httpsignature

package
v0.0.24 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 10 Imported by: 0

Documentation

Overview

Package httpsignature implements a strict RFC 9421 response-signature profile using Ed25519 and RFC 9530 Content-Digest fields.

Index

Constants

View Source
const (
	HeaderAcceptSignature = "Accept-Signature"
	HeaderSignatureInput  = "Signature-Input"
	HeaderSignature       = "Signature"
	HeaderContentDigest   = "Content-Digest"

	DefaultLabel = "sig1"
	DefaultTag   = "fh-rfc9421-response"
	Algorithm    = "ed25519"

	// CoveredComponents is the exact RFC 9421 Inner List used by this profile.
	// Request method and target URI bind the response to the request that caused
	// it; Content-Digest binds the exact response content bytes.
	CoveredComponents = "(\"@status\" \"content-digest\" \"content-type\" \"@method\";req \"@target-uri\";req)"
)

Variables

View Source
var (
	ErrMalformed   = errors.New("http signature: malformed structured field")
	ErrPolicy      = errors.New("http signature: profile policy violation")
	ErrSignature   = errors.New("http signature: verification failed")
	ErrDigest      = errors.New("http signature: content digest mismatch")
	ErrExpired     = errors.New("http signature: signature is expired or not yet valid")
	ErrNonce       = errors.New("http signature: nonce mismatch")
	ErrUnsupported = errors.New("http signature: unsupported signature parameters")
)

Functions

func DecodePrivateKey

func DecodePrivateKey(value string) (ed25519.PrivateKey, error)

func DecodePublicKey

func DecodePublicKey(value string) (ed25519.PublicKey, error)

func EncodePrivateKey

func EncodePrivateKey(key ed25519.PrivateKey) (string, error)

EncodePrivateKey encodes the 32-byte Ed25519 seed as unpadded base64url.

func EncodePublicKey

func EncodePublicKey(key ed25519.PublicKey) (string, error)

func FormatAcceptSignature

func FormatAcceptSignature(label, nonce, keyID string) (string, error)

FormatAcceptSignature creates an RFC 9421 Accept-Signature dictionary member that requests this profile and asks the signer to echo the unique nonce.

func FormatContentDigest

func FormatContentDigest(content []byte) string

func FormatSignature

func FormatSignature(label string, signature []byte) (string, error)

func FormatSignatureInput

func FormatSignatureInput(label string, params Parameters) (string, string, error)

func GenerateKey

func GenerateKey() (ed25519.PublicKey, ed25519.PrivateKey, error)

func IsVerificationError

func IsVerificationError(err error) bool

func NewNonce

func NewNonce() (string, error)

func SignResponse

func SignResponse(privateKey ed25519.PrivateKey, label string, params Parameters, status int, contentType, method, targetURI string, content []byte) (contentDigest, signatureInput, signature string, err error)

SignResponse produces all three fields required by the response profile.

func SignatureBase

func SignatureBase(status int, contentDigest, contentType, method, targetURI, signatureParams string) ([]byte, error)

SignatureBase constructs the exact RFC 9421 signature base for this profile.

func VerifyContentDigest

func VerifyContentDigest(field string, content []byte) error

Types

type AcceptRequest

type AcceptRequest struct {
	Label string
	Nonce string
	KeyID string
	Alg   string
	Tag   string
	Raw   string
}

func ParseAcceptSignature

func ParseAcceptSignature(field, label string) (AcceptRequest, error)

ParseAcceptSignature parses the requested labeled member and enforces the exact covered-component and algorithm profile used by this package.

type KeyResolver

type KeyResolver func(keyID string) (ed25519.PublicKey, bool)

type Parameters

type Parameters struct {
	Created int64
	Expires int64
	Nonce   string
	KeyID   string
	Alg     string
	Tag     string
}

type ResponseMessage

type ResponseMessage struct {
	Status         int
	ContentDigest  string
	ContentType    string
	SignatureInput string
	Signature      string
}

ResponseMessage contains the exact HTTP values needed by this response signature profile. It is useful for clients, such as WASM, that do not use net/http for network I/O.

type Verifier

type Verifier struct {
	Label       string
	KeyID       string
	PublicKey   ed25519.PublicKey
	ResolveKey  KeyResolver
	ClockSkew   time.Duration
	MaxValidity time.Duration
	Now         func() time.Time
}

func (Verifier) VerifyMessage

func (v Verifier) VerifyMessage(method, targetURI string, response ResponseMessage, body []byte, expectedNonce string) error

VerifyMessage verifies already-extracted HTTP response fields and never returns authenticated content to the caller on failure.

Directories

Path Synopsis
Package httpclient provides optional net/http convenience wrappers around github.com/oarkflow/fh/pkg/httpsignature's RFC 9421 response-signature verification.
Package httpclient provides optional net/http convenience wrappers around github.com/oarkflow/fh/pkg/httpsignature's RFC 9421 response-signature verification.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL