Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support DID URL dereferencing according to DID specifications #244

Open
Tracked by #243
gerardsn opened this issue Dec 2, 2022 · 3 comments
Open
Tracked by #243

Support DID URL dereferencing according to DID specifications #244

gerardsn opened this issue Dec 2, 2022 · 3 comments

Comments

@gerardsn
Copy link
Member

gerardsn commented Dec 2, 2022

The DID specification distinguishes between resolving a DID document and dereferencing to a specific item on that document. The specifications also describes how conforming resolvers should be implemented. https://w3c-ccg.github.io/did-resolution/ (draft) provides some more details and useful examples on did resolution

RFC006 service dereferencing approach

More specifically, in RFC006 we have defined a service as

{
    "id": "<did>#<id-string>"                 # id-string = BASE58(SHA256(json-bytes-without-id))
    "type": "<unique-type-name>"
    "serviceEndpoint": ... (string or map)
}

According to RFC006 we need to (de-)reference this service as

<did>/serviceEndpoint?type=<service-type>

DID v1.0 service dereferencing approach

Lets say that the service has "id": "<did>#service1" then according to the DID standard, a conforming resolver can (de-)reference this service using the id fragment

<did>?service=service1

Differences

The official (de)referencing method does not seem to conflict with ours and can just be implemented.

The main difference is that we dereference based on the service.type (and therefore require the type to be unique), while the standard does this based on the fragment in the service.id (which is also specced to be unique).

My understanding is that we use service.type as a unique parameter to prevent issues when a service is replaced. For example, if did-1 references a service on did-2, and did-2 wants to change this serviceEndpoint from A.example.com to B.example.com, we still want the reference in did-1 to dereference properly. However, this issue only exists because we have defined the id fragment as id-string that is derived from the rest of the service (that is not being used for anything as far as I can see, but could be related to #242).

Dropping the id-string requirement means that the id field can be used as an identifier that is consistent even after changing the serviceEndpoint. This would also allow us to use service.type as a type that we can impose more constraints on to make validation easier. We currently have the following types: node-contact-info, NutsComm, NutsService, NutsCompoundService that each have a clearly defined format. (node-contact-info and NutsComm can be considered services or compound services with additional requirements)

If we are to apply (some) of these changes, we need to come up with a migration strategy. Since both methods do not conflict they can probably exists at the same time. Bolts specified types also need more thinking

@gerardsn gerardsn changed the title Support DID URL dereferencing according to DID specifications Support DID resolution according to DID specifications Dec 2, 2022
@woutslakhorst
Copy link
Member

So the title should be about service dereferencing, not DID resolvement/resolution?

@gerardsn gerardsn changed the title Support DID resolution according to DID specifications Support DID URL dereferencing according to DID specifications Dec 22, 2022
@gerardsn
Copy link
Member Author

Changed it back. I thought resolution referred to both dereferencing and resolving. I did not look at resolving, but did not want to exclude it either.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants