import type { InspectCapabilityChain, CapabilityInvocationOptions } from '@interop/zcap'; import type { IVerifier, IVerificationMethod, IZcap } from '@interop/data-integrity-core'; import type { IDocumentLoader } from '@interop/data-integrity-core/loader'; /** * A jsonld-signatures signature suite instance (or instances) used to verify * the capability delegation chain, e.g. `new Ed25519Signature2020()`. Derived * from `@interop/zcap`'s public option type, which carries the underlying * `LinkedDataProof` type from `@interop/jsonld-signatures` (a dependency this * library does not otherwise import). */ export type SignatureSuite = NonNullable; /** * An async function that dereferences a key id and returns a verifier and the * verification method document for that key. */ export type GetVerifier = (options: { keyId: string; documentLoader: IDocumentLoader; }) => Promise<{ verifier: IVerifier; verificationMethod: IVerificationMethod; }>; /** * @param options {object} - Options to use. * @param options.url {string} - The url of the request. Used as the invocation * target. An absolute URI (any scheme -- `https:`, `http:`, `did:`, `urn:`, * ...) is used verbatim; a relative url is resolved against the request host * as `https://${host}${url}`. * @param options.method {string} - The HTTP request method. * @param options.headers {object} - The headers from the request. * @param options.getVerifier {GetVerifier} - An async function to * call to get a verifier and verification method for the key ID. * @param options.documentLoader {IDocumentLoader} - A jsonld document loader; it * must be able to load the root zcap and any contexts used in the zcap * delegation chain. * @param options.expectedHost {string|string[]} - The expected host of the * request. * @param options.expectedAction {string} - The expected action of the zcap. * @param options.expectedRootCapability {string|string[]} - The expected root * capability of the zcap. * @param options.expectedTarget {string} - The expected target of the zcap. * @param options.suite {SignatureSuite} - The jsigs signature suite(s) for * verifying the capability delegation chain. * @param [options.allowTargetAttenuation=false] {boolean} - Allow the * invocationTarget of a delegation chain to be increasingly restrictive * based on a hierarchical RESTful URL structure. * @param [options.additionalHeaders=[]] {string[]} - Additional headers * to verify. * @param [options.beforeValidatePurpose] {Function} - A function that is * called prior to validating the proof purpose and is passed the purpose * instance, proof meta data, and capability information. * @param [options.inspectCapabilityChain] {Function} - A function that can * inspect a capability chain. * @param [options.maxChainLength] {number} - The maximum length of the * capability delegation chain. * @param [options.maxDelegationTtl] {number} - The maximum milliseconds to * live for a delegated zcap as measured by the time difference between * `expires` and `created` on the delegation proof. * @param [options.maxClockSkew=300] {number} - A maximum number of seconds * that clocks may be skewed when checking capability expiration date-times * against `date`, when comparing invocation proof creation time against * delegation proof creation time, and when comparing the capability * invocation expiration time against `now`. * @param [options.now=now] {number|Date} - A unix timestamp or an * instance of Date. */ export interface VerifyCapabilityInvocationOptions { url: string; method: string; headers: Record; getVerifier: GetVerifier; documentLoader: IDocumentLoader; expectedHost: string | string[]; expectedAction: string; expectedRootCapability: string | string[]; expectedTarget: string; suite: SignatureSuite; allowTargetAttenuation?: boolean; additionalHeaders?: string[]; beforeValidatePurpose?: (params: { purpose: unknown; proof: unknown; capability: string | IZcap; capabilityAction: unknown; }) => Promise | void; inspectCapabilityChain?: InspectCapabilityChain; maxChainLength?: number; maxClockSkew?: number; maxDelegationTtl?: number; now?: number | Date; } /** * The result of a capability invocation verification. */ export interface VerifyCapabilityInvocationResult { verified: boolean; error?: Error; capability?: string | IZcap; capabilityAction?: unknown; controller?: string; dereferencedChain?: IZcap[]; invoker?: string; verificationMethod?: IVerificationMethod; } /** * Decodes the embedded delegated capability carried by a * `Capability-Invocation` header's `capability` parameter -- the * `base64url(gzip(json))` wire form produced by * `@interop/http-signature-zcap-invoke`'s `signCapabilityInvocation`. * Exported so consumers can inspect a submitted capability chain without * running the full verification (e.g. to name a failure cause after * verification has already failed). * * @param options {object} - Options to use. * @param options.encoded {string} - The `capability` parameter value from a * parsed `Capability-Invocation` header. * * @returns {IZcap} The decoded capability. * @throws {Error} A `DataError`-named error when the value is improperly * encoded. */ export declare function decodeEmbeddedCapability({ encoded }: { encoded: string; }): IZcap; /** * Verifies a zcap invocation in the form of an http-signature header. * * @param options {VerifyCapabilityInvocationOptions} - Options to use. * * @returns {Promise} The result of the * verification. */ export declare function verifyCapabilityInvocation({ url, method, headers, getVerifier, documentLoader, expectedHost, expectedAction, expectedRootCapability, expectedTarget, suite, additionalHeaders, allowTargetAttenuation, beforeValidatePurpose, inspectCapabilityChain, maxChainLength, maxClockSkew, maxDelegationTtl, now }: VerifyCapabilityInvocationOptions): Promise; //# sourceMappingURL=index.d.ts.map