| // Copyright 2026 Google LLC |
| // |
| // Licensed under the Apache License, Version 2.0 (the "License"); |
| // you may not use this file except in compliance with the License. |
| // You may obtain a copy of the License at |
| // |
| // https://www.apache.org/licenses/LICENSE-2.0 |
| // |
| // Unless required by applicable law or agreed to in writing, software |
| // distributed under the License is distributed on an "AS IS" BASIS, |
| // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| // See the License for the specific language governing permissions and |
| // limitations under the License. |
| // |
| |
| #ifndef THIRD_PARTY_CREDENTIO_ASSERTION_VALIDATOR_H_ |
| #define THIRD_PARTY_CREDENTIO_ASSERTION_VALIDATOR_H_ |
| |
| #include <string> |
| |
| #include "absl/container/flat_hash_set.h" |
| #include "assertion/assertion_parser.h" |
| #include "jumbf/uri.h" |
| #include "proto/assertion.pb.h" |
| #include "proto/manifest.pb.h" |
| #include "validator/tracker.h" |
| |
| namespace credentio { |
| |
| // Validator of assertions referenced by a claim. |
| class AssertionValidator { |
| public: |
| struct Options { |
| bool skip_actions_assertion_validation_for_test = false; |
| }; |
| AssertionValidator() = default; |
| explicit AssertionValidator(const Options& options) : options_(options) {} |
| virtual ~AssertionValidator() = default; |
| |
| // Resolves and validates assertions in a claim, writing the assertions to |
| // the `assertions` field of the manifest. |
| // |
| // `redacted_assertion_paths` contains absolute paths of assertions that have |
| // been declared as redacted by some claim in the manifest store. The |
| // validator skips validating assertions with these paths, after verifying |
| // that they have been properly redacted. |
| virtual void ValidateClaimAssertions( |
| const jumbf::UriResolver& uri_resolver, |
| const absl::flat_hash_set<std::string>& redacted_assertion_paths, |
| Manifest& manifest, ValidationTracker& validation_tracker) const; |
| |
| private: |
| const Options options_; |
| const AssertionParser assertion_parser_; |
| }; |
| |
| } // namespace credentio |
| |
| #endif // THIRD_PARTY_CREDENTIO_ASSERTION_VALIDATOR_H_ |