Cette page a été traduite par une machine et n'a pas encore été révisée par une personne. L'anglais est la référence ; les corrections sont les bienvenues sur GitHub. GitHub

Cookwala / SDK et scénarios / 052

Read the recall list and try to verify the example recall

Catalogs publish signed recalls; executors poll them and refuse recalled revisions. The reference hub has none to publish. The example recall is signed, and verifying it needs the issuer's key record, which this repository does not ship.

Audience: regulator · Objectif: Rendre les gens en meilleure santé · Niveau: beginner

Lire d'abord: /docs/CORE/ /docs/HUB/

Étapes

  1. The reference hub publishes an empty recall list. recalls

  2. Verify the example recall with no key records. The signature names a key id; without its record the result is unknown_key, not ok. A refusal to trust is a result. verify

  3. The content hash of the recall, computed without the signature field, is what the signature covers. hash

Résultat

You know where recalls come from and that verification without a key record fails safely. Next: scenario 054 verifies documents against real key records from the conformance vectors.

Ligne de commande

cookwala hub --recipes examples --speed 200
curl -s http://localhost:7878/v1/recalls
cookwala verify examples/core/recall.json
cookwala hash examples/core/recall.json

Sortie enregistrée

Statut: ok

[1] recalls: []
[2] verify: {"ok": false, "reason": "unknown_key"}
[3] hash: {"hash": "sha256:690225c63501e33d8bc268203fa45cca9a23c43b717e4b2eccc2018f00770bb0"}

Code

Exécuter: python scenarios/out/052-read-recalls-and-check-the-signed-example-recall/python.py

# Scenario 052: Read the recall list and try to verify the example recall
# Catalogs publish signed recalls; executors poll them and refuse recalled revisions. The reference hub has none to publish. The example recall is signed, and verifying it needs the issuer's key record, which this repository does not ship.
# Run a hub first: python hub/cookwala_hub.py --recipes examples
import json, os
from cookwala.client import CookwalaClient, CookwalaProblem

def load(path):
    with open(path, encoding="utf-8") as f:
        return json.load(f)

def pick(obj, path):
    for part in path.replace("]", "").replace("[", ".").split("."):
        obj = obj[int(part)] if part.isdigit() else (len(obj) if part == "length" else obj.get(part))
    return obj

c = CookwalaClient(os.environ.get("COOKWALA_HUB", "http://localhost:7878"))


# Step 1: The reference hub publishes an empty recall list.
recalls = c.recalls()
assert pick(recalls, "length") == 0, pick(recalls, "length")
print("ok", "length", "=", 0)

# Step 2: Verify the example recall with no key records. The signature names a key id; without its record the result is unknown_key, not ok. A refusal to trust is a result.
v = c.verify(load("examples/core/recall.json"), [])
assert pick(v, "ok") == False, pick(v, "ok")
print("ok", "ok", "=", False)
assert pick(v, "reason") == "unknown_key", pick(v, "reason")
print("ok", "reason", "=", "unknown_key")

# Step 3: The content hash of the recall, computed without the signature field, is what the signature covers.
h = c.hash(load("examples/core/recall.json"))
assert pick(h, "hash") == "sha256:690225c63501e33d8bc268203fa45cca9a23c43b717e4b2eccc2018f00770bb0", pick(h, "hash")
print("ok", "hash", "=", "sha256:690225c63501e33d8bc268203fa45cca9a23c43b717e4b2eccc2018f00770bb0")

print("scenario complete")

scenarios/052-read-recalls-and-check-the-signed-example-recall.json

Précédent: 051 Suivant: 053