Repository navigation
DOC: 51Did factor outcomes and the public key list as released - #245
Merged
Merged
Conversation
…nd the key list with startsAt and endsAt The 51Did page now says that each creator context factor is verified, mismatch, misconfigured or notrecorded, that the factor block is sent on a mismatch, on a misconfigured result that still compared some factors and whenever any factor is notrecorded whatever the overall result, and that a verified result beside notrecorded factors rests on the factors that were recorded. The public key section now describes the key list at /api/v4/id/key as the service publishes it, being every key whose period has started plus the next key in the fifteen minutes before its start, each entry with startsAt, endsAt, created and publicKey, the datetime filter read as UTC, the private cache lifetime, and the rule the client in each package applies to hold the list and verify offline. The OWID public-key endpoint replaces the creator endpoint, which now answers 404. The readers table gains the Rust package.
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Aligns the 51Did page (
src/identifiers/fodid.md) to the 51Did verification and public key behaviour of cloud release 4.4.45 and the 51Did packages released with it.What was wrong
contextismismatchormisconfiguredwith some factors compared, and each factor as one of three values. The service reports four values,verified,mismatch,misconfiguredandnotrecorded, and sends the block whenever any factor isnotrecorded, whatever the overall result, so averifiedcontext can sit besidenotrecordedfactors.GET /owid/api/v3/creatorwith apublicKeySPKIfield. That endpoint answers 404 on production and the OWID key endpoint isGET /owid/api/v3/public-key, answering{ format, publicKey, validFrom, validTo }.createdandpublicKey, described thedatetimefilter as selecting oncreated, and said the endpoint needed a Resource Key. Each entry carriesstartsAt,endsAt,createdandpublicKey, the filter selects keys whose period starts at or after the timestamp, and a licence key alone is accepted.What it now says
verified,mismatch,misconfiguredornotrecorded.notrecordedmeans the creator recorded no value, so the factor took no part incontext, andfactorsis sent on a mismatch, on a misconfigured result that still compared some factors, and whenever any factor isnotrecorded. Averifiedcontext besidenotrecordedfactors rests on the factors that were recorded.GET /api/v4/id/key/{resource}(or a licence key aslicense) publishes every key whose period has started plus the next key in the fifteen minutes before its start. Each entry carriesstartsAt,endsAt(the next key's start, carried by the newest entry although the next key is not published),createdandpublicKey. A key may be replaced before itsendsAt.datetimeis read as UTC and selects keys starting at or after it. The answer is cached privately for at most 1800 seconds and never past the next publication, and a refusal is never cached.endsAtheld, fetches only for an identifier dated at or after that less the fifteen minute allowance, at most once a minute, fetches the whole list again once it is a day old, and after a failed signature fetches once more from the start of the key in force at the identifier's date before reporting a failure.GET /owid/api/v3/public-key?date=<minutes>returns the one key in force atdatewithvalidFromandvalidTo, takes the same credentials and is metered.fodid-clientfor Rust.What the wording matches
Cloud release 4.4.45, live on production, and the 51Did packages fiftyone.pipeline.did 4.5.51 (npm), fiftyone-pipeline-did 4.5.31 (PyPI), com.51degrees:pipeline.did 4.5.40 (Maven Central), FiftyOne.Did 4.5.116 (NuGet), 51degrees/fiftyone.pipeline.did 4.5.1 (Packagist) and fodid-client 4.5.7-9 (crates.io).
Checked against the cloud source at tag 4.4.45 (
Controllers/FodId/KeyController.cs,Controllers/FodId/RedeemController.cs,Helpers/ContextVerifier.cs,Keys/Data/KeySchedule.cs,Controllers/OwidApi/PublicKeyController.cs), the .NET, Node and Rust clients on their main branches, and production, where/owid/api/v3/creatoranswers 404 and/owid/api/v3/public-keyand/api/v4/id/keyanswer 401 withCache-Control: no-storewithout a credential. The shared 51degrees.com link lint passes with this repository's forbid mode.