Checks the digital product passport (DPP) data retrievable for a product identifier against the automated passport criteria of dpp-criteria (EN 18219, EN 18223 and related regulation).
Results state how many automated checks passed. They are not a certification and do not establish a presumption of conformity.
-
/is a start page: enter a product identifier (the URL encoded in the data carrier) and see the result per criterion./?productId=<identifier>runs the check directly and can be linked. -
GET /api/v1/validate/<product identifier>retrieves the passport like a phone scanning a data carrier (plain HTTPS GET, no credentials) and checks it. -
POST /api/v1/validatechecks a passport sent as JSON, or as compact JWS withContent-Type: application/vc+jwt(alsoapplication/jwt,application/jose). -
Criteria with
check.type: shaclare validated with SOyA: the passport goes through the SOyA web-cli endpointsacquireandvalidatefor the structure named in the criterion. Results belong to a criterion by the criterion ID at the start of each message. -
Criteria with
check.type: resolverequest the product identifier themselves (with the Accept header the criterion names) and needGET /api/v1/validate/<product identifier>; withPOSTthey are skipped. -
Criteria with
check.type: didsend the DIDs of the passport to didlint (DID Core, DID Resolution) and check linked verifiable presentations for the VC Data Model 2.0 context. The didlint instance is set withDIDLINT_URL(defaulthttps://didlint.ownyourdata.eu); it is the only service dpplint calls besides the passport and the resources it links. -
Criteria with
check.type: proofverify integrity proofs of the passport against a key of the economic operator:-
W3C Data Integrity proofs in the passport (
DataIntegrityProof, cryptosuiteeddsa-jcs-2022); -
the passport as compact JWS (VC-JOSE-COSE,
EdDSAorES256, key named bykid). WithGET, dpplint also requests the identifier withAccept: application/vc+jwt, application/jwt, application/jose; a JWS delivered that way has to carry the same passport as the JSON answer. -
the passport DID (
digitalProductPassportId,did:oyd): its DID document, resolved by didlint in the current version, carries in the service of typeDigitalProductPassportapayloadHash(SHA-256 multihash, base58btc) of the passport bytes delivered by that service'sserviceEndpoint. dpplint compares it with the bytes from theserviceEndpointand with the bytes delivered for the product identifier (withPOST: with the content sent).
Keys for Data Integrity and JWS are taken from a
did:keyor from the DID document resolved by didlint (Ed25519 or P-256, aspublicKeyMultibaseorpublicKeyJwk). Passports without a proof, and other proof formats, are reported asskipped. -
-
Criteria with
check.type: linkscheck everyRelatedResourceof the passport for the required attributes and send a HEAD request to its URL (at most 20 URLs per passport). A URL that does not answer gives a warning. -
Criteria whose condition does not hold are reported as
skipped. -
dpplint only contacts public addresses: URLs whose host resolves to loopback, private or link-local ranges are not retrieved.
DPPLINT_ALLOW_PRIVATE_NETWORKS=1lifts this for local development. -
API documentation:
/api-docs.
The image contains everything it needs at run time: the Rails API, the SOyA
web-cli (oydeu/soya-web-cli) and the criteria and SOyA structures of
dpp-criteria, built with soya init when the image is built. It does not
contact soya.ownyourdata.eu.
./build.sh
docker run --rm --platform linux/amd64 -p 3000:3000 oydeu/dpplint
curl -s http://localhost:3000/api/v1/validate/https://dpp.oydapp.eu/01/09520123456788/21/000001
./build.sh <ref> builds with a given commit or tag of dpp-criteria; the
default is main. GET /version shows the commit in use. The image is built
for linux/amd64, like the SOyA web-cli it contains.
kubernetes/ holds the manifests for dpplint.ownyourdata.eu: deployment,
service, certificate (cert-manager, ClusterIssuer letsencrypt-prod) and ingress
(nginx).
docker run --rm --platform linux/amd64 oydeu/dpplint test
Apache License 2.0 – see LICENSE.