Port Dart's typed atKeys key material to at_java, with Dart-interoperable JSON
@gkc ci sta già lavorando.
Dal 1/9/2026.
Valutazione
Questa issue non è ancora stata valutata.
Descrizione
Is your feature request related to a problem? Please describe.
at_java's AtKeys models a keyfile as seven flat base64 Strings. Dart's at_auth
#2047 replaced that with a versioned keys[] document of self-describing key
material — keyId, keyPartType, keyAlgorithmType, bytes, operations,
createdAt, status. at_java cannot represent it, and the two SDKs' keyfiles are
currently mutually unreadable: at_java writes "version" as a JSON string where
Dart's parser requires an int, and Dart's "keys" array cannot bind into at_java's
Map<String,String>.
Describe the solution you'd like
Port the Dart implementation as follows...
| Dart class | Dart field | Dart type (known-values class) | JSON member | Java type | Java field |
|---|---|---|---|---|---|
AtKeys |
atsign |
Atsign? |
atsign |
AtSign |
atSign |
_materialsByKeyId |
Map<String, Map<String, AtKeysMaterial>> |
keys |
Map<KeyId, Map<CryptographicMaterial.Role, CryptographicMaterial>> |
materials |
|
AtKeysMaterial |
keys[].keyParts[] |
CryptographicMaterial |
|||
keyId |
String |
keys[].keyId |
KeyId |
keyId |
|
enrollmentId |
String? |
keys[].enrollmentId |
EnrollmentId |
enrollmentId |
|
keyPartType |
String (CryptographicKeyType) |
keyPartType |
CryptographicMaterial.Role |
role |
|
keyAlgorithmType |
String (KeyAlgorithmType) |
keyAlgorithmType |
CryptographicMaterial.Algorithm |
algorithm |
|
operations |
List<String> |
operations |
List<CryptographicMaterial.Operation> |
operations |
|
bytes |
AtBytes |
bytes |
byte[] |
bytes |
|
createdAt |
DateTime |
createdAt |
OffsetDateTime |
createdAt |
|
status |
KeyPartStatus |
status |
CryptographicMaterial.Status |
status |
Implement version specific JSON encode/decode such that atKeys JSON written by current and previous version of Dart can be loaded.
The legacy fields in AtKeys will be removed. Deprecated getters will be added to fix the current code and then ultimately be removed once CryptoProvider is ported.
Describe alternatives you've considered
Port like-for-like.
Additional context
Open questions for the team
-
CryptographicMaterialorKeyingMaterial? The latter is the actual term of
art — NIST SP 800-57 defines "keying material", RFC 5869 uses "input keying
material" (IKM). "Cryptographic material" is common informally (AWS KMS, Vault)
but isn't a standards term. This is the type everything else nests inside, so
worth settling before code. -
StatusorState? NIST SP 800-57 §7 defines a key state machine
(pre-activation, active, suspended, deactivated, compromised, destroyed) and
activeis literally a NIST state. Against: ourretired/deadare not NIST's
deactivated/destroyed, and the wire field isstatus— soStatewould claim
an alignment the values don't honour. -
Do we need to support Dart's
AtKeys.metadatapassthrough? Dart parks every
unrecognised top-level keyfile key there and writes it back flat. at_java has
never modelled it, so the default is not to add it — but then at_java drops
those keys on save. -
What is the known vocabulary for
operations? Dart has no known-values class
for it, and the only values anywhere in its tree aresignanddecrypt, both in
tests — soOperation's known set has to be agreed rather than ported. Seed it
from JWKkey_ops(sign/verify/encrypt/decrypt/wrapKey/unwrapKey/
deriveKey/deriveBits), or from just those two and let it grow?
- Lingua principale
- Java
- Stelle
- 2
- Fork
- 19
- Merge medio
- 1g 6h
- PR unite (30g)
- 7
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di atsign-foundation/at_java
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 45/100
atsign-foundation/at_java#443 ·
-
Port pluggable cryptography and re-wire current cryptography as defaultForse di nuovo libera @gkc l’ha presa 40 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#430 · 1 assegnatario ·
-
Generate a SBOM and SLSA attestations during the release workflowForse di nuovo libera @cpswan l’ha presa 195 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#383 · 3 commenti · 2 assegnatari ·
-
Enhance Activate utility such that it has feature parity with dart activate_cliForse di nuovo libera @akafredperry l’ha presa 256 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#338 · 1 assegnatario ·
-
Should Activate utility be migrated to an AtActivationClient interface and implementation in the api package?Forse di nuovo libera @akafredperry l’ha presa 257 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
atsign-foundation/at_java#334 · 1 assegnatario ·
Tutte le issue di atsign-foundation/at_java
Issue simili
-
BoxAttachmentMulti parsing leaks IOException / ArrayIndexOutOfBoundsException on malformed content instead of IllegalArgumentExceptionForse già presa @Kshot3000 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
ergoplatform/ergo-appkit#272 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
utopia-rise/godot-jvm#1004 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
spring-projects/spring-grpc#442 ·