Esta página foi traduzida por máquina e ainda não foi revisada por uma pessoa. O inglês é a referência; correções são bem-vindas no GitHub. GitHub

Cookwala / SDK e cenários / 101

A halal authority certifies a meal, re-certifies it later, and a second authority certifies it too

Certifications are detached, signed documents that point at a recipe revision by hash (RFC-0010). Validate one, hash it, verify its signature against the authority's published key, and read the field that makes it a re-certification.

Público: certifier · Objetivo: Torne as pessoas mais saudáveis · Nível: intermediate

Leia primeiro: /docs/RECIPE-FORMAT/ /docs/CORE/

Passos

  1. The October document from the (fictional) halal authority validates against common.schema.json#/$defs/Certification. validate

  2. Its hash is what a recipe, an offer item or a registry entry points at; the document itself names the kofta revision it certifies by hash. hash

  3. Verify the authority's signature against its KeyRecord (here the public RFC 8032 test key, so this is an exercise, not a claim). verify

  4. A different authority, a different scheme, a different recipe: the same check. verify

  5. The October document supersedes the January one from the same authority: the newest verifying document of an authority is the current one; several authorities may certify the same meal and each counts.

Resultado

You can tell a certification from a claim: it is signed by a named authority, points at an exact revision, has a window and a status, and can be superseded. Next: the profile vectors in conformance/profiles/certifications.json cover expiry, revocation, forged signatures and re-certification.

Linha de comando

cookwala validate --kind common examples/certifications/halal-kofta-oven-2026-10.json
cookwala hash examples/certifications/halal-kofta-oven-2026-10.json
cookwala verify examples/certifications/halal-kofta-oven-2026-10.json --keys conformance/keys/certification-test-keys.json
jq .supersedes examples/certifications/halal-kofta-oven-2026-10.json

Saída gravada

Status: ok

[1] validate: {"ok": true, "errors": []}
[2] hash: {"hash": "sha256:f478c8f716e38d9bcaa6af2fda2aff203327c625931540dfe2195917bb937072"}
[3] verify: {"ok": true, "reason": "ok"}
[4] verify: {"ok": true, "reason": "ok"}

Código

Executar: python scenarios/out/101-a-meal-certified-twice-and-recertified/python.py

# Scenario 101: A halal authority certifies a meal, re-certifies it later, and a second authority certifies it too
# Certifications are detached, signed documents that point at a recipe revision by hash (RFC-0010). Validate one, hash it, verify its signature against the authority's published key, and read the field that makes it a re-certification.
# Run a hub first: python hub/cookwala_hub.py --recipes examples
import json, os
from cookwala.client import CookwalaClient, CookwalaProblem

def load(path):
    with open(path, encoding="utf-8") as f:
        return json.load(f)

def pick(obj, path):
    for part in path.replace("]", "").replace("[", ".").split("."):
        obj = obj[int(part)] if part.isdigit() else (len(obj) if part == "length" else obj.get(part))
    return obj

c = CookwalaClient(os.environ.get("COOKWALA_HUB", "http://localhost:7878"))


# Step 1: The October document from the (fictional) halal authority validates against common.schema.json#/$defs/Certification.
v = c.validate("common", load("examples/certifications/halal-kofta-oven-2026-10.json"))
assert pick(v, "ok") == True, pick(v, "ok")
print("ok", "ok", "=", True)

# Step 2: Its hash is what a recipe, an offer item or a registry entry points at; the document itself names the kofta revision it certifies by hash.
h = c.hash(load("examples/certifications/halal-kofta-oven-2026-10.json"))

# Step 3: Verify the authority's signature against its KeyRecord (here the public RFC 8032 test key, so this is an exercise, not a claim).
sig = c.verify(load("examples/certifications/halal-kofta-oven-2026-10.json"), load("conformance/keys/certification-test-keys.json"))
assert pick(sig, "ok") == True, pick(sig, "ok")
print("ok", "ok", "=", True)
assert pick(sig, "reason") == "ok", pick(sig, "reason")
print("ok", "reason", "=", "ok")

# Step 4: A different authority, a different scheme, a different recipe: the same check.
sig2 = c.verify(load("examples/certifications/vegetarian-shakshuka-2026-06.json"), load("conformance/keys/certification-test-keys.json"))
assert pick(sig2, "ok") == True, pick(sig2, "ok")
print("ok", "ok", "=", True)

# Step 5: The October document supersedes the January one from the same authority: the newest verifying document of an authority is the current one; several authorities may certify the same meal and each counts.
assert pick(v, "ok") == True, pick(v, "ok")
print("ok", "ok", "=", True)

print("scenario complete")

scenarios/101-a-meal-certified-twice-and-recertified.json

Anterior: 100