Skip to content

Prove structured Relay claims survive the eSignet UserInfo exchange #2

Description

@jeremi

Context

We want the social registry eSignet flow to authenticate a person and release household context as relationship data. A clean OIDC shape may use a top-level structured claim such as household_memberships, whose value is an array of objects.

Current code appears structurally capable of this: the Relay client parses object/array JSON values into Java Map/List, ClaimMapper copies values as Object, and UserInfoSigner serializes the final UserInfo map as JSON. However, current tests and docs mostly prove scalar, number, and boolean claims, not nested objects/arrays.

Desired behavior

  • Support a top-level claim such as household_memberships whose value is an array of objects.
  • Keep eSignet accepted claims top-level only. Nested selection like household_memberships[].relationship is out of scope unless eSignet/Relay later define it explicitly.
  • Document the configuration pattern:
    • MOSIP_ESIGNET_OPENID_SCOPE_CLAIMS includes household_memberships
    • registry.esignet.claim-map.household_memberships=household_memberships
    • Relay profile declares/releases household_memberships

Acceptance criteria

  • Add a Relay client test proving object and array values are parsed and preserved.
  • Add a ClaimMapper test proving a structured released value is copied into UserInfo unchanged.
  • Add an exchange test that decodes the signed UserInfo JWS and asserts household_memberships remains an array of objects.
  • Update docs to state: structured values are supported as top-level claims; fine-grained nested consent/selection is not currently supported.

Notes

This is important for the social registry model: login subject is a person, while household membership is contextual relationship data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions