Class: OryClient::UpdateSettingsFlowWithDeviceAuthnMethodRotateSecret

Inherits:
ApiModelBase
  • Object
show all
Defined in:
lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb

Overview

Re-issues a fresh pin_secret for an existing PIN-protected DeviceAuthn key without changing the device signing key. It is the recovery path for a forgotten PIN or a locked key. The server returns the new secret exactly once, HPKE-sealed to the supplied transport_public_key, in the flow's continue_with items (action show_pin_entry_ui).

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Methods inherited from ApiModelBase

_deserialize, #_to_hash, #to_body, #to_s

Constructor Details

#initialize(attributes = {}) ⇒ UpdateSettingsFlowWithDeviceAuthnMethodRotateSecret

Initializes the object

Parameters:

  • attributes (Hash) (defaults to: {})

    Model attributes in the form of hash



64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 64

def initialize(attributes = {})
  if (!attributes.is_a?(Hash))
    fail ArgumentError, "The input argument (attributes) must be a hash in `OryClient::UpdateSettingsFlowWithDeviceAuthnMethodRotateSecret` initialize method"
  end

  # check to see if the attribute exists and convert string to symbol for hash key
  acceptable_attribute_map = self.class.acceptable_attribute_map
  attributes = attributes.each_with_object({}) { |(k, v), h|
    if (!acceptable_attribute_map.key?(k.to_sym))
      fail ArgumentError, "`#{k}` is not a valid attribute in `OryClient::UpdateSettingsFlowWithDeviceAuthnMethodRotateSecret`. Please check the name to make sure it's valid. List of attributes: " + acceptable_attribute_map.keys.inspect
    end
    h[k.to_sym] = v
  }

  if attributes.key?(:'client_key_id')
    self.client_key_id = attributes[:'client_key_id']
  else
    self.client_key_id = nil
  end

  if attributes.key?(:'signature')
    self.signature = attributes[:'signature']
  else
    self.signature = nil
  end

  if attributes.key?(:'transport_public_key')
    self.transport_public_key = attributes[:'transport_public_key']
  else
    self.transport_public_key = nil
  end
end

Instance Attribute Details

#client_key_idObject

The client_key_id of the existing PIN-protected key whose pin_secret to rotate: the lowercase-hex SHA-256 of the device public key in PKIX, ASN.1 DER (SubjectPublicKeyInfo) form. The device signing key is unchanged by the rotation.



20
21
22
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 20

def client_key_id
  @client_key_id
end

#signatureObject

Proves current possession of the enrolled device signing key. To compute it: 1. Base64-decode the settings flow's hidden deviceauthn_nonce UI node value, parse the result as JSON, and base64-decode its nonce field. 2. Concatenate the raw nonce bytes and the raw transport_public_key bytes; this is the challenge. 3. Sign the challenge exactly as at login: on Android with Signature.getInstance(\"SHA256withECDSA\"), submitting the resulting ASN.1 DER-encoded ECDSA signature; on iOS with DCAppAttestService.generateAssertion, passing the challenge bytes as the clientDataHash argument — do not hash them again — and submitting the returned CBOR-encoded App Attest assertion unchanged. Binding the transport key into the signed challenge ensures a hijacked session (stolen token, XSS) cannot rotate the secret and have it sealed to a transport key it controls.



23
24
25
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 23

def signature
  @signature
end

#transport_public_keyObject

The device's X25519 transport public key (32 bytes, base64-encoded) used to seal the freshly issued pin_secret so only this device can open it. Generate a fresh, random X25519 key pair for each rotation — it is a transport-encryption key, distinct from the attested signing key — and submit the raw 32-byte public key. Keep the private key only until the sealed pin_secret from the response has been opened, then discard it. The HPKE suite is DHKEM(X25519, HKDF-SHA256), HKDF-SHA256, AES-128-GCM.



26
27
28
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 26

def transport_public_key
  @transport_public_key
end

Class Method Details

.acceptable_attribute_mapObject

Returns attribute mapping this model knows about



38
39
40
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 38

def self.acceptable_attribute_map
  attribute_map
end

.acceptable_attributesObject

Returns all the JSON keys this model knows about



43
44
45
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 43

def self.acceptable_attributes
  acceptable_attribute_map.values
end

.attribute_mapObject

Attribute mapping from ruby-style variable name to JSON key.



