Skip to content

feat(delegation): scopes, signed payload formats and delegation chain evaluation - #1192

Merged
coodos merged 3 commits into
mainfrom
feat/delegation-package
Oct 8, 2026
Merged

coodos merged 3 commits into
mainfrom
feat/delegation-package

Conversation

@coodos

@coodos coodos commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Description of change

PR 2 of 5 for company signing delegation: @metastate-foundation/delegation, the pure logic every other piece uses. No I/O; callers inject record lookups and signature verification. Built as CommonJS like signature-validator, so evault-core (CJS) and ESM packages can both import it.

  • Scopes: ontology:<uuid> or @<platform>:<keyword>; subset checks; core denylist (binding-document, Company, Shareholding, Role, Delegation, DelegatedSignature, and the reserved @w3ds namespace for login/key/vault acts).
  • w3ds-sign/v1 payload: what a delegate signs for a company. The platform sends it as the w3ds://sign session and the eID wallet signs it unchanged. Canonical JSON, exactly one valid encoding, refuses core scopes, capped at 1024 chars.
  • w3ds-grant/v1 payload: what a director or re-delegator signs to authorise a Role/Delegation/Shareholding/Company record. It commits to the record by SHA-256, so it stays short. checkGrantAuthorization verifies it.
  • isReservedPayload: every w3ds- string; login verifiers will reject these (PR 4).
  • evaluateDelegation: walks a delegation up to its role; each link must be live, same company, narrowing, granted by the parent's delegate, from a parent that allows re-delegation; cycles and depth > 16 rejected. Returns effective scopes plus every link's appLimits (apps must satisfy all, so a child can't loosen them).
  • checkDelegatedSignature: a parsed payload against an evaluated chain (company, signer, delegation, scope).

Whether a director was entitled to grant is checked at write time by the eVault (PR 3), not here.

Issue Number

Type of change

  • New (a change which implements a new feature)

How the change has been tested

34 vitest cases: scope parsing/normalising/denylist, payload round-trip, order independence, tamper and non-canonical rejection, grant authorization mismatch and forged signature, chain acceptance (direct and re-delegated) and every rejection code. Built output imported from ESM; sha256Hex checked with no global crypto (Node 18 path). pnpm install --frozen-lockfile passes with only the new importer added to the lockfile.

Change checklist

  • I have ensured that the CI Checks pass locally
  • I have removed any unnecessary logic
  • My code is well documented
  • I have signed my commits
  • My code follows the pattern of the application
  • I have self reviewed my code

@coodos

coodos commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 786c3066-0f7e-438f-83c7-96e75fbdedf6
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T16:29:24.703680Z 5743165 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9d4cbc4a6f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/canonical.ts
Comment thread packages/delegation/src/payloads.ts
Comment thread packages/delegation/src/chain.ts Outdated
Comment thread packages/delegation/src/scopes.ts
@coodos

coodos commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b3bb33e451

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/chain.ts
Comment thread packages/delegation/src/payloads.ts
Comment thread packages/delegation/src/scopes.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 574316556c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread packages/delegation/src/payloads.ts
@coodos
coodos merged commit 9da091c into main Oct 8, 2026
6 checks passed
@coodos
coodos deleted the feat/delegation-package branch October 8, 2026 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant