Parse a certificate into its typed view **without** verifying the proof. For displaying a document whose trust has not been established, or that is about to be verified by a caller that already holds the key. Never make an authorization decision on the result of this function alone.
(document: &Value)
| 196 | /// about to be verified by a caller that already holds the key. Never make an |
| 197 | /// authorization decision on the result of this function alone. |
| 198 | pub fn parse(document: &Value) -> Result<Delegation> { |
| 199 | expect_type(document, TYPE_DELEGATION)?; |
| 200 | let obj = as_object(document)?; |
| 201 | |
| 202 | let id_urn = string_field(obj, "@id")?; |
| 203 | let id = DelegationId::from_base32(&id_urn) |
| 204 | .ok_or_else(|| CanonicalError::Proof(format!("malformed delegation @id: {id_urn}")))?; |
| 205 | |
| 206 | let scope = obj |
| 207 | .get("scope") |
| 208 | .ok_or_else(|| CanonicalError::Proof("delegation carries no scope".into()))?; |
| 209 | let scope = serde_json::from_value(scope.clone()) |
| 210 | .map_err(|e| CanonicalError::Proof(format!("malformed delegation scope: {e}")))?; |
| 211 | |
| 212 | Ok(Delegation { |
| 213 | id, |
| 214 | delegator: string_field(obj, "delegator")?, |
| 215 | delegator_key: string_field(obj, "delegatorKey")?, |
| 216 | delegator_name: string_field(obj, "delegatorName")?, |
| 217 | delegate: string_field(obj, "delegate")?, |
| 218 | delegate_key: string_field(obj, "delegateKey")?, |
| 219 | delegate_name: string_field(obj, "delegateName")?, |
| 220 | software_agent: obj |
| 221 | .get("softwareAgent") |
| 222 | .and_then(Value::as_str) |
| 223 | .map(str::to_string), |
| 224 | scope, |
| 225 | issued: timestamp_field(obj, "issued")?, |
| 226 | expires: optional_timestamp_field(obj, "expires")?, |
| 227 | }) |
| 228 | } |
| 229 | |
| 230 | /// Recover the delegate's Ed25519 public key from a parsed certificate. |
| 231 | /// |