Documentation
¶
Overview ¶
Package httpsignature implements a strict RFC 9421 response-signature profile using Ed25519 and RFC 9530 Content-Digest fields.
Index ¶
- Constants
- Variables
- func DecodePrivateKey(value string) (ed25519.PrivateKey, error)
- func DecodePublicKey(value string) (ed25519.PublicKey, error)
- func EncodePrivateKey(key ed25519.PrivateKey) (string, error)
- func EncodePublicKey(key ed25519.PublicKey) (string, error)
- func FormatAcceptSignature(label, nonce, keyID string) (string, error)
- func FormatContentDigest(content []byte) string
- func FormatSignature(label string, signature []byte) (string, error)
- func FormatSignatureInput(label string, params Parameters) (string, string, error)
- func GenerateKey() (ed25519.PublicKey, ed25519.PrivateKey, error)
- func IsVerificationError(err error) bool
- func NewNonce() (string, error)
- func SignResponse(privateKey ed25519.PrivateKey, label string, params Parameters, status int, ...) (contentDigest, signatureInput, signature string, err error)
- func SignatureBase(status int, ...) ([]byte, error)
- func VerifyContentDigest(field string, content []byte) error
- type AcceptRequest
- type KeyResolver
- type Parameters
- type ResponseMessage
- type Verifier
Constants ¶
const ( HeaderAcceptSignature = "Accept-Signature" HeaderSignatureInput = "Signature-Input" HeaderSignature = "Signature" HeaderContentDigest = "Content-Digest" DefaultLabel = "sig1" DefaultTag = "fh-rfc9421-response" Algorithm = "ed25519" // CoveredComponents is the exact RFC 9421 Inner List used by this profile. // Request method and target URI bind the response to the request that caused // it; Content-Digest binds the exact response content bytes. CoveredComponents = "(\"@status\" \"content-digest\" \"content-type\" \"@method\";req \"@target-uri\";req)" )
Variables ¶
var ( ErrMalformed = errors.New("http signature: malformed structured field") ErrPolicy = errors.New("http signature: profile policy violation") ErrSignature = errors.New("http signature: verification failed") ErrDigest = errors.New("http signature: content digest mismatch") ErrExpired = errors.New("http signature: signature is expired or not yet valid") ErrNonce = errors.New("http signature: nonce mismatch") ErrUnsupported = errors.New("http signature: unsupported signature parameters") )
Functions ¶
func DecodePrivateKey ¶
func DecodePrivateKey(value string) (ed25519.PrivateKey, error)
func EncodePrivateKey ¶
func EncodePrivateKey(key ed25519.PrivateKey) (string, error)
EncodePrivateKey encodes the 32-byte Ed25519 seed as unpadded base64url.
func FormatAcceptSignature ¶
FormatAcceptSignature creates an RFC 9421 Accept-Signature dictionary member that requests this profile and asks the signer to echo the unique nonce.
func FormatContentDigest ¶
func FormatSignatureInput ¶
func FormatSignatureInput(label string, params Parameters) (string, string, error)
func GenerateKey ¶
func GenerateKey() (ed25519.PublicKey, ed25519.PrivateKey, error)
func IsVerificationError ¶
func SignResponse ¶
func SignResponse(privateKey ed25519.PrivateKey, label string, params Parameters, status int, contentType, method, targetURI string, content []byte) (contentDigest, signatureInput, signature string, err error)
SignResponse produces all three fields required by the response profile.
func SignatureBase ¶
func SignatureBase(status int, contentDigest, contentType, method, targetURI, signatureParams string) ([]byte, error)
SignatureBase constructs the exact RFC 9421 signature base for this profile.
func VerifyContentDigest ¶
Types ¶
type AcceptRequest ¶
type AcceptRequest struct {
Label string
Nonce string
KeyID string
Alg string
Tag string
Raw string
}
func ParseAcceptSignature ¶
func ParseAcceptSignature(field, label string) (AcceptRequest, error)
ParseAcceptSignature parses the requested labeled member and enforces the exact covered-component and algorithm profile used by this package.
type Parameters ¶
type ResponseMessage ¶
type ResponseMessage struct {
Status int
ContentDigest string
ContentType string
SignatureInput string
Signature string
}
ResponseMessage contains the exact HTTP values needed by this response signature profile. It is useful for clients, such as WASM, that do not use net/http for network I/O.
type Verifier ¶
type Verifier struct {
Label string
KeyID string
PublicKey ed25519.PublicKey
ResolveKey KeyResolver
ClockSkew time.Duration
MaxValidity time.Duration
Now func() time.Time
}
func (Verifier) VerifyMessage ¶
func (v Verifier) VerifyMessage(method, targetURI string, response ResponseMessage, body []byte, expectedNonce string) error
VerifyMessage verifies already-extracted HTTP response fields and never returns authenticated content to the caller on failure.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package httpclient provides optional net/http convenience wrappers around github.com/oarkflow/fh/pkg/httpsignature's RFC 9421 response-signature verification.
|
Package httpclient provides optional net/http convenience wrappers around github.com/oarkflow/fh/pkg/httpsignature's RFC 9421 response-signature verification. |