Diese Seite wurde maschinell übersetzt und wurde noch nicht von einer Person überprüft. Englisch ist die Referenz; Korrekturen auf GitHub sind willkommen. GitHub

Cookwala / SDK und Szenarien / 100

A recall through a mirror: verify against the issuer, never the relay

Federation has no centre, so a recall may arrive through a mirror. The three federation vectors show it: the issuer's signature still verifies after relaying, the mirror's own signature proves nothing, and a mirror that edits the recall breaks the signature.

Zielgruppe: food safety officer · Ziel: Menschen gesünder machen, Roboter für Menschen · Level: intermediate

Zuerst lesen: /docs/FEDERATION/ /docs/CORE/

Schritte

  1. The recall rc-100 (action block) republished by a mirror, checked with the issuer's key: ok. verify

  2. The same recall re-signed by the mirror with its own key: unknown_key when only the issuer is trusted. verify

  3. A mirror that changes block to warn: bad_signature, even with the mirror's key also in the trust list. verify

Ergebnis

You know why a hub resolves the issuer's key from the issuer's own discovery document and verifies byte for byte, and why cookwala.ai is one entry on a trust list, not a root.

Kommandozeile

cookwala conformance
jq '.[] | {id, expected}' conformance/profiles/federation.json

Aufgezeichnete Ausgabe

Status: ok

[1] verify: {"ok": true, "reason": "ok"}
[2] verify: {"ok": false, "reason": "unknown_key"}
[3] verify: {"ok": false, "reason": "bad_signature"}

Code

Ausführen: python scenarios/out/100-verify-recall-against-issuer-not-relay/python.py

# Scenario 100: A recall through a mirror: verify against the issuer, never the relay
# Federation has no centre, so a recall may arrive through a mirror. The three federation vectors show it: the issuer's signature still verifies after relaying, the mirror's own signature proves nothing, and a mirror that edits the recall breaks the signature.
# Run a hub first: python hub/cookwala_hub.py --recipes examples
import json, os
from cookwala.client import CookwalaClient, CookwalaProblem

def load(path):
    with open(path, encoding="utf-8") as f:
        return json.load(f)

def pick(obj, path):
    for part in path.replace("]", "").replace("[", ".").split("."):
        obj = obj[int(part)] if part.isdigit() else (len(obj) if part == "length" else obj.get(part))
    return obj

c = CookwalaClient(os.environ.get("COOKWALA_HUB", "http://localhost:7878"))


# Step 1: The recall rc-100 (action block) republished by a mirror, checked with the issuer's key: ok.
relayed = c.verify(pick(load("conformance/profiles/federation.json"), "0.input.document"), pick(load("conformance/profiles/federation.json"), "0.input.keys"))
assert pick(relayed, "ok") == True, pick(relayed, "ok")
print("ok", "ok", "=", True)
assert pick(relayed, "reason") == "ok", pick(relayed, "reason")
print("ok", "reason", "=", "ok")

# Step 2: The same recall re-signed by the mirror with its own key: unknown_key when only the issuer is trusted.
resigned = c.verify(pick(load("conformance/profiles/federation.json"), "1.input.document"), pick(load("conformance/profiles/federation.json"), "1.input.keys"))
assert pick(resigned, "ok") == False, pick(resigned, "ok")
print("ok", "ok", "=", False)
assert pick(resigned, "reason") == "unknown_key", pick(resigned, "reason")
print("ok", "reason", "=", "unknown_key")

# Step 3: A mirror that changes block to warn: bad_signature, even with the mirror's key also in the trust list.
altered = c.verify(pick(load("conformance/profiles/federation.json"), "2.input.document"), pick(load("conformance/profiles/federation.json"), "2.input.keys"))
assert pick(altered, "ok") == False, pick(altered, "ok")
print("ok", "ok", "=", False)
assert pick(altered, "reason") == "bad_signature", pick(altered, "reason")
print("ok", "reason", "=", "bad_signature")

print("scenario complete")

scenarios/100-verify-recall-against-issuer-not-relay.json

Zurück: 099 Weiter: 101