Skip to content

Latest commit

 

History

History
49 lines (32 loc) · 1.67 KB

README.markdown

File metadata and controls

49 lines (32 loc) · 1.67 KB

Attribute index

Generate documentation for the IRMA scheme manager. You can browse a live version over here.

Installing

Dependencies:

  • git (to clone the scheme managers)
  • Python 3
  • Jinja2 (Debian package: python3-jinja2)
  • yarn

Before content can be generated, the scheme managers need to be downloaded:

git clone [email protected]:privacybydesign/pbdf-schememanager.git
git clone [email protected]:privacybydesign/irma-demo-schememanager.git

Currently the paths for these are hardcoded, but that can be changed if needed.

Running

To generate the HTML for the attribute index, run the script:

python3 update.py

If you want to have an up-to-date attribute index, it is recommended to update the scheme managers regularly and run the update script afterwards.

To generate the JavaScript handling issuance sessions of demo credentials, run:

yarn
yarn run build

Using untrusted scheme managers

Currently, scheme managers are considered trusted. Generating an attribute index for an untrusted scheme manager has at least the following problems at the moment:

  • URLs are not validated yet. They could start with javascript:, leading to XSS.
  • XML parsers are by default often vulnerable to security problems like the "billion laughs" attack, which causes enormous amounts of RAM to be used by the script. This is likely the case for the update script as well.

So, before an attribute index can be generated from untrusted scheme managers, these problems (and possibly others) need to be fixed first.