Claims class
A CWT claims set with typed accessors for standard CWT (RFC 8392) and EAT (RFC 9711) claims.
Standard claims are exposed as typed properties, and setting one to null
removes it. Claims may be set in any order. Custom or application-specific
claims can be accessed via operator[] using their integer key. Claim
values must encode into the CBOR subset that the cbor library lists.
Custom claims read back from a token hold plain Dart values. Byte strings
come back as Uint8List, and integers as int, or as BigInt beyond its
range.
Applications must evaluate the EAT claims against their attestation policy
and enforce RFC 9711's relationships between claims. For example, hwmodel
and oemboot require oemid, hwversion requires hwmodel, and
swversion requires swname. DebugState.disabledPermanently also
requires oemid. These relationships are not checked by verify.
Constructors
- Claims()
- Creates an empty claims set.
Properties
- audience ↔ String?
-
Identifies the recipients the token is intended for (key 3), a URI or
any string the ecosystem agrees on.
getter/setter pair
- bootCount ↔ int?
-
The number of times the device has booted, a monotonic counter (key 267).
getter/setter pair
- bootSeed ↔ Uint8List?
-
A random value unique to the current boot cycle (key 268), the same in
every token of one boot cycle.
getter/setter pair
- debugStatus ↔ DebugState?
-
The state of the device's debug facilities at attestation time (key 263).
getter/setter pair
- expiration ↔ int?
-
The time on or after which the token must not be accepted (key 4), in
seconds since the Unix epoch.
getter/setter pair
- hashCode → int
-
The hash code for this object.
no setterinherited
- hwModel ↔ Uint8List?
-
The product or board model identifier (key 259), opaque bytes as the
manufacturer defines them.
getter/setter pair
- hwVersion ↔ String?
-
The hardware revision identifier (key 260).
getter/setter pair
- intendedUse ↔ IntendedUse?
-
The purpose the token was issued for (key 275).
getter/setter pair
- issuedAt ↔ int?
-
The time at which the token was issued (key 6), in seconds since the Unix
epoch.
getter/setter pair
- issuer ↔ String?
-
Identifies the principal that issued the token (key 1), a URI or any
string the ecosystem agrees on.
getter/setter pair
- notBefore ↔ int?
-
The time before which the token must not be accepted (key 5), in seconds
since the Unix epoch.
getter/setter pair
- oemBoot ↔ bool?
-
Whether every boot stage was OEM authorized, meaning secure boot passed
(key 262).
getter/setter pair
- oemid → Object?
-
Identifies the hardware manufacturer (key 258, RFC 9711 Section 4.2.3),
by a random ID, an IEEE OUI or an IANA PEN.
no setter
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- subject ↔ String?
-
Identifies the principal that is the subject of the token (key 2), for a
device its serial or attestation subject.
getter/setter pair
- swName ↔ String?
-
The name of the firmware or software running on the device (key 270).
getter/setter pair
- swVersion ↔ String?
-
The software version identifier (key 271).
getter/setter pair
- tokenId ↔ Uint8List?
-
A unique identifier for the token (key 7), opaque bytes unique per token.
getter/setter pair
- ueid ↔ Uint8List?
-
A globally unique device identifier such as a serial number or IMEI
(key 256).
getter/setter pair
- uptime ↔ int?
-
The number of seconds since the last boot (key 261).
getter/setter pair
Methods
-
getConfirmXdsa(
) → PublicKey? - Extracts the bound xDSA public key from the Confirm claim, or null if absent or a different key type.
-
getConfirmXhpke(
) → PublicKey? - Extracts the bound xHPKE public key from the Confirm claim, or null if absent or a different key type.
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
setConfirmXdsa(
PublicKey key) → void - Binds an xDSA public key to the token via the Confirm claim (key 8, RFC 8747), replacing any key bound before.
-
setConfirmXhpke(
PublicKey key) → void - Binds an xHPKE public key to the token via the Confirm claim (key 8, RFC 8747), replacing any key bound before.
-
setOemidIeee(
Uint8List id) → void - Sets OEMID to a 3-byte IEEE OUI/MA-L.
-
setOemidPen(
int pen) → void - Sets OEMID to an IANA Private Enterprise Number.
-
setOemidRandom(
Uint8List id) → void - Sets OEMID to a 16-byte random manufacturer identifier.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
-
operator [](
int key) → Object? - Gets a custom claim by its integer key, or null if absent.
-
operator []=(
int key, Object? value) → void -
Sets a custom claim by its integer key, or removes it if
valueis null.