PolicySessionResolver
Opens the policy-server session that ocean-node checks on a download or compute job.
Nautilus holds one per instance, built from its credentials and sessionStore; use it
directly only with the standalone access(config, context) / compute(config, context)
functions (as context.policySessions).
Usage
const = new ({
: new (, { : 'https://wallet.example.org' })
})
const = await .({
, // the node that checks the policy
,
: 'a-service-id',
: '0x…' // signer.getAddress(), unchanged
}) What resolve does
- Neither the asset nor the service has
credentials({}counts as having them):null. - A cached session for (node, asset, service, consumer), opened less than
sessionTtlMsago: that one. A session that needed a presentation is first checked again (checkSessionId), since the verifier forgets it when it expires or restarts. An entry that is too old, or that the check does not report verified, is deleted and the steps below run again. - The node is known to have no policy server (
hasPolicyServer()isfalse: its status saysisPSConfigured: false, or an earlierinitiateshowed it):null. When the status does not say, as on upstream ocean-node 4.2.0, step 5 tells. - The service asks for a verifiable presentation and no credential provider is set: throws, before anything is signed.
initiate, fornode.policySessionAddress(consumerAddress): the address the node forwards to the policy server (for a Signer,consumerAddressitself; for a JWT, the address in the token). A node without a policy server answers with a 404 and no body:null; no session is cached, andhasPolicyServer()answersfalsefor 10 minutes unless it knew the node to have one. Otherwise the policy server checks it and opens a session, or refuses (PolicyDeniedError). The session id ismessage.sessionId; the openid4vp request ismessage.redirectUri.- Only when the
SSIpolicyasks for credentials: the provider'spresent(), thencheckSessionId, which must reportverificationResult: true(elsePolicyDeniedError). - The session is cached and returned as the payload for the node's
policyServerslot: a presented session in memory only, unlesspersistPresentedSessions.
Options
| Option | Type | Purpose |
|---|---|---|
credentials | CredentialProvider | Answers presentation requests. Not needed for address-only gates. |
sessionStore | SessionStore | Where sessions are kept. Default: MemorySessionStore. A store of your own gets only sessions opened without a presentation. |
persistPresentedSessions | boolean | Also keep presented sessions in sessionStore. Default false. See the warning below. |
sessionTtlMs | number | How long a cached session is reused, in ms from initiate. 0 caches nothing. Default: DEFAULT_SESSION_TTL_MS, 2 minutes. |
Methods
resolve(request) · setCredentialProvider(credentials | undefined) · clearSessions()
Errors
| Error | When |
|---|---|
PolicyDeniedError | The policy server refused the consumer: a reply with success: false and a 4xx (code: its status, reason: its message, bounded), or the verifier did not accept the presentation (code is undefined, reason names the failed policies, policyResults lists each policy's name, outcome and error, never the presentation). Also carries did, serviceId and consumerAddress. |
OceanNodeError | Anything else, with the status: the node's own 401 (nonce, signature, "Auth not configured"), its 404 (Not found: the asset is not indexed there), its 400 when it cannot reach the policy server, a network error, a timeout, a rate limit or a 5xx. |
Error | The service asks for a presentation and no credential provider is set. |