Repository navigation
feat(delegation): scopes, signed payload formats and delegation chain evaluation - #1192
Conversation
|
@codex review |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9d4cbc4a6f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…sable validity dates
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b3bb33e451
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 574316556c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Description of change
PR 2 of 5 for company signing delegation:
@metastate-foundation/delegation, the pure logic every other piece uses. No I/O; callers inject record lookups and signature verification. Built as CommonJS likesignature-validator, so evault-core (CJS) and ESM packages can both import it.ontology:<uuid>or@<platform>:<keyword>; subset checks; core denylist (binding-document, Company, Shareholding, Role, Delegation, DelegatedSignature, and the reserved@w3dsnamespace for login/key/vault acts).w3ds-sign/v1payload: what a delegate signs for a company. The platform sends it as thew3ds://signsession and the eID wallet signs it unchanged. Canonical JSON, exactly one valid encoding, refuses core scopes, capped at 1024 chars.w3ds-grant/v1payload: what a director or re-delegator signs to authorise a Role/Delegation/Shareholding/Company record. It commits to the record by SHA-256, so it stays short.checkGrantAuthorizationverifies it.isReservedPayload: everyw3ds-string; login verifiers will reject these (PR 4).evaluateDelegation: walks a delegation up to its role; each link must be live, same company, narrowing, granted by the parent's delegate, from a parent that allows re-delegation; cycles and depth > 16 rejected. Returns effective scopes plus every link'sappLimits(apps must satisfy all, so a child can't loosen them).checkDelegatedSignature: a parsed payload against an evaluated chain (company, signer, delegation, scope).Whether a director was entitled to grant is checked at write time by the eVault (PR 3), not here.
Issue Number
Type of change
How the change has been tested
34 vitest cases: scope parsing/normalising/denylist, payload round-trip, order independence, tamper and non-canonical rejection, grant authorization mismatch and forged signature, chain acceptance (direct and re-delegated) and every rejection code. Built output imported from ESM;
sha256Hexchecked with no globalcrypto(Node 18 path).pnpm install --frozen-lockfilepasses with only the new importer added to the lockfile.Change checklist