a2aproject / a2aproject/a2a-go

[Task] Implement utilities for AgentCard signing

Aperta
#141 2 commenti 0 reazioni 1 assegnatario Assegnata a @Iwaniukooo11 Vedi su GitHub
Lingua principale
Go
Stelle
460
Fork
93
Merge medio
2g 21h
PR unite (30g)
9

Descrizione

Implement utilities for AgentCard signatures.
Signatures are described [in the spec](https://a2a-protocol.org/v0.3.0/specification/#555-agentinterface-object) and this Python [PR](https://github.com/a2aproject/a2a-python/pull/581) can serve as a reference.

1. Create a new package `a2acrypto`.
2. Make it export a verfifier.
```go
type KeyResolver interface {
ResolveKey(kid, jku string) (crypto.PublicKey, error)
}

type VerifierConfig struct {
KeyResolver KeyResolver
}

func NewVerifier(config VerifierConfig) *Verifier { ... }

func (v *Verifier) Verify(card *a2a.AgentCard, signature *a2a.AgentCardSignature) error { ... }
```
3. Make it export a signer.
```go
type SignerConfig struct {
PrivateKey crypto.Signer
KeyID string
Algorithm string
JWKSURL string
}

func NewSigner(config SignerConfig) *Signer { ... }

func (s *Signer) Sign(card *a2a.AgentCard) (*a2a.AgentCardSignature, error) { ... }
```
4. Make `a2aclient.Client` be configurable with `a2aclient.WithCardVerifier(*a2acrypto.Verifier)`. If set, the verifier should run when `GetAgentCard()` is called.
5. Make `agentcard.Resolver` have an `*a2acrypto.Verifier` field. If set, the verifier should be used in `Resolve()`.
6. Use the signer to implement an `a2asrv.NewSignedCardProducer` for wrapping a user-provided AgentCardProducer.
```go
type signedAgentCardProducer struct {
wrapped AgentCardProducer
signer *a2asrv.Signer
}

func (p *signedAgentCardProducer) Card(ctx context.Context) (*a2a.AgentCard, error) { ... }

func NewSignedCardProducer(*a2acrypto.Signer, AgentCardProducer) AgentCardProducer { ... }
```

Add tests to verify the implementation. Can use Python or other SDK to generate an expected signature to compare against.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Read the linked spec and Python PR to understand the signature scheme. Start by creating the new a2acrypto package and implementing the Verifier and Signer interfaces as described. Look at existing a2aclient.Client and agentcard.Resolver to see where to integrate the verifier. Write tests that generate signatures with the Python SDK and verify them with the Go implementation.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
go
Ambito
backend-api-design
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
45/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.