Feat/handle deny consent 2 - #33
Open
grahamallen-1 wants to merge 2 commits into
Open
grahamallen-1 wants to merge 2 commits into
grahamallen-1 wants to merge 2 commits into
Conversation
Update spruce opencred with latest from stateofca
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Handle deny-consent (access_denied) on the OID4VP response endpoint
Summary
When a user declines to share their credentials, the wallet returns an OAuth
access_deniederror to the verifier instead of avp_token. Today OpenCred does not recognize that response: it falls through to vp_token extraction and the exchange is left hanging until it times out or the user intervenes. This teaches the standard OID4VP response handler to treat a returnederroras a completed-but-failed presentation, so the verifier can surface an error and clean up its state immediately.What changes
In
handleAuthorizationResponse(lib/workflows/profiles/native-oid4vp-standard.js), before extracting thevp_token: if the response body carries a stringerror, validate that the returnedstatematches the authorization request, then mark the exchangeinvalidand record the error under the current step's results (bumping the sequence). A mismatchedstatethrows, as elsewhere in this handler. This runs after thedc_api.jwtdecrypt step, so it applies to both encrypted and plain responses.The exchange moving to
invalidwith the error recorded is what lets the frontend show the user a clear "you declined / cancelled" message instead of spinning until the exchange TTL expires.Paired wallet change
This is the verifier half of a wallet-side change. The wallet (sprucekit-mobile 0.21.1) exposes a
denyPermissionAPI that POSTs to the response endpoint witherror=access_deniedandstate={state}, informing the verifier that the user cancelled. Wallet PR summary:A user can decide to deny consent while presenting their credentials. The verifier app needs to be made aware of this choice so it can clean up local state and display an error message. Without responding to the denial, the verifier app is left on its own and requires a timeout or user intervention. The
access_deniederror code specifies that "The End-User did not give consent to share the requested Credentials with the Verifier." Consume sprucekit-mobile/0.21.1, which exposes thedenyPermissionAPI that will POST /response witherror=access_deniedandstate={state}.Tests
Adds
test/unit/workflows/61-oid4vp-standard-deny-consent.test.js:errormarks the exchangeinvalid, records the error, and bumps the sequencestatethrowsVerified: lint clean; unit suite green; the new tests fail against the pre-change handler.
References
OAuth 2.0 (RFC 6749) — the
access_deniederror code ("The resource owner or authorization server denied the request"): §4.1.2.1 and §5.2https://www.rfc-editor.org/rfc/rfc6749#section-4.1.2.1
OpenID Connect Core 1.0 —
access_deniedin the authentication error response ("The End-User ... did not consent"): §3.1.2.6https://openid.net/specs/openid-connect-core-1_0.html#AuthError
OpenID for Verifiable Presentations 1.0 — the authorization error response returned to the verifier (
error+state), including delivery overdirect_post:https://openid.net/specs/openid-4-verifiable-presentations-1_0.html
Wallet change: sprucekit-mobile 0.21.1
denyPermission(POSTserror=access_denied+stateto the response endpoint).