Conversation
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
# Conflicts: # oid4vc/docker/Dockerfile
ruff format and 3 E501 line-length errors in mdoc/utils.py were failing the Lint plugins CI check prior to this PR's rebase. Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
The zrok demo path doesn't use ngrok; this was leftover from copy-pasting env.zrok.example from the ngrok .env.example. Signed-off-by: Micah Peltier <micah6_8@yahoo.com>
Contributor
|
@mepeltier as an FYI there will be a PR to add cbor support to the status list plugin. With both 18013-5 R2 IETF token status list will be covered. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds mDL/mdoc revocation support end-to-end — issuance with an embedded IETF status-list claim, status-list publishing/updates from the demo UI, and presentation-time status checking, and adds zrok as an alternative tunnel provider for the OID4VC demo (alongside the existing ngrok setup)
What's included
mDL/mdoc revocation
isomdl_mdoc_sign(mdoc/issuer.py) now accepts an optionalstatusclaim, embedded into the MSO at issuance time.mdoc/utils.pyadds status-list resolution/decoding: fetches the published IETF status-list JWT, decodes the bitstring, and returns the credential's current status (or a fail-closed error string if the check can't be completed).mdoc/cred_verifier.py/mdoc/pres_verifier.pywire status checking into presentation verification.zrok demo support
docker-compose-zrok.yaml+env.zrok.example— a zrok-based alternative to the ngrok demo stack, for environments where ngrok isn't viable (e.g. requires a paid plan for stable URLs).zrok-watchdog.shpolls the demo's public URL and restarts the share if it drops.docker/entrypoint.sh,auth_server/docker/entrypoint.sh, andfrontend/entrypoint.shnow skip ngrok tunnel-introspection when the relevant URL env vars (OID4VCI_ENDPOINT,TENANT_ISSUER_BASE_URL, etc.) are already set directly — existing ngrok setups are unaffected.AUTHSERVER_NGROK_URL→AUTHSERVER_PUBLIC_URLinternally (container-facing only);docker-compose.yamlmaps the existing host-sideAUTHSERVER_NGROK_URLvar to it, so no.envchanges are needed for existing ngrok users.Docker build — heads up for reviewers
This branch intentionally diverges from
main's currentoid4vc/docker/Dockerfile, which installs a prebuiltisomdl-uniffiwheel (v0.1.0-indicio.1). That wheel does not have status-claim support, which the revocation feature above depends on. This PR instead buildsisomdl-uniffifrom source against theIndicio-tech/isomdl-uniffi#feat/mso-status-claimbranch. This does result in slow build times and dependency on a mutable GitHub URL, rather than a stable release artifact. PRs are open inspruceid/isomdlandIndicio-tech/isomdl_uniffito add status-claim support in the upstream dependencies.Once
isomdl-unifficuts an official release wheel with status-claim support, this Dockerfile should revert to the wheel-install patternmaincurrently uses (which I plan on taking care of before merging this PR, assuming those PRs get merged quickly enough). Left aNOTEcomment in the Dockerfile itself as a pointer for whoever does that, if I don't have a chance to.Separately,
.github/workflows/pr-linting-and-unit-tests.yamlstill installs the oldv0.1.0-indicio.1wheel for unit tests (unchanged by this PR) — fine today since no unit test exercises the newstatusparameter directly, but worth knowing if that changes.Testing
ruff check .andruff format --check .pass.poetry run pytest— 45 passed.Requests for Feedback
General feedback for the PR as a whole is appreciated, but here are some specific items that I'd appreciate feedback on:
ngrokdemo setupzrokdemo instructions