-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Support recursive disclosures #2
Comments
Just to be clear, it means that you can selectively disclose each attribute within a nested object AND the nested fully by itself? If it is an OR it is already supported, but not both together within a single credential. |
I think it's an AND. You can e.g. have the whole
and this could be nested as many layers deep as you want. So to parse an SD-JWT to the decoded payload you would have to parse a disclosure, see if it has an |
But by making the |
Let me check the spec later, would be good to double check this. I might've missed this when reading through it. |
It seems the Meeco implementation does support recursive disclosures: https://github.com/Meeco/sd-jwt |
I can't seem to find an example of what this library does not support, do you have a direct link? |
See the link to the spec I posted in my initial message: https://www.ietf.org/archive/id/draft-ietf-oauth-selective-disclosure-jwt-06.html#name-example-sd-jwt-with-recursi |
I think the following output is not possible:
With the following disclosures:
|
I see, yes that is not possible currently. I think for now I will just apply the fix you provided with the |
The SD-JWT spec describes the possibility of recursive disclosures. Where you can have a selectively discloseable value, that then contains selectively discloseable values within the selectively discloseable value: https://www.ietf.org/archive/id/draft-ietf-oauth-selective-disclosure-jwt-06.html#name-example-sd-jwt-with-recursi
Doesn't seem like a really important feature to support right away, but opening this issue to keep track of the status.
We would probably have to add another field that can be added to the disclosureFrame to indicate the property itself should be recursively dislcosed. Currently when you provide the following dislcosure frame:
You get the following output (kinda)
Following the structure of
__decoyCount
, I think we can do something like this for the disclosure frame:To receive this output:
Not fully happy with the
__recursiveDisclosure
name yet, but I hope you get the idea.The text was updated successfully, but these errors were encountered: