Package-level declarations

Types

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
interface CodeService

Provides generation and single-use validation of short-lived codes, e.g. authorization codes, pre-authorized codes, or issuer_state values.

Link copied to clipboard
class CredentialAuthorizationServiceStrategy @JvmOverloads constructor(credentialSchemes: Set<CredentialScheme>, mapper: CredentialSchemeMapper = DefaultCredentialSchemeMapper()) : AuthorizationServiceStrategy

Provide authentication and authorization for credential issuance.

Link copied to clipboard

Provides the actual data of the user as a credential that shall be issued

Link copied to clipboard
data class CredentialDataProviderInput(val userInfo: OidcUserInfoExtended, val subjectPublicKey: CryptoPublicKey, val credentialScheme: CredentialScheme, val credentialRepresentation: CredentialRepresentation)

Input for CredentialDataProviderFun to resolve the actual data of the user:

Link copied to clipboard
class CredentialIssuer @JvmOverloads constructor(statusListTokenResolver: StatusListTokenResolver? = null, authorizationService: OAuth2AuthorizationServerAdapter, issuer: Issuer, keyMaterial: Set<KeyMaterial> = setOf(issuer.keyMaterial), cryptoAlgorithms: Set<SignatureAlgorithm> = keyMaterial.map { it.signatureAlgorithm }.toSet(), credentialSchemes: Set<CredentialScheme>, publicContext: String = "https://wallet.a-sit.at/credential-issuer", credentialEndpointPath: String = "/credential", nonceEndpointPath: String = "/nonce", requireKeyAttestation: Boolean = false, proofValidator: ProofValidator = ProofValidator( publicContext = publicContext, requireKeyAttestation = requireKeyAttestation, statusListTokenResolver = statusListTokenResolver ), signMetadata: SignJwtFun<IssuerMetadata> = SignJwt(EphemeralKeyWithoutCert(), JwsHeaderCertOrJwk()), encryptionService: IssuerEncryptionService = IssuerEncryptionService(), credentialSchemeMapper: CredentialSchemeMapper = DefaultCredentialSchemeMapper(), preferredClientStatusPeriod: Duration? = 31.days, displayProperties: Set<DisplayProperties>? = null, clock: Clock = Clock.System)

Server implementation to issue credentials using OID4VCI.

Link copied to clipboard
class DefaultCodeService @JvmOverloads constructor(nonceService: NonceService = DefaultNonceService()) : CodeService

Holds valid codes in memory, delegating to nonceService, i.e. entries are protected with a mutex and expire after the lifetime of that service.

Link copied to clipboard
class IssuerEncryptionService @JvmOverloads constructor(encryptCredentialResponse: EncryptJweFun = EncryptJwe(), requireResponseEncryption: Boolean = false, supportedJweAlgorithms: Set<JweAlgorithm> = setOf(JweAlgorithm.ECDH_ES), supportedJweEncryptionAlgorithms: Set<JweEncryption> = setOf(JweEncryption.A256GCM), requireRequestEncryption: Boolean = false, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), decryptCredentialRequest: DecryptJweFun? = DecryptJwe(decryptionKeyMaterial))

Server implementation to handle credential request decryption and credential response encryption using OID4VCI.

Link copied to clipboard

Used in OID4VCI by CredentialIssuer to obtain user data when issuing credentials using OID4VCI.

Link copied to clipboard
@Serializable
data class OAuth2Error(val error: String, val errorDescription: String? = null, val errorUri: String? = null, val state: String? = null)

The OAuth 2.0 Authorization Framework: Error responses, see RFC 6749.

Link copied to clipboard
@Serializable
sealed class OAuth2Exception : Throwable

OAuth2/OIDC error representation for issuer and wallet flows. Use to model protocol errors and serialize them for responses.

Link copied to clipboard
object OAuth2ExceptionSerializer : JsonContentPolymorphicSerializer<OAuth2Exception>
Link copied to clipboard
fun interface OAuth2LoadUserFun

Interface used in at.asitplus.wallet.lib.oauth2.AuthorizationService to actually load user data during the OAuth 2.0 flow, after an authn request (see AuthenticationRequestParameters) has been validated.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Names and values of an application/x-www-form-urlencoded payload.

Link copied to clipboard
class ProofValidator @JvmOverloads constructor(publicContext: String = "https://wallet.a-sit.at/credential-issuer", verifyJwsObject: VerifyJwsObjectFun = VerifyJwsObject(), verifyJwsSignatureWithKey: VerifyJwsSignatureWithKeyFun = VerifyJwsSignatureWithKey(), supportedAlgorithms: Collection<JwsAlgorithm.Signature> = SimpleAuthorizationService.DEFAULT_WALLET_ATTESTATION_ALGORITHMS, clock: Clock = Clock.System, timeLeeway: Duration = 5.minutes, verifyAttestationProof: suspend (JwsCompactTyped<KeyAttestationJwt>) -> Boolean = { true }, requireKeyAttestation: Boolean = false, clientNonceService: NonceService = DefaultNonceService(), statusListTokenResolver: StatusListTokenResolver? = null, verifyKeyAttestationSignature: VerifyJwsObjectFun = VerifyJwsObjectFun { KmmResult.failure(IllegalStateException("No trusted key attestation verifier configured")) })

Server implementation to issue credentials using OID4VCI.

Link copied to clipboard
@Serializable
data class TokenInfo(val token: String, val authorizationDetails: Set<AuthorizationDetails>? = null, val scope: String? = null)

Internal data class for a token introspection result

Link copied to clipboard
class WalletEncryptionService @JvmOverloads constructor(requestResponseEncryption: Boolean = false, requireRequestEncryption: Boolean = false, encryptCredentialRequest: EncryptJweFun = EncryptJwe(), supportedJweAlgorithm: JweAlgorithm = JweAlgorithm.ECDH_ES, fallbackJweEncryptionAlgorithm: JweEncryption = JweEncryption.A256GCM, decryptionKeyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), ephemeralEncryptionKeyService: EphemeralEncryptionKeyService = EphemeralEncryptionKeyService(), decryptCredentialResponse: DecryptJweFun? = DecryptJweWithEphemeralKey(ephemeralEncryptionKeyService))

Wallet implementation to handle credential request encryption and credential response decryption using OID4VCI.

Link copied to clipboard
class WalletService @JvmOverloads constructor(val clientId: String = "https://wallet.a-sit.at/app", keyMaterial: KeyMaterial = EphemeralKeyWithoutCert(), remoteResourceRetriever: RemoteResourceRetrieverFunction = { null }, encryptionService: WalletEncryptionService = WalletEncryptionService(), loadKeyAttestation: suspend (WalletService.KeyAttestationInput) -> KmmResult<JwsCompactTyped<KeyAttestationJwt>>? = null, selectProofJwtKeyBinding: suspend (KeyMaterial) -> Pair<JsonWebKey?, String?> = { key -> Pair(key.jsonWebKey, null) })

Client service to retrieve credentials using OID4VCI

Properties

Link copied to clipboard

Json instance for FormParameters, lenient so that it can decode the unquoted values of URL query parameters.

Functions

Link copied to clipboard
inline fun <T> FormParameters.decode(): T
fun <T> FormParameters.decode(deserializer: DeserializationStrategy<T>): T
Link copied to clipboard
inline fun <T> String.decodeFromPostBody(): T

Deserializes the percent-encoded parameters of a POST body into T.

Link copied to clipboard
inline fun <T> String.decodeFromUrlQuery(): T

Deserializes a percent-encoded URL query into T.

Deserializes already-decoded FormParameters into T, decoding percent-encoding once more.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
fun SerialDescriptor.isStringElement(name: String): Boolean

Whether the member serialized as name is a string, for descriptors that have members at all.

Link copied to clipboard

Returns true if the other authorization detail is semantically the same, i.e., it has the same OpenIdAuthorizationDetails.credentialConfigurationId.

Link copied to clipboard

Empty strings can not be decoded by io.ktor.http.decodeURLQueryComponent, so we'll need to filter it.