iya-sts
    Preparing search index...

    OpenID Federation 1.1 Trust Chains (4, 10) and the Trust Marks they carry (7.3): validating a chain, assembling one by walking authority_hints towards a configured Trust Anchor within bounds, and resolving the subject's metadata through it.

    Index
    • Builds an instance over what it depends on.

      Parameters

      • deps: TrustChainDeps

        the logger, the clock and its leeway, the walk's limits, the fetcher, and the lookup of an entity this process answers for itself

      Returns export=

    TYP: Readonly<
        {
            ENTITY_EVENTS_STATEMENT: "entity-events-statement+jwt";
            ENTITY_STATEMENT: "entity-statement+jwt";
            EXPLICIT_REGISTRATION_RESPONSE: "explicit-registration-response+jwt";
            JWK_SET: "jwk-set+jwt";
            RESOLVE_RESPONSE: "resolve-response+jwt";
            TRUST_MARK: "trust-mark+jwt";
            TRUST_MARK_DELEGATION: "trust-mark-delegation+jwt";
            TRUST_MARK_STATUS: "trust-mark-status-response+jwt";
        },
    > = EntityStatement.TYP

    The federation JWT typ values, EntityStatement.TYP.

    • Obtains an entity's Entity Configuration, verified by its own keys (9, 3.2): in process for this service's own realms, fetched otherwise, and answered from the walk's memory when already obtained.

      Parameters

      • entityId: string

        the Entity Identifier

      • walk: any

        the walk's state: what it has seen and fetched

      Returns Promise<any>

      a promise of the verified configuration, or of why it could not be obtained

    • Resolves an entity (10): walks to every configured Trust Anchor reachable, within the walk's bounds, validates each chain found and chooses the shortest valid one.

      Parameters

      • entityId: string

        the subject's Entity Identifier

      • anchors: TrustAnchor[]

        the Trust Anchors, possibly narrowed by the caller

      • Optionaloptions: any

        configuration (the subject's Entity Configuration handed over rather than fetched) and audience

      Returns Promise<Validated>

      a promise of the chosen chain, validated, or of why there was none

    • Obtains the Subordinate Statement a superior makes about an entity from the fetch endpoint its verified configuration names (8.1), verified by the superior's keys and checked for who it is from and about.

      Parameters

      • superior: any

        the superior's verified configuration

      • sub: string

        the subject's Entity Identifier

      • walk: any

        the walk's state

      Returns Promise<any>

      a promise of the verified statement, or of why it could not be obtained

    • Validates a Trust Chain (4, 10.2): every check of 10.2, then the constraints (6.2) and the subject's resolved metadata (6.1).

      Parameters

      • jwts: any

        the statements in chain order: the subject's Entity Configuration, the Subordinate Statements upwards, optionally the Trust Anchor's Entity Configuration

      • anchors: TrustAnchor[]

        the configured Trust Anchors

      • Optionaloptions: any

        audience: the OP an Explicit Registration request's first statement must name

      Returns Validated

      the chain's claims, its Trust Anchor, its expiry (the least exp) and the resolved metadata; or a refusal with its code

    • Validates a Trust Mark delegation (7.2.2) against the owner named for its type in the Trust Anchor's trust_mark_owners.

      Parameters

      • delegation: any

        the delegation JWT

      • mark: any

        the Trust Mark's claims

      • owner: any

        the owner's Entity Identifier and keys

      Returns Validated

      { ok: true }, or a refusal with its code

    • Validates a Trust Mark (7.3) presented in an entity's configuration, against the issuer's keys established through its own chain.

      Parameters

      • markJwt: any

        the Trust Mark JWT

      • subject: string

        the entity presenting it

      • anchorClaims: any

        the Trust Anchor's Entity Configuration claims

      • issuerJwks: any

        the issuer's Federation Entity Keys

      • federationTrusted: boolean

        also require the anchor to list the type and allow the issuer

      Returns Validated

      { ok, chain } holding the mark's claims, or a refusal with its code

    • Answers the service logger, for a caller building the dependencies.

      Returns any

      the logger