Port Dart's typed atKeys key material to at_java, with Dart-interoperable JSON
@gkc 已经在做这个了。
开始于 2026年9月1日。
评估
这个 Issue 还没有评估数据。
描述
Is your feature request related to a problem? Please describe.
at_java's AtKeys models a keyfile as seven flat base64 Strings. Dart's at_auth
#2047 replaced that with a versioned keys[] document of self-describing key
material — keyId, keyPartType, keyAlgorithmType, bytes, operations,
createdAt, status. at_java cannot represent it, and the two SDKs' keyfiles are
currently mutually unreadable: at_java writes "version" as a JSON string where
Dart's parser requires an int, and Dart's "keys" array cannot bind into at_java's
Map<String,String>.
Describe the solution you'd like
Port the Dart implementation as follows...
| Dart class | Dart field | Dart type (known-values class) | JSON member | Java type | Java field |
|---|---|---|---|---|---|
AtKeys |
atsign |
Atsign? |
atsign |
AtSign |
atSign |
_materialsByKeyId |
Map<String, Map<String, AtKeysMaterial>> |
keys |
Map<KeyId, Map<CryptographicMaterial.Role, CryptographicMaterial>> |
materials |
|
AtKeysMaterial |
keys[].keyParts[] |
CryptographicMaterial |
|||
keyId |
String |
keys[].keyId |
KeyId |
keyId |
|
enrollmentId |
String? |
keys[].enrollmentId |
EnrollmentId |
enrollmentId |
|
keyPartType |
String (CryptographicKeyType) |
keyPartType |
CryptographicMaterial.Role |
role |
|
keyAlgorithmType |
String (KeyAlgorithmType) |
keyAlgorithmType |
CryptographicMaterial.Algorithm |
algorithm |
|
operations |
List<String> |
operations |
List<CryptographicMaterial.Operation> |
operations |
|
bytes |
AtBytes |
bytes |
byte[] |
bytes |
|
createdAt |
DateTime |
createdAt |
OffsetDateTime |
createdAt |
|
status |
KeyPartStatus |
status |
CryptographicMaterial.Status |
status |
Implement version specific JSON encode/decode such that atKeys JSON written by current and previous version of Dart can be loaded.
The legacy fields in AtKeys will be removed. Deprecated getters will be added to fix the current code and then ultimately be removed once CryptoProvider is ported.
Describe alternatives you've considered
Port like-for-like.
Additional context
Open questions for the team
-
CryptographicMaterialorKeyingMaterial? The latter is the actual term of
art — NIST SP 800-57 defines "keying material", RFC 5869 uses "input keying
material" (IKM). "Cryptographic material" is common informally (AWS KMS, Vault)
but isn't a standards term. This is the type everything else nests inside, so
worth settling before code. -
StatusorState? NIST SP 800-57 §7 defines a key state machine
(pre-activation, active, suspended, deactivated, compromised, destroyed) and
activeis literally a NIST state. Against: ourretired/deadare not NIST's
deactivated/destroyed, and the wire field isstatus— soStatewould claim
an alignment the values don't honour. -
Do we need to support Dart's
AtKeys.metadatapassthrough? Dart parks every
unrecognised top-level keyfile key there and writes it back flat. at_java has
never modelled it, so the default is not to add it — but then at_java drops
those keys on save. -
What is the known vocabulary for
operations? Dart has no known-values class
for it, and the only values anywhere in its tree aresignanddecrypt, both in
tests — soOperation's known set has to be agreed rather than ported. Seed it
from JWKkey_ops(sign/verify/encrypt/decrypt/wrapKey/unwrapKey/
deriveKey/deriveBits), or from just those two and let it grow?
- 主要语言
- Java
- 星标
- 2
- 派生
- 19
- 平均合并
- 23 小时 2 分钟
- 30 天内合并 PR
- 8
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
atsign-foundation/at_java 的其他 Issue
-
Port pluggable cryptography and re-wire current cryptography as default可能重新可做 @gkc 于 28 天前认领,目前没有进行中的 PR。 未关闭enhancement
atsign-foundation/at_java#430 · 已指派 1 人 ·
-
Generate a SBOM and SLSA attestations during the release workflow可能重新可做 @cpswan 于 183 天前认领,目前没有进行中的 PR。 未关闭enhancement
atsign-foundation/at_java#383 · 3 条评论 · 已指派 2 人 ·
-
Enhance Activate utility such that it has feature parity with dart activate_cli可能重新可做 @akafredperry 于 245 天前认领,目前没有进行中的 PR。 未关闭enhancement
atsign-foundation/at_java#338 · 已指派 1 人 ·
-
Should Activate utility be migrated to an AtActivationClient interface and implementation in the api package?可能重新可做 @akafredperry 于 245 天前认领,目前没有进行中的 PR。 未关闭enhancement
atsign-foundation/at_java#334 · 已指派 1 人 ·
-
Introduce a protocol package and migrate all code that builds at protocol commands and interprets at protocol responses and notifications可能重新可做 @akafredperry 于 245 天前认领,目前没有进行中的 PR。 未关闭enhancement
atsign-foundation/at_java#335 · 2 条评论 · 已指派 1 人 ·
查看 atsign-foundation/at_java 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 88/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 76/100
github/copilot-sdk#2793 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
-
enhancement good first issue
难度 1/5 1-3 小时 新手友好度 88/100