httpsignature

package
v0.0.25 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 10 Imported by: 0

README

RFC 9421 HTTP response signatures

mw/httpsignature implements a strict, interoperable RFC 9421 response-signature profile using Ed25519 and an RFC 9530 Content-Digest.

The client sends Accept-Signature with a unique nonce. The server signs:

  • @status
  • content-digest
  • content-type
  • the originating request's @method using ;req
  • the originating request's @target-uri using ;req

The signature parameters include created, expires, nonce, keyid, alg="ed25519", and tag="fh-rfc9421-response".

middleware, err := httpsignature.New(httpsignature.Config{
    PrivateKey: privateKey,
    KeyID:      "response-signing-2026-01",
    Origin:     "https://api.example.com",
})
if err != nil {
    log.Fatal(err)
}
app.Use(middleware)

AllowedOrigins can list additional exact origins when one server intentionally supports multiple authorities. The middleware selects the signing origin from the validated request Host, so @target-uri continues to match what the client requested. The secure WASM example uses this only for the development authorities localhost, 127.0.0.1, and 0.0.0.0; production should normally configure one HTTPS origin.

Use pkg/httpsignature.Client for a fail-closed Go client. See examples/rfc9421 for Go and browser implementations.

The negotiated profile deliberately rejects Content-Encoding; otherwise an intermediary could modify an unsigned content-coding header and change how authenticated bytes are interpreted. Install it after authorization and as the last response-transform middleware. Do not enable compression on these routes or use streaming responses because the final content must be buffered and digested. Use HTTPS even though responses are signed.

The default nonce store is bounded and process-local. Multi-instance deployments must provide a distributed atomic kv.Store.