Skip to content

Added consent-mgt methods and consent provider implementation - #2178

Merged
anushasunkada merged 2 commits into
mosip:develop-gofrom
anushasunkada:sachin-dev
Jul 17, 2026
Merged

anushasunkada merged 2 commits into
mosip:develop-gofrom
anushasunkada:sachin-dev

Conversation

@anushasunkada

@anushasunkada anushasunkada commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • New Features

    • Added consent checks during authorization flows.
    • Users can review, allow, or deny requested claims and scopes.
    • Consent decisions are remembered and reused until they expire or the request changes.
    • Added consent history and improved handling of accepted claims and permissions.
    • KYC attribute requests and response formats now follow client configuration.
  • Bug Fixes

    • Improved authorization reliability when consent data or runtime information is unavailable.
    • Fixed client update concurrency validation.

sacrana0 and others added 2 commits July 15, 2026 22:06
Signed-off-by: Sachin Rana <sacrana324@gmail.com>
Signed-off-by: anushasunkada <anushasunkada@gmail.com>
@coderabbitai

coderabbitai Bot commented Jul 17, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: d928136e-b581-400f-9d59-59f46dfa34df

📥 Commits

Reviewing files that changed from the base of the PR and between 953ebbf and 7ca8153.

⛔ Files ignored due to path filters (1)
  • esignet-service/go.sum is excluded by !**/*.sum
📒 Files selected for processing (25)
  • esignet-service/cmd/esignet/main.go
  • esignet-service/data/flows/flow-esignet.yaml
  • esignet-service/go.mod
  • esignet-service/internal/clientmgmt/db/query.sql
  • esignet-service/internal/consentmgmt/db/db.go
  • esignet-service/internal/consentmgmt/db/models.go
  • esignet-service/internal/consentmgmt/db/querier.go
  • esignet-service/internal/consentmgmt/db/query.sql
  • esignet-service/internal/consentmgmt/db/query.sql.go
  • esignet-service/internal/consentmgmt/db/schema.sql
  • esignet-service/internal/consentmgmt/model.go
  • esignet-service/internal/consentmgmt/model_test.go
  • esignet-service/internal/consentmgmt/service.go
  • esignet-service/internal/consentmgmt/service_test.go
  • esignet-service/internal/consentmgmt/util.go
  • esignet-service/internal/consentmgmt/util_test.go
  • esignet-service/internal/engine/actor_provider.go
  • esignet-service/internal/engine/clear_inputs_executor.go
  • esignet-service/internal/engine/consent_provider.go
  • esignet-service/internal/engine/consent_provider_test.go
  • esignet-service/internal/engine/executors.go
  • esignet-service/internal/engine/executors_test.go
  • esignet-service/internal/engine/mosip/authenticator.go
  • esignet-service/internal/engine/stub_providers_test.go
  • esignet-service/sqlc.yaml

Walkthrough

Adds PostgreSQL-backed consent persistence and hashing, implements consent resolution and recording, integrates consent prompts into the authorization flow, shares Redis runtime state, and updates authentication metadata and KYC response handling.

Changes

Consent enforcement

Layer / File(s) Summary
Consent persistence and hashing
esignet-service/internal/consentmgmt/*, esignet-service/sqlc.yaml
Adds consent schemas, generated queries, service operations, normalization, deterministic hashing, expiry handling, and unit tests.
Consent resolution and recording
esignet-service/internal/engine/consent_provider.go, esignet-service/internal/engine/consent_provider_test.go
Evaluates stored consent against authorization requests, builds prompts, records decisions, and validates error paths.
Runtime and authorization wiring
esignet-service/cmd/esignet/main.go, esignet-service/data/flows/flow-esignet.yaml
Shares Redis-backed runtime state, wires the consent provider, and routes authorization through consent checking and prompting.
Authentication metadata and KYC response updates
esignet-service/internal/engine/executors.go, esignet-service/internal/engine/mosip/authenticator.go
Builds runtime and application metadata, uses client response details, derives KYC consent from requested attributes, and returns encrypted KYC data as jwt.
Supporting interface and dependency updates
esignet-service/internal/engine/clear_inputs_executor.go, esignet-service/go.mod, esignet-service/internal/clientmgmt/db/query.sql
Adds metadata interface methods, updates dependencies, and names the optimistic timestamp SQL argument.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant AuthorizationFlow
  participant ConsentProvider
  participant RuntimeStore
  participant PostgreSQL
  AuthorizationFlow->>ConsentProvider: Resolve consent
  ConsentProvider->>RuntimeStore: Read authorization request
  ConsentProvider->>PostgreSQL: Fetch stored consent
  ConsentProvider-->>AuthorizationFlow: Prompt or continue
  AuthorizationFlow->>ConsentProvider: Record decision
  ConsentProvider->>PostgreSQL: Save consent and history
Loading

Possibly related issues

Possibly related PRs

Poem

Consent checks now wake,
Redis shares the runtime road,
Claims hash into trust.
Prompts wait when records fade,
PostgreSQL keeps the trail.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 golangci-lint (2.12.2)

level=error msg="[linters_context] typechecking error: pattern ./...: directory prefix . does not contain main module or its selected dependencies"


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants