
View on GitHub


0 mins
Test Coverage
 * Copyright (C) 2022 Nuts community
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * GNU General Public License for more details.
 * You should have received a copy of the GNU General Public License
 * along with this program.  If not, see <>.

package didnuts

import (
    ssi ""
    nutsCrypto ""

var _ management.DocManipulator = (*Manipulator)(nil)

// Manipulator contains helper methods to update a Nuts DID document.
type Manipulator struct {
    // KeyCreator is used for getting a fresh key and use it to generate the Nuts DID
    KeyCreator nutsCrypto.KeyCreator
    // Updater is used for updating DID documents after the operation has been performed
    Updater management.DocUpdater
    // Resolver is used for resolving DID Documents
    Resolver resolver.DIDResolver

// Deactivate updates the DID Document so it can no longer be updated
// It removes key material, services and controllers.
func (u Manipulator) Deactivate(ctx context.Context, id did.DID) error {
    _, _, err := u.Resolver.Resolve(id, &resolver.ResolveMetadata{AllowDeactivated: true})
    if err != nil {
        return err
    // A deactivated DID resolves to an empty DID document.
    emptyDoc := CreateDocument()
    emptyDoc.ID = id
    return u.Updater.Update(ctx, id, emptyDoc)

// AddVerificationMethod adds a new key as a VerificationMethod to the document.
// The key is added to the VerficationMethod relationships specified by keyUsage.
func (u Manipulator) AddVerificationMethod(ctx context.Context, id did.DID, keyUsage management.DIDKeyFlags) (*did.VerificationMethod, error) {
    doc, meta, err := u.Resolver.Resolve(id, &resolver.ResolveMetadata{AllowDeactivated: true})
    if err != nil {
        return nil, err
    if meta.Deactivated {
        return nil, resolver.ErrDeactivated
    method, err := CreateNewVerificationMethodForDID(ctx, doc.ID, u.KeyCreator)
    if err != nil {
        return nil, err
    method.Controller = doc.ID
    applyKeyUsage(doc, method, keyUsage)
    if err = u.Updater.Update(ctx, id, *doc); err != nil {
        return nil, err
    return method, nil

// RemoveVerificationMethod is a helper function to remove a verificationMethod from a DID Document
func (u Manipulator) RemoveVerificationMethod(ctx context.Context, id did.DID, keyID did.DIDURL) error {
    doc, meta, err := u.Resolver.Resolve(id, &resolver.ResolveMetadata{AllowDeactivated: true})
    if err != nil {
        return err
    if meta.Deactivated {
        return resolver.ErrDeactivated
    lenBefore := len(doc.VerificationMethod)
    if lenBefore == len(doc.VerificationMethod) {
        // do not update if nothing has changed
        return nil

    return u.Updater.Update(ctx, id, *doc)

// CreateNewVerificationMethodForDID creates a new VerificationMethod of type JsonWebKey2020
// with a freshly generated key for a given DID.
func CreateNewVerificationMethodForDID(ctx context.Context, id did.DID, keyCreator nutsCrypto.KeyCreator) (*did.VerificationMethod, error) {
    key, err := keyCreator.New(ctx, didSubKIDNamingFunc(id))
    if err != nil {
        return nil, err
    keyID, err := did.ParseDIDURL(key.KID())
    if err != nil {
        return nil, err
    method, err := did.NewVerificationMethod(*keyID, ssi.JsonWebKey2020, id, key.Public())
    if err != nil {
        return nil, err
    return method, nil

func (u Manipulator) CreateService(_ context.Context, _ did.DID, _ did.Service) (*did.Service, error) {
    return nil, fmt.Errorf("CreateService() is not supported for did:%s", MethodName)

func (u Manipulator) UpdateService(_ context.Context, _ did.DID, _ ssi.URI, _ did.Service) (*did.Service, error) {
    return nil, fmt.Errorf("UpdateService() is not supported for did:%s", MethodName)

func (u Manipulator) DeleteService(_ context.Context, _ did.DID, _ ssi.URI) error {
    return fmt.Errorf("DeleteService() is not supported for did:%s", MethodName)