Builds an instance over what it depends on.
the logger, the clock and its leeway, the walk's limits, the fetcher, and the lookup of an entity this process answers for itself
Static ReadonlyTYPThe federation JWT typ values, EntityStatement.TYP.
Obtains an entity's Entity Configuration, verified by its own keys (9, 3.2): in process for this service's own realms, fetched otherwise, and answered from the walk's memory when already obtained.
the Entity Identifier
the walk's state: what it has seen and fetched
a promise of the verified configuration, or of why it could not be obtained
Resolves an entity (10): walks to every configured Trust Anchor reachable, within the walk's bounds, validates each chain found and chooses the shortest valid one.
the subject's Entity Identifier
the Trust Anchors, possibly narrowed by the caller
Optionaloptions: any
configuration (the subject's Entity Configuration handed
over rather than fetched) and audience
a promise of the chosen chain, validated, or of why there was none
Obtains the Subordinate Statement a superior makes about an entity from the fetch endpoint its verified configuration names (8.1), verified by the superior's keys and checked for who it is from and about.
the superior's verified configuration
the subject's Entity Identifier
the walk's state
a promise of the verified statement, or of why it could not be obtained
Validates a Trust Chain (4, 10.2): every check of 10.2, then the constraints (6.2) and the subject's resolved metadata (6.1).
the statements in chain order: the subject's Entity Configuration, the Subordinate Statements upwards, optionally the Trust Anchor's Entity Configuration
the configured Trust Anchors
Optionaloptions: any
audience: the OP an Explicit Registration request's
first statement must name
the chain's claims, its Trust Anchor, its expiry (the least exp)
and the resolved metadata; or a refusal with its code
Validates a Trust Mark delegation (7.2.2) against the owner named for its
type in the Trust Anchor's trust_mark_owners.
the delegation JWT
the Trust Mark's claims
the owner's Entity Identifier and keys
{ ok: true }, or a refusal with its code
Validates a Trust Mark (7.3) presented in an entity's configuration, against the issuer's keys established through its own chain.
the Trust Mark JWT
the entity presenting it
the Trust Anchor's Entity Configuration claims
the issuer's Federation Entity Keys
also require the anchor to list the type and allow the issuer
{ ok, chain } holding the mark's claims, or a refusal with its
code
StaticdefaultAnswers the service logger, for a caller building the dependencies.
the logger
OpenID Federation 1.1 Trust Chains (4, 10) and the Trust Marks they carry (7.3): validating a chain, assembling one by walking
authority_hintstowards a configured Trust Anchor within bounds, and resolving the subject's metadata through it.