clientIdAt(uint256 index) external view returns (bytes memory);
205
206            function addClientId(bytes calldata _id) external;
207            function removeClientId(bytes calldata _id) external;
208            function setOpenClientIds(bool _open) external;
209
210            event ClientIdAdded(bytes clientId);
211            event ClientIdRemoved(bytes clientId);
212            event OpenClientIdsSet(bool open);
213        }
214    }
215}
216
217pub use x_zk_verifier_inner::XZkVerifier;
218
219/// Bindings for `login/WebWallet.sol`.
220#[allow(clippy::too_many_arguments, unused_attributes)]
221mod wallet_inner {
222    use alloy::sol;
223
224    sol! {
225        #[sol(rpc)]
226        interface WebWallet {
227            function threshold() external view returns (uint8);
228            function nonce() external view returns (uint256);
229            function registry() external view returns (address);
230            function factory() external view returns (address);
231            function identityCount() external view returns (uint256);
232            function identityAt(uint256 index) external view returns (bytes32);
233            function isIdentity(bytes32 identityHash) external view returns (bool);
234            function sessionCount(bytes32 platformHandleKey) external view returns (uint256);
235            function sessionAt(bytes32 platformHandleKey, uint256 index) external view returns (address);
236            function isSession(address addr) external view returns (bool);
237            function sessionIdentity(address addr) external view returns (bytes32);
238            function execute(
239                address target,
240                uint256 value,
241                bytes calldata data,
242                bytes[] calldata sigs
243            ) external;
244            function executeBatch(
245                address[] calldata targets,
246                uint256[] calldata values,
247                bytes[] calldata datas,
248                bytes[] calldata sigs
249            ) external;
250            function upgradeToLatest() external;
251            function setThreshold(uint8 newThreshold) external;
252
253            event SessionRegistered(string platform, string handle, address indexed sessionAddr);
254            event SessionRevoked(string platform, string handle, address indexed sessionAddr);
255            event Executed(address indexed target, uint256 value, uint256 nonce);
256            event NativeReceived(address indexed from, uint256 amount);
257            event NativeSent(address indexed to, uint256 amount);
258        }
259    }
260}
261
262pub use wallet_inner::WebWallet;
263
264/// Bindings for `login/WalletFactory.sol`.
265#[allow(clippy::too_many_arguments, unused_attributes)]
266mod factory_inner {
267    use alloy::sol;
268
269    sol! {
270        #[sol(rpc)]
271        interface WalletFactory {
272            function initialize(address owner_, address walletImpl_, address registry_) external;
273            function setRegistry(address newRegistry) external;
274            function latestImplementation() external view returns (address);
275            function upgradeWalletImplementation(address newImplementation) external;
276
277            event WalletCreated(address indexed wallet, bytes32 indexed firstIdentity);
278            event WalletImplementationUpgraded(address indexed newImplementation);
279        }
280    }
281}
282
283pub use factory_inner::WalletFactory;
284
285/// Minimal ERC-20 surface (transfer event scanning + balances).
286#[allow(clippy::too_many_arguments, unused_attributes)]
287mod erc20_inner {
288    use alloy::sol;
289
290    sol! {
291        #[sol(rpc)]
292        interface IERC20 {
293            function balanceOf(address account) external view returns (uint256);
294            function transfer(address to, uint256 value) external returns (bool);
295            function approve(address spender, uint256 value) external returns (bool);
296            function allowance(address owner, address spender) external view returns (uint256);
297
298            event Transfer(address indexed from, address indexed to, uint256 value);
299            event Approval(address indexed owner, address indexed spender, uint256 value);
300        }
301    }
302}
303
304pub use erc20_inner::IERC20;
305
306/// UltraHonk verifier interface — matches the `IHonkVerifier` the login and
307/// identity verifiers call. Used off-chain in pre-flight to bounce bogus proof
308/// bytes before paying gas. View call only; no state mutation.
309#[allow(clippy::too_many_arguments, unused_attributes)]
310mod honk_verifier_inner {
311    use alloy::sol;
312
313    sol! {
314        #[sol(rpc)]
315        interface IHonkVerifier {
316            function verify(bytes calldata proof, bytes32[] calldata publicInputs) external view returns (bool);
317        }
318    }
319}
320
321pub use honk_verifier_inner::IHonkVerifier;