specs/auth/authenticate/v0_3/payload
library
Classes
-
Payload
-
The subject presents a previously-issued challenge along with the framework
proof
that binds the document to a VID. The proof IS the authentication. 0.3 adds an
optional proxied form: principal names a party the signer authenticates as,
distinct from issuer (the signer, e.g. a VTA acting on the principal's behalf),
together with delegationEvidence establishing the entitlement. Absent
principal, or principal equal to issuer, is the ordinary
auth/authenticate/0.2 form unchanged. 0.3 also carries forward the optional
sessionKey member from 0.2.
-
PayloadDelegationEvidence
-
REQUIRED whenever
principal is present and differs from issuer; MUST be omitted
otherwise. Describes the evidence that entitles issuer to authenticate as
principal. The framework does not prescribe its shape — see Authorization — but
the consumer's policy MUST verify it independently rather than take issuer's
claim of entitlement at face value.
-
Response
-
Issued by the auth service after verifying the proof on the authenticate document
(and, for a proxied request, the delegation evidence). Carried in a Trust Task
document whose type is https://trusttasks.org/spec/auth/authenticate/0.3#response.
-
Session
-
A logical authentication context bound to a subject. Producers and consumers
exchange Session-shaped data in challenge issuance, authentication responses, and
introspection (whoami).
-
TokenBundle
-
An access token (typically short-lived JWT) paired with an optional refresh token
(typically long-lived opaque string). The shapes follow OAuth 2.0 (RFC 6749 §5.1)
conventions but are not coupled to any particular OAuth profile.
Typedefs
-
Ext
= Map<String, dynamic>
-
Vendor-namespaced extension object per SPEC.md §4.5.1. Each immediate key MUST be a
reverse-DNS namespace; structure under each namespace is opaque to the framework.