a2aproject / a2aproject/a2a-go
[Task] Implement utilities for AgentCard signing
- Lenguaje dominante
- Go
- Estrellas
- 460
- Forks
- 93
- Merge medio
- 2 d 21 h
- PR fusionados (30 d)
- 9
Descripción
Implement utilities for AgentCard signatures.
Signatures are described [in the spec](https://a2a-protocol.org/v0.3.0/specification/#555-agentinterface-object) and this Python [PR](https://github.com/a2aproject/a2a-python/pull/581) can serve as a reference.
1. Create a new package `a2acrypto`.
2. Make it export a verfifier.
```go
type KeyResolver interface {
ResolveKey(kid, jku string) (crypto.PublicKey, error)
}
type VerifierConfig struct {
KeyResolver KeyResolver
}
func NewVerifier(config VerifierConfig) *Verifier { ... }
func (v *Verifier) Verify(card *a2a.AgentCard, signature *a2a.AgentCardSignature) error { ... }
```
3. Make it export a signer.
```go
type SignerConfig struct {
PrivateKey crypto.Signer
KeyID string
Algorithm string
JWKSURL string
}
func NewSigner(config SignerConfig) *Signer { ... }
func (s *Signer) Sign(card *a2a.AgentCard) (*a2a.AgentCardSignature, error) { ... }
```
4. Make `a2aclient.Client` be configurable with `a2aclient.WithCardVerifier(*a2acrypto.Verifier)`. If set, the verifier should run when `GetAgentCard()` is called.
5. Make `agentcard.Resolver` have an `*a2acrypto.Verifier` field. If set, the verifier should be used in `Resolve()`.
6. Use the signer to implement an `a2asrv.NewSignedCardProducer` for wrapping a user-provided AgentCardProducer.
```go
type signedAgentCardProducer struct {
wrapped AgentCardProducer
signer *a2asrv.Signer
}
func (p *signedAgentCardProducer) Card(ctx context.Context) (*a2a.AgentCard, error) { ... }
func NewSignedCardProducer(*a2acrypto.Signer, AgentCardProducer) AgentCardProducer { ... }
```
Add tests to verify the implementation. Can use Python or other SDK to generate an expected signature to compare against.
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.