29
30
31
32
33
34
35
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 29

def self.attribute_map
  {
    :'client_key_id' => :'client_key_id',
    :'signature' => :'signature',
    :'transport_public_key' => :'transport_public_key'
  }
end

.build_from_hash(attributes) ⇒ Object

Builds the object from hash

Parameters:

  • attributes (Hash)

    Model attributes in the form of hash

Returns:

  • (Object)

    Returns the model itself



182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 182

def self.build_from_hash(attributes)
  return nil unless attributes.is_a?(Hash)
  attributes = attributes.transform_keys(&:to_sym)
  transformed_hash = {}
  openapi_types.each_pair do |key, type|
    if attributes.key?(attribute_map[key]) && attributes[attribute_map[key]].nil?
      transformed_hash["#{key}"] = nil
    elsif type =~ /\AArray<(.*)>/i
      # check to ensure the input is an array given that the attribute
      # is documented as an array but the input is not
      if attributes[attribute_map[key]].is_a?(Array)
        transformed_hash["#{key}"] = attributes[attribute_map[key]].map { |v| _deserialize($1, v) }
      end
    elsif !attributes[attribute_map[key]].nil?
      transformed_hash["#{key}"] = _deserialize(type, attributes[attribute_map[key]])
    end
  end
  new(transformed_hash)
end

.openapi_nullableObject

List of attributes with nullable: true



57
58
59
60
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 57

def self.openapi_nullable
  Set.new([
  ])
end

.openapi_typesObject

Attribute type mapping.



48
49
50
51
52
53
54
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 48

def self.openapi_types
  {
    :'client_key_id' => :'String',
    :'signature' => :'String',
    :'transport_public_key' => :'String'
  }
end

Instance Method Details

#==(o) ⇒ Object

Checks equality by comparing each attribute.

Parameters:

  • Object (Object)

    to be compared



159
160
161
162
163
164
165
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 159

def ==(o)
  return true if self.equal?(o)
  self.class == o.class &&
      client_key_id == o.client_key_id &&
      signature == o.signature &&
      transport_public_key == o.transport_public_key
end

#eql?(o) ⇒ Boolean

Parameters:

  • Object (Object)

    to be compared

Returns:

  • (Boolean)

See Also:

  • `==` method


169
170
171
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 169

def eql?(o)
  self == o
end

#hashInteger

Calculates hash code according to all attributes.

Returns:

  • (Integer)

    Hash code



175
176
177
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 175

def hash
  [client_key_id, signature, transport_public_key].hash
end

#list_invalid_propertiesObject

Show invalid properties with the reasons. Usually used together with valid?

Returns:

  • Array for valid properties with the reasons



99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 99

def list_invalid_properties
  warn '[DEPRECATED] the `list_invalid_properties` method is obsolete'
  invalid_properties = Array.new
  if @client_key_id.nil?
    invalid_properties.push('invalid value for "client_key_id", client_key_id cannot be nil.')
  end

  if @signature.nil?
    invalid_properties.push('invalid value for "signature", signature cannot be nil.')
  end

  if @transport_public_key.nil?
    invalid_properties.push('invalid value for "transport_public_key", transport_public_key cannot be nil.')
  end

  invalid_properties
end

#to_hashHash

Returns the object in the form of hash

Returns:

  • (Hash)

    Returns the object in the form of hash



204
205
206
207
208
209
210
211
212
213
214
215
216
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 204

def to_hash
  hash = {}
  self.class.attribute_map.each_pair do |attr, param|
    value = self.send(attr)
    if value.nil?
      is_nullable = self.class.openapi_nullable.include?(attr)
      next if !is_nullable || (is_nullable && !instance_variable_defined?(:"@#{attr}"))
    end

    hash[param] = _to_hash(value)
  end
  hash
end

#valid?Boolean

Check to see if the all the properties in the model are valid

Returns:

  • (Boolean)

    true if the model is valid



119
120
121
122
123
124
125
# File 'lib/ory-client/models/update_settings_flow_with_device_authn_method_rotate_secret.rb', line 119

def valid?
  warn '[DEPRECATED] the `valid?` method is obsolete'
  return false if @client_key_id.nil?
  return false if @signature.nil?
  return false if @transport_public_key.nil?
  true
end