mirror of
https://github.com/sonr-io/sonr.git
synced 2026-08-03 01:41:44 +00:00
* refactor: move constants to genesis.proto * feat: add ipfs_active flag to genesis state * feat: add IPFS connection initialization to keeper * feat: add testnet process-compose * refactor: rename sonr-testnet docker image to sonr-runner * refactor: update docker-vm-release workflow to use 'latest' tag * feat: add permission to workflows * feat: add new service chain execution * feat: add abstract vault class to pkl * feat: use jetpackio/devbox image for runner * feat: introduce dwn for local service worker * refactor: remove unnecessary dockerfile layers * refactor(deploy): Update Dockerfile to copy go.mod and go.sum from the parent directory * build: move Dockerfile to root directory * build: Add Dockerfile for deployment * feat: Update Dockerfile to work with Go project in parent directory * build: Update docker-compose.yaml to use relative paths * feat: Update docker-compose to work with new image and parent git directory * refactor: remove unnecessary test script * <no value> * feat: add test_node script for running node tests * feat: add IPFS cluster to testnet * feat: add docker image for sonr-runner * fix: typo in export path * feat(did): Add Localhost Registration Enabled Genesis Option * feat: add support for Sqlite DB in vault * feat: improve vault model JSON serialization * feat: support querying HTMX endpoint for DID * feat: Add primary key, unique, default, not null, auto increment, and foreign key field types * feat: Add PublicKey model in pkl/vault.pkl * feat: add frontend server * refactor: move dwn.wasm to vfs directory * feat(frontend): remove frontend server implementation * feat: Add a frontend server and web auth protocol * feat: implement new key types for MPC and ZK proofs * fix: Update enum types and DefaultKeyInfos * fix: correct typo in KeyAlgorithm enum * feat(did): add attestation format validation * feat: Add x/did/builder/extractor.go * feat: Update JWK parsing in x/did/builder/extractor.go * feat: Use github.com/onsonr/sonr/x/did/types package * feat: Extract and format public keys from WebAuthn credentials * feat: Introduce a new `mapToJWK` function to convert a map to a `types.JWK` struct * feat: add support for extracting JWK public keys * feat: remove VerificationMethod struct * refactor: extract public key extraction logic * feat: add helper functions to map COSECurveID to JWK curve names * feat: pin initial vault
115 lines
3.7 KiB
Go
115 lines
3.7 KiB
Go
package builder
|
|
|
|
import (
|
|
"bytes"
|
|
"encoding/base64"
|
|
"reflect"
|
|
)
|
|
|
|
type CredentialDescriptor struct {
|
|
// The valid credential types.
|
|
Type CredentialType `json:"type"`
|
|
|
|
// CredentialID The ID of a credential to allow/disallow.
|
|
CredentialID URLEncodedBase64 `json:"id"`
|
|
|
|
// The authenticator transports that can be used.
|
|
Transport []AuthenticatorTransport `json:"transports,omitempty"`
|
|
|
|
// The AttestationType from the Credential. Used internally only.
|
|
AttestationType string `json:"-"`
|
|
}
|
|
|
|
func NewCredentialDescriptor(credentialID string, transports []AuthenticatorTransport, attestationType string) *CredentialDescriptor {
|
|
return &CredentialDescriptor{
|
|
CredentialID: URLEncodedBase64(credentialID),
|
|
Transport: transports,
|
|
AttestationType: attestationType,
|
|
Type: CredentialTypePublicKeyCredential,
|
|
}
|
|
}
|
|
|
|
type AuthenticatorSelection struct {
|
|
// AuthenticatorAttachment If this member is present, eligible authenticators are filtered to only
|
|
// authenticators attached with the specified AuthenticatorAttachment enum.
|
|
AuthenticatorAttachment AuthenticatorAttachment `json:"authenticatorAttachment,omitempty"`
|
|
|
|
// RequireResidentKey this member describes the Relying Party's requirements regarding resident
|
|
// credentials. If the parameter is set to true, the authenticator MUST create a client-side-resident
|
|
// public key credential source when creating a public key credential.
|
|
RequireResidentKey *bool `json:"requireResidentKey,omitempty"`
|
|
|
|
// ResidentKey this member describes the Relying Party's requirements regarding resident
|
|
// credentials per Webauthn Level 2.
|
|
ResidentKey ResidentKeyRequirement `json:"residentKey,omitempty"`
|
|
|
|
// UserVerification This member describes the Relying Party's requirements regarding user verification for
|
|
// the create() operation. Eligible authenticators are filtered to only those capable of satisfying this
|
|
// requirement.
|
|
UserVerification UserVerificationRequirement `json:"userVerification,omitempty"`
|
|
}
|
|
|
|
type AuthenticatorData struct {
|
|
RPIDHash []byte `json:"rpid"`
|
|
Flags AuthenticatorFlags `json:"flags"`
|
|
Counter uint32 `json:"sign_count"`
|
|
AttData AttestedCredentialData `json:"att_data"`
|
|
ExtData []byte `json:"ext_data"`
|
|
}
|
|
|
|
type AttestationObject struct {
|
|
// The authenticator data, including the newly created public key. See AuthenticatorData for more info
|
|
AuthData AuthenticatorData
|
|
|
|
// The byteform version of the authenticator data, used in part for signature validation
|
|
RawAuthData []byte `json:"authData"`
|
|
|
|
// The format of the Attestation data.
|
|
Format string `json:"fmt"`
|
|
|
|
// The attestation statement data sent back if attestation is requested.
|
|
AttStatement map[string]any `json:"attStmt,omitempty"`
|
|
}
|
|
|
|
type URLEncodedBase64 []byte
|
|
|
|
func (e URLEncodedBase64) String() string {
|
|
return base64.RawURLEncoding.EncodeToString(e)
|
|
}
|
|
|
|
// UnmarshalJSON base64 decodes a URL-encoded value, storing the result in the
|
|
// provided byte slice.
|
|
func (e *URLEncodedBase64) UnmarshalJSON(data []byte) error {
|
|
if bytes.Equal(data, []byte("null")) {
|
|
return nil
|
|
}
|
|
|
|
// Trim the leading spaces.
|
|
data = bytes.Trim(data, "\"")
|
|
|
|
// Trim the trailing equal characters.
|
|
data = bytes.TrimRight(data, "=")
|
|
|
|
out := make([]byte, base64.RawURLEncoding.DecodedLen(len(data)))
|
|
|
|
n, err := base64.RawURLEncoding.Decode(out, data)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
v := reflect.ValueOf(e).Elem()
|
|
v.SetBytes(out[:n])
|
|
|
|
return nil
|
|
}
|
|
|
|
// MarshalJSON base64 encodes a non URL-encoded value, storing the result in the
|
|
// provided byte slice.
|
|
func (e URLEncodedBase64) MarshalJSON() ([]byte, error) {
|
|
if e == nil {
|
|
return []byte("null"), nil
|
|
}
|
|
|
|
return []byte(`"` + base64.RawURLEncoding.EncodeToString(e) + `"`), nil
|
|
}
|