spi

package
v6.2.13 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: GPL-3.0 Imports: 13 Imported by: 0

Documentation

Overview

Package spi is a generated GoMock package.

Index

Constants

This section is empty.

Variables

View Source
var ErrKeyAlreadyExists = errors.New("key already exists")

ErrKeyAlreadyExists indicates that a private key for this keyID already exists.

View Source
var ErrNotFound = errors.New("entry not found")

ErrNotFound indicates that the specified crypto storage entry couldn't be found.

View Source
var KidPattern = regexp.MustCompile(`^(?:(?:[\da-zA-Z_\- :#.])|(?:%[0-9a-fA-F]{2}))+$`)

KidPattern is the regexp for acceptable kids

Functions

func GenerateAndStore

func GenerateAndStore(ctx context.Context, store Storage, keyName string) (crypto.PublicKey, string, error)

GenerateAndStore generates a new key pair and stores it in the provided storage. It always generates a plain, exportable EC key, which can be used for both signing and decryption.

func GenerateKeyPair

func GenerateKeyPair() (*ecdsa.PrivateKey, error)

GenerateKeyPair generates a new key pair using the default key type. It's intended to be used by crypto backends that don't create unexportable keys.

Types

type KeyNameVersion

type KeyNameVersion struct {
	KeyName string
	Version string
}

KeyNameVersion contains a key name and version. It used as return argument for ListPrivateKeys.

type MockStorage

type MockStorage struct {
	// contains filtered or unexported fields
}

MockStorage is a mock of Storage interface.

func NewMockStorage

func NewMockStorage(ctrl *gomock.Controller) *MockStorage

NewMockStorage creates a new mock instance.

func (*MockStorage) CheckHealth

func (m *MockStorage) CheckHealth() map[string]core.Health

CheckHealth mocks base method.

func (*MockStorage) DeletePrivateKey

func (m *MockStorage) DeletePrivateKey(ctx context.Context, keyName string) error

DeletePrivateKey mocks base method.

func (*MockStorage) EXPECT

func (m *MockStorage) EXPECT() *MockStorageMockRecorder

EXPECT returns an object that allows the caller to indicate expected use.

func (*MockStorage) GetPrivateKey

func (m *MockStorage) GetPrivateKey(ctx context.Context, keyName, version string) (crypto.Signer, error)

GetPrivateKey mocks base method.

func (*MockStorage) ListPrivateKeys

func (m *MockStorage) ListPrivateKeys(ctx context.Context) []KeyNameVersion

ListPrivateKeys mocks base method.

func (*MockStorage) Name

func (m *MockStorage) Name() string

Name mocks base method.

func (*MockStorage) NewPrivateKey

func (m *MockStorage) NewPrivateKey(ctx context.Context, keyName string) (crypto.PublicKey, string, error)

NewPrivateKey mocks base method.

func (*MockStorage) PrivateKeyExists

func (m *MockStorage) PrivateKeyExists(ctx context.Context, keyName, version string) (bool, error)

PrivateKeyExists mocks base method.

func (*MockStorage) SavePrivateKey

func (m *MockStorage) SavePrivateKey(ctx context.Context, keyname string, key crypto.PrivateKey) error

SavePrivateKey mocks base method.

type MockStorageMockRecorder

type MockStorageMockRecorder struct {
	// contains filtered or unexported fields
}

MockStorageMockRecorder is the mock recorder for MockStorage.

func (*MockStorageMockRecorder) CheckHealth

func (mr *MockStorageMockRecorder) CheckHealth() *gomock.Call

CheckHealth indicates an expected call of CheckHealth.

func (*MockStorageMockRecorder) DeletePrivateKey

func (mr *MockStorageMockRecorder) DeletePrivateKey(ctx, keyName any) *gomock.Call

DeletePrivateKey indicates an expected call of DeletePrivateKey.

func (*MockStorageMockRecorder) GetPrivateKey

func (mr *MockStorageMockRecorder) GetPrivateKey(ctx, keyName, version any) *gomock.Call

GetPrivateKey indicates an expected call of GetPrivateKey.

func (*MockStorageMockRecorder) ListPrivateKeys

func (mr *MockStorageMockRecorder) ListPrivateKeys(ctx any) *gomock.Call

ListPrivateKeys indicates an expected call of ListPrivateKeys.

func (*MockStorageMockRecorder) Name

func (mr *MockStorageMockRecorder) Name() *gomock.Call

Name indicates an expected call of Name.

func (*MockStorageMockRecorder) NewPrivateKey

func (mr *MockStorageMockRecorder) NewPrivateKey(ctx, keyName any) *gomock.Call

NewPrivateKey indicates an expected call of NewPrivateKey.

func (*MockStorageMockRecorder) PrivateKeyExists

func (mr *MockStorageMockRecorder) PrivateKeyExists(ctx, keyName, version any) *gomock.Call

PrivateKeyExists indicates an expected call of PrivateKeyExists.

func (*MockStorageMockRecorder) SavePrivateKey

func (mr *MockStorageMockRecorder) SavePrivateKey(ctx, keyname, key any) *gomock.Call

SavePrivateKey indicates an expected call of SavePrivateKey.

type PublicKeyEntry

type PublicKeyEntry struct {
	Period core.Period `json:"period"`

	Key map[string]interface{} `json:"publicKeyJwk,omitempty"`
	// contains filtered or unexported fields
}

PublicKeyEntry is a public key entry also containing the period it's valid for.

func (*PublicKeyEntry) FromJWK

func (pke *PublicKeyEntry) FromJWK(key jwk.Key) error

FromJWK fills the publicKeyEntry with key material from the given key

func (PublicKeyEntry) JWK

func (pke PublicKeyEntry) JWK() jwk.Key

JWK returns the key as JSON Web Key.

func (*PublicKeyEntry) UnmarshalJSON

func (pke *PublicKeyEntry) UnmarshalJSON(bytes []byte) error

UnmarshalJSON parses the json

type Storage

type Storage interface {
	core.HealthCheckable
	// NewPrivateKey creates a new private key. The backend will create the version and publicKey.
	// It should be preferred over generating a key in the application and saving it to the storage,
	// as it allows for unexportable (safer) keys.
	NewPrivateKey(ctx context.Context, keyName string) (publicKey crypto.PublicKey, version string, err error)
	// GetPrivateKey from the storage backend and return its handler as an implementation of crypto.Signer.
	GetPrivateKey(ctx context.Context, keyName string, version string) (crypto.Signer, error)
	// PrivateKeyExists checks if the private key indicated with the keyname/version is stored in the storage backend.
	PrivateKeyExists(ctx context.Context, keyName string, version string) (bool, error)
	// SavePrivateKey imports the key under the keyname in the storage backend.
	// see https://github.com/nuts-foundation/nuts-node/issues/3292
	SavePrivateKey(ctx context.Context, keyname string, key crypto.PrivateKey) error
	// ListPrivateKeys returns the KeyName and Version of the private keys that are present. Returns a []string(nil) if there was a problem.
	ListPrivateKeys(ctx context.Context) []KeyNameVersion
	// DeletePrivateKey removes the private key with the given keyname from the storage backend.
	DeletePrivateKey(ctx context.Context, keyName string) error
}

Storage interface containing functions for storing and retrieving keys.

func NewValidatedKIDBackendWrapper

func NewValidatedKIDBackendWrapper(backend Storage, kidPattern *regexp.Regexp) Storage

NewValidatedKIDBackendWrapper creates a new wrapper for storage backends. Every call to the backend which takes a kid as param, gets the kid validated against the provided kidPattern.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL