iya-sts
    Preparing search index...

    OpenID Federation 1.1 section 6: the seven standard metadata policy operators, validating, merging and applying policies down a chain, and the three constraints. A pure library of static methods: it fetches, signs and reads nothing.

    Index
    OPERATORS: readonly string[] = OPERATORS

    The standard operators, in their order of application.

    • Applies a resolved policy to the whole metadata claim: every entity type the metadata holds and the policy names. A type the metadata lacks is not created.

      Parameters

      • metadata: any

        the subject's metadata

      • policy: any

        the resolved policy

      Returns Outcome

      { ok, metadata }, or a policy error

    • Applies a resolved policy to one entity type's metadata (6.1.4.2), each parameter's operators in their order of application.

      Parameters

      • type: string

        the entity type

      • metadata: any

        that type's metadata

      • policy: any

        the resolved policy for the type

      Returns Outcome

      { ok, metadata } as a new object, or a policy error

    • Checks a chain's max_path_length and naming constraints (6.2).

      Parameters

      • chain: any[]

        the claim sets in chain order: the subject's Entity Configuration, then the Subordinate Statements up to the Trust Anchor's, optionally the Trust Anchor's Entity Configuration last

      Returns Outcome

      { ok }, or a policy error with its code

    • Checks the combination rules of one parameter policy (6.1.3.1), for a single statement's policy and a merged one alike.

      Parameters

      • ops: any

        the parameter policy's operators and their values

      Returns string

      the problem, or '' when the combination is allowed

    • Checks that a constraints object is well formed; members this service does not understand are ignored (6.2).

      Parameters

      • constraints: any

        the constraints

      Returns string

      the problem, or '' when it is well formed

    • Matches a host against a naming constraint by RFC 5280 section 4.2.1.10's domain-name rule: a leading period matches any host below it, anything else that host exactly.

      Parameters

      • host: string

        the host

      • constraint: string

        the constraint

      Returns boolean

      true when it matches

    • Answers the host of an Entity Identifier, lower-cased.

      Parameters

      • entityId: string

        the Entity Identifier

      Returns string

      the host, or '' when it has none

    • Answers the intersection of two arrays as a set, in the first array's order.

      Parameters

      • a: any[]

        the first array

      • b: any[]

        the second

      Returns any[]

      the intersection

    • Merges a subordinate's validated policy into the current one (6.1.4.1), checking the merged combinations again. Neither argument is changed.

      Parameters

      • current: any

        the policy merged so far

      • next: any

        the next statement's validated policy

      Returns Outcome

      { ok, policy }, or a policy error with its code

    • Merges one operator's values by that operator's own rule.

      Parameters

      • op: string

        the operator

      • a: any

        the current value

      • b: any

        the subordinate's value

      Returns { ok: boolean; value?: any; why?: string }

      { ok, value }, or { ok: false, why }

    • Checks one operator's configured value for its type (6.1.3).

      Parameters

      • op: string

        the operator

      • v: any

        its value

      Returns string

      the problem, or '' when it is acceptable

    • Overlays the Immediate Superior's metadata (3.1.1) on the subject's, for the entity types the subject declares only.

      Parameters

      • metadata: any

        the subject's metadata

      • superior: any

        the superior's metadata claim about it

      Returns any

      the overlaid metadata

    • Resolves a chain's policy (6.1.4.1): the critical operators gathered from every statement, then each policy validated and merged in order.

      Parameters

      • statements: any[]

        the Subordinate Statements' claims, most superior first

      Returns Outcome

      { ok, policy }, empty when none carries one, or a policy error

    • Resolves the subject's metadata from a verified chain, in the order the specification fixes: the superior's metadata, the entity-type constraint, then the resolved policy.

      Parameters

      • chain: any[]

        the claim sets in chain order

      Returns Outcome

      { ok, metadata }, or a policy error with its code

    • Answers whether two values are equal, whatever the order of their members.

      Parameters

      • a: any

        one value

      • b: any

        the other

      Returns boolean

      true when they are equal

    • Serialises a value with its keys sorted, as a stable key for equality; not a canonicalisation for a signature.

      Parameters

      • value: any

        the value

      Returns string

      the serialisation

    • Removes the entity types the chain's allowed_entity_types do not allow (6.2.3); federation_entity always survives.

      Parameters

      • metadata: any

        the subject's metadata

      • chain: any[]

        the claim sets in chain order

      Returns any

      the metadata with only the allowed types

    • Answers whether every member of one array is in another, compared stably.

      Parameters

      • small: any[]

        the array that may be the subset

      • big: any[]

        the array that may hold it

      Returns boolean

      true when every member is held

    • Answers the union of two arrays as a set, in the first array's order.

      Parameters

      • a: any[]

        the first array

      • b: any[]

        the second

      Returns any[]

      the union

    • Validates one statement's metadata_policy (6.1.2, 6.1.4.1).

      Operators this service does not understand, and nobody made critical, are dropped from the answer; a critical one it does not understand is a policy error.

      Parameters

      • policy: any

        the statement's metadata_policy

      • critical: string[]

        the operators the chain declared critical

      Returns Outcome

      { ok, policy }, or a policy error with its code