BoundedAuthorityProtocol. RoleAttestation. V1
(Bounded Authority Protocol v0.6.2)
Copy Markdown
View Source
Explicit entry point for the byte-distinct role-attestation profile (bap-role-attestation/1).
Summary
Functions
Assembles a role attestation at profile maxima.
Assembles a role attestation under caller bounds.
Builds the deterministic role-attestation signing input.
Boundedly decodes a role attestation without evaluating trust.
Verifies a role attestation against caller-supplied attestor trust, subject binding, and now.
Functions
@spec assemble_compact(BoundedAuthorityProtocol.V1.SigningInput.t(), binary()) :: {:ok, binary()} | {:error, :invalid}
Assembles a role attestation at profile maxima.
@spec assemble_compact( BoundedAuthorityProtocol.V1.SigningInput.t(), binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map() ) :: {:ok, binary()} | {:error, :invalid}
Assembles a role attestation under caller bounds.
@spec attestation_signing_input( BoundedAuthorityProtocol.RoleAttestation.V1.RoleAttestation.t(), BoundedAuthorityProtocol.V1.Bounds.t() | map() ) :: {:ok, BoundedAuthorityProtocol.V1.SigningInput.t()} | {:error, :invalid}
Builds the deterministic role-attestation signing input.
@spec decode_attestation(binary(), BoundedAuthorityProtocol.V1.Bounds.t() | map()) :: {:ok, BoundedAuthorityProtocol.RoleAttestation.V1.DecodedAttestation.t()} | {:error, :invalid}
Boundedly decodes a role attestation without evaluating trust.
@spec verify_attestation( binary(), BoundedAuthorityProtocol.RoleAttestation.V1.ExpectedAttestation.t() ) :: {:ok, BoundedAuthorityProtocol.RoleAttestation.V1.AttestationFacts.t()} | {:error, :invalid}
Verifies a role attestation against caller-supplied attestor trust, subject binding, and now.