Skip to main content

libid_contracts/bindings/
identity.rs

1//! Bindings for the identity-names stack (`solidity/contracts/identity/`):
2//! `IdentityNames`, the per-platform verifiers, and the Google JWKS trust
3//! list.
4
5/// Bindings for `identity/IdentityNames.sol`.
6///
7/// `Rules` mirrors `HandleNormalizer.Rules` — the normalization rules the
8/// contract stores per platform. Platform ids are `keccak256` of the
9/// platform's domain string.
10#[allow(clippy::too_many_arguments, unused_attributes)]
11mod names_inner {
12    use alloy::sol;
13
14    sol! {
15        #[sol(rpc)]
16        interface IdentityNames {
17            #[derive(Debug, serde::Serialize, serde::Deserialize)]
18            struct Rules {
19                uint16 maxLength;
20                bool stripLeadingAt;
21                bool isEmail;
22                bool allowUnderscore;
23                bool allowHyphen;
24            }
25
26            function initialize(address owner_) external;
27            function setPlatform(
28                bytes32 platformId,
29                address verifier,
30                uint64 maxFutureObservation,
31                Rules calldata rules
32            ) external;
33
34            function verifierOf(bytes32 platformId) external view returns (address);
35            function bind(bytes32 platformId, bytes calldata proof, bool publishName) external;
36            function unpublish(bytes32 platformId) external;
37            function resolveId(bytes32 platformId, string calldata userId) external view returns (address);
38            function resolveHandle(bytes32 platformId, string calldata handle) external view returns (address);
39            function resolvePair(bytes32 platformId, string calldata handle, string calldata userId) external view returns (address);
40            function reverseOf(address wallet, bytes32 platformId) external view returns (string memory);
41            function primaryOf(address wallet, bytes32 platformId) external view returns (string memory);
42
43            event HandleRetired(bytes32 indexed platformId, bytes32 indexed handleNode, address indexed owner);
44            event PlatformConfigured(bytes32 indexed platformId, address verifier);
45            event NameUnpublished(address indexed owner, bytes32 indexed platformId);
46        }
47    }
48}
49
50pub use names_inner::IdentityNames;
51
52/// The claim every identity verifier returns
53/// (`identity/IIdentityVerifier.sol`).
54#[allow(clippy::too_many_arguments, unused_attributes)]
55mod verifier_iface_inner {
56    use alloy::sol;
57
58    sol! {
59        #[sol(rpc)]
60        interface IIdentityVerifier {
61            #[derive(Debug, serde::Serialize, serde::Deserialize)]
62            struct IdentityClaim {
63                string userId;
64                string handle;
65                address target;
66                uint64 observedAt;
67            }
68
69            function verify(bytes calldata proof) external view returns (IdentityClaim memory claim);
70            function platformName() external view returns (string memory);
71        }
72    }
73}
74
75pub use verifier_iface_inner::IIdentityVerifier;
76
77/// Bindings for `identity/XIdentityVerifier.sol`.
78#[allow(clippy::too_many_arguments, unused_attributes)]
79mod x_verifier_inner {
80    use alloy::sol;
81
82    sol! {
83        #[sol(rpc)]
84        interface XIdentityVerifier {
85            #[derive(Debug, serde::Serialize, serde::Deserialize)]
86            struct MeAttestation {
87                bytes32 bearerHash;
88                uint32 bearerRangeStart;
89                uint32 bearerRangeEnd;
90                bytes sentRevealed;
91                uint32 sentPrefixEnd;
92                uint32 sentSuffixEnd;
93                bytes recvRevealed;
94                string handle;
95                string userId;
96                address sessionAddr;
97                uint64 timestamp;
98                bytes notarySignature;
99            }
100
101            #[derive(Debug, serde::Serialize, serde::Deserialize)]
102            struct XProof {
103                bytes proof;
104                bytes32[] publicInputs;
105                MeAttestation meAttest;
106            }
107
108            #[derive(Debug, serde::Serialize, serde::Deserialize)]
109            struct ResponseShape {
110                string platformName;
111                string endpoint;
112                string handlePrefix;
113                string idPrefix;
114                string idSuffix;
115            }
116
117            function initialize(
118                address owner_,
119                address notaryContract_,
120                address honkVerifier_,
121                ResponseShape calldata shape_
122            ) external;
123            function setHonkVerifier(address honkVerifier_) external;
124            function setResponseShape(ResponseShape calldata shape_) external;
125
126            function notaryContract() external view returns (address);
127            function notary() external view returns (address);
128            function platformName() external view returns (string memory);
129            function endpoint() external view returns (string memory);
130            function handlePrefix() external view returns (string memory);
131            function idPrefix() external view returns (string memory);
132            function idSuffix() external view returns (string memory);
133        }
134    }
135}
136
137pub use x_verifier_inner::XIdentityVerifier;
138
139/// Bindings for `identity/GitHubIdentityVerifier.sol`.
140#[allow(clippy::too_many_arguments, unused_attributes)]
141mod github_verifier_inner {
142    use alloy::sol;
143
144    sol! {
145        #[sol(rpc)]
146        interface GitHubIdentityVerifier {
147            #[derive(Debug, serde::Serialize, serde::Deserialize)]
148            struct FullTlsProof {
149                bytes notarySignature;
150                bytes backendSignature;
151                address userAddress;
152                address walletAddress;
153                bytes32 domainHash;
154                bytes32 clientRandom;
155                bytes32 serverRandom;
156                bytes serverEphemeralKey;
157                bytes32 transcriptRoot;
158                uint256 timestamp;
159                bytes32[] domainPath;
160                bytes32[] usernamePath;
161                bytes32[] endpointPath;
162                bytes32[] idPath;
163            }
164
165            /// The proof plus the strings it is checked against. A verifier
166            /// takes one `bytes` argument, so they travel together.
167            #[derive(Debug, serde::Serialize, serde::Deserialize)]
168            struct GitHubProof {
169                FullTlsProof tls;
170                string domain;
171                string handle;
172                string userId;
173                string endpoint;
174            }
175
176            #[derive(Debug, serde::Serialize, serde::Deserialize)]
177            struct ResponseShape {
178                string endpoint;
179                string handlePrefix;
180                string idPrefix;
181                string idSuffix;
182            }
183
184            function initialize(
185                address owner_,
186                address notaryContract_,
187                address backend_,
188                ResponseShape calldata shape_
189            ) external;
190            function setBackend(address backend_) external;
191            function setResponseShape(ResponseShape calldata shape_) external;
192
193            function notaryContract() external view returns (address);
194            function notary() external view returns (address);
195            function backend() external view returns (address);
196            function platformName() external view returns (string memory);
197        }
198    }
199}
200
201pub use github_verifier_inner::GitHubIdentityVerifier;
202
203/// Bindings for `identity/GoogleIdentityVerifier.sol`.
204#[allow(clippy::too_many_arguments, unused_attributes)]
205mod google_verifier_inner {
206    use alloy::sol;
207
208    sol! {
209        #[sol(rpc)]
210        interface GoogleIdentityVerifier {
211            /// One proof over a Google-signed id_token. Identity binds on
212            /// `sub` (the immutable Google account id).
213            #[derive(Debug, serde::Serialize, serde::Deserialize)]
214            struct UserProof {
215                bytes honkProof;
216                bytes32[] publicInputs;
217                string email;
218                address sessionKey;
219                string sub;
220            }
221
222            function initialize(address owner_, address honkVerifier_, address jwksRoots_) external;
223            function setTrust(address honkVerifier_, address jwksRoots_) external;
224
225            function honkVerifier() external view returns (address);
226            function jwksRoots() external view returns (address);
227            function platformName() external view returns (string memory);
228        }
229    }
230}
231
232pub use google_verifier_inner::GoogleIdentityVerifier;
233
234/// Bindings for `identity/IdentityJwksRoots.sol` — the naming system's own
235/// Google JWKS trust list. Starts EMPTY: Google names bind only once a
236/// notarized reading of Google's JWKS has landed here.
237#[allow(clippy::too_many_arguments, unused_attributes)]
238mod jwks_roots_inner {
239    use alloy::sol;
240
241    sol! {
242        #[sol(rpc)]
243        interface IdentityJwksRoots {
244            #[derive(Debug, serde::Serialize, serde::Deserialize)]
245            struct NotarizedJwksProof {
246                bytes notarySignature;
247                bytes32 domainHash;
248                bytes32 clientRandom;
249                bytes32 serverRandom;
250                bytes serverEphemeralKey;
251                bytes32 transcriptRoot;
252                uint256 timestamp;
253                bytes32[] domainPath;
254                bytes32[] endpointPath;
255            }
256
257            #[derive(Debug, serde::Serialize, serde::Deserialize)]
258            struct JwkClaim {
259                bytes jwkBytes;
260                bytes32[] jwkPath;
261                bytes kid;
262                bytes nB64url;
263            }
264
265            function initialize(address owner_, address notaryContract_) external;
266            function untrustModulus(bytes32 modulusHash) external;
267            function rotate(NotarizedJwksProof calldata proof, JwkClaim[] calldata claims) external;
268            function trustedHashExpiresAt(bytes32 modulusHash) external view returns (uint256);
269            function notaryContract() external view returns (address);
270            function notary() external view returns (address);
271
272            event ModulusRotated(bytes32 indexed kidHash, string kid, bytes32 modulusHash, uint256 expiresAt);
273            event ModulusUntrusted(bytes32 indexed modulusHash);
274        }
275    }
276}
277
278pub use jwks_roots_inner::IdentityJwksRoots;