Skip to main content

libid_contracts/bindings/
oidc.rs

1//! Bindings for the Google OIDC verifier
2//! (`solidity/contracts/login/oidc/GoogleOidcVerifier.sol`).
3
4/// The surface a deployer and a JWKS rotation listener need. Keep the struct
5/// fields in lockstep with the Solidity types.
6#[allow(clippy::too_many_arguments, unused_attributes)]
7mod inner {
8    use alloy::sol;
9
10    sol! {
11        #[sol(rpc)]
12        interface GoogleOidcVerifier {
13            #[derive(Debug, serde::Serialize, serde::Deserialize)]
14            struct NotarizedJwksProof {
15                bytes notarySignature;
16                bytes32 domainHash;
17                bytes32 clientRandom;
18                bytes32 serverRandom;
19                bytes serverEphemeralKey;
20                bytes32 transcriptRoot;
21                uint256 timestamp;
22                bytes32[] domainPath;
23                bytes32[] endpointPath;
24            }
25
26            #[derive(Debug, serde::Serialize, serde::Deserialize)]
27            struct JwkClaim {
28                bytes jwkBytes;
29                bytes32[] jwkPath;
30                bytes kid;
31                bytes nB64url;
32            }
33
34            /// `_verifier` is the deployed Honk circuit verifier
35            /// (`Verifier.sol:HonkVerifier`); `notaryContract_` is the shared
36            /// Notary contract; `initialAud` seeds the audience allowlist —
37            /// without it the verifier is fail-closed and rejects every proof.
38            function initialize(
39                address _verifier,
40                address _owner,
41                address notaryContract_,
42                string calldata initialAud
43            ) external;
44
45            function setExpectedAudience(string calldata clientId) external;
46            function setExpectedAudienceHash(bytes32 audienceHash) external;
47            function setRegistry(address r) external;
48
49            function modulusOfKid(bytes32 kidHash) external view returns (bytes32);
50            function expiresAtKid(bytes32 kidHash) external view returns (uint256);
51            function platformName() external view returns (string memory);
52            function notaryContract() external view returns (address);
53            function notary() external view returns (address);
54
55            function rotate(NotarizedJwksProof calldata proof, JwkClaim[] calldata claims) external;
56
57            event ModulusRotated(bytes32 indexed kidHash, string kid, bytes32 modulusHash, uint256 expiresAt);
58            event AudienceConfigured(bytes32 indexed audienceHash, string clientId);
59        }
60    }
61}
62
63pub use inner::GoogleOidcVerifier;