Static ReadonlyOPERATORSThe standard operators, in their order of application.
StaticapplyApplies a resolved policy to the whole metadata claim: every entity type
the metadata holds and the policy names. A type the metadata lacks is not
created.
the subject's metadata
the resolved policy
{ ok, metadata }, or a policy error
StaticapplyApplies a resolved policy to one entity type's metadata (6.1.4.2), each parameter's operators in their order of application.
the entity type
that type's metadata
the resolved policy for the type
{ ok, metadata } as a new object, or a policy error
StaticcheckChecks a chain's max_path_length and naming constraints (6.2).
the claim sets in chain order: the subject's Entity Configuration, then the Subordinate Statements up to the Trust Anchor's, optionally the Trust Anchor's Entity Configuration last
{ ok }, or a policy error with its code
StaticcombinationChecks the combination rules of one parameter policy (6.1.3.1), for a single statement's policy and a merged one alike.
the parameter policy's operators and their values
the problem, or '' when the combination is allowed
StaticconstraintsChecks that a constraints object is well formed; members this service does not understand are ignored (6.2).
the constraints
the problem, or '' when it is well formed
StatichostMatches a host against a naming constraint by RFC 5280 section 4.2.1.10's domain-name rule: a leading period matches any host below it, anything else that host exactly.
the host
the constraint
true when it matches
StatichostAnswers the host of an Entity Identifier, lower-cased.
the Entity Identifier
the host, or '' when it has none
StaticintersectionAnswers the intersection of two arrays as a set, in the first array's order.
the first array
the second
the intersection
StaticmergeMerges a subordinate's validated policy into the current one (6.1.4.1), checking the merged combinations again. Neither argument is changed.
the policy merged so far
the next statement's validated policy
{ ok, policy }, or a policy error with its code
StaticmergeMerges one operator's values by that operator's own rule.
the operator
the current value
the subordinate's value
{ ok, value }, or { ok: false, why }
StaticoperatorChecks one operator's configured value for its type (6.1.3).
the operator
its value
the problem, or '' when it is acceptable
StaticoverlayOverlays the Immediate Superior's metadata (3.1.1) on the subject's, for
the entity types the subject declares only.
the subject's metadata
the superior's metadata claim about it
the overlaid metadata
StaticresolveResolves a chain's policy (6.1.4.1): the critical operators gathered from every statement, then each policy validated and merged in order.
the Subordinate Statements' claims, most superior first
{ ok, policy }, empty when none carries one, or a policy error
StaticresolvedResolves the subject's metadata from a verified chain, in the order the
specification fixes: the superior's metadata, the entity-type constraint,
then the resolved policy.
the claim sets in chain order
{ ok, metadata }, or a policy error with its code
StaticsameAnswers whether two values are equal, whatever the order of their members.
one value
the other
true when they are equal
StaticstableSerialises a value with its keys sorted, as a stable key for equality; not a canonicalisation for a signature.
the value
the serialisation
StaticstripRemoves the entity types the chain's allowed_entity_types do not allow
(6.2.3); federation_entity always survives.
the subject's metadata
the claim sets in chain order
the metadata with only the allowed types
StaticsubsetAnswers whether every member of one array is in another, compared stably.
the array that may be the subset
the array that may hold it
true when every member is held
StaticunionAnswers the union of two arrays as a set, in the first array's order.
the first array
the second
the union
StaticvalidateValidates one statement's metadata_policy (6.1.2, 6.1.4.1).
Operators this service does not understand, and nobody made critical, are dropped from the answer; a critical one it does not understand is a policy error.
the statement's metadata_policy
the operators the chain declared critical
{ ok, policy }, or a policy error with its code
OpenID Federation 1.1 section 6: the seven standard metadata policy operators, validating, merging and applying policies down a chain, and the three constraints. A pure library of static methods: it fetches, signs and reads nothing.