-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
statuses
constraints
not evaluated
#163
Comments
statuses
contstraints
not evaluatedstatuses
constraints
not evaluated
Hey @DJHunn39, it is correct that statuses are not validated by the PEX library. I think this may be better suited also for a higher level framework to handle (such as Credo). As statuses also concerns revocation, which is quite expensive to check in a presentation, and thus might need some special handling. Do you think it makes sense if we do check for expiration with statuses active, but ignore the revocation check? On the Credo verification side currently verification will always fail if the credential is expired or revoked, independent of what is in the Presentation Definition |
Agreed. We also check outside of the definition. Although there are use cases where for instance an expired, or maybe even a revoked credential might make sense. I think we could create a callback for these use cases, so people using Credo, Veramo or any other implementation can hookup there status implementation of choice. This library would never be able to do that, because we do not want to incorporate all kinds of libs/deps and having to support multiple implementations |
Fair enough, we can perform the check outside of PEX (or Credo, if necessary) too. I'll have another look at what happens when we use an expired credential in a submission, so far I haven't seen it fail but it sounds like there's either a problem on my end or in Credo based on what @TimoGlastra mentioned. As @nklomp mentioned, there are cases where an expired credential could be acceptable, so ideally Credo/others would make provisions for that. It would get confusing if Credo partially supports status checks, imo. |
I'm submitting a ...
bug report
feature request
Summary
It appears the library doesn't evaluate submissions against
statuses
constraints
in proof definitions.For example, for this proof definition:
I would expect an SD-JWT VC with an
exp
in the past to be unusable when generating a submission for this proof definition. Instead, a submission is created, and is accepted by a verifier.The input descriptor in the proof definition above aligns with the DIF PEX standard (both v1 and latest).
I've had a look at the handlers listed in the
evaluationClient
, and I think it's missing one for this type of constraint.statuses
constraints
in proof definitions are validated, though, so I might have missed some other piece of code that performs status evaluation.The text was updated successfully, but these errors were encountered: