Expand description
The libID ceremony profiles.
What each platform’s notarized sessions request, which host answers them,
and which bytes of the response a Platform Verifier reads. The values are
generated from solidity/contracts/ceremony/profiles.json, the same file
CeremonyProfile.sol is generated from, so a prover and the chain cannot
hold different copies.
§What is not here
Ids. platformId is keccak256 of Profile::platform and authorityId
is keccak256 of Session::authority, and this crate hashes neither: a
caller that needs an id already has a hasher, and a crate that pulled one
in to precompute six values would make every consumer carry it.
Behaviour. Which ranges a session reveals, how a handle normalizes, what a verifier checks – all hand written where they belong. This is the table those read.
Structs§
- Identity
Session - The identity session: the authenticated read that names the account.
- Profile
- One platform’s ceremony profile at one Platform Ceremony Version.
- Session
- One notarized session: which server, and which request.
- Token
Session - The token session: the OAuth exchange.
Enums§
- IdShape
- Which shape a platform’s immutable identifier takes in its response.
Constants§
- GITHUB
- A confidential client. The exchange runs in the deployment because the secret cannot reach the browser, and the two sessions are served by DIFFERENT hosts – which is why one pinned authority per profile would be wrong.
- Google’s evidence is a signed token checked against Google’s published keys, so the profile notarizes nothing: no session, no attestation, and no Notary Fee.
- LAUNCH
- The closed launch list. A platform outside it has no profile, and
CeremonyProfile.attestationCountreverts on one. - MAX_
FUTURE_ ATTESTATION_ SKEW_ SECONDS - Governance-owned launch parameters, in seconds.
- PROOF_
LIFETIME_ SECONDS_ GITHUB - PROOF_
LIFETIME_ SECONDS_ X - X
- A public client with S256 PKCE and two browser-owned sessions, both served by the same host.
Functions§
- launch
- The launch profile for a platform name, or nothing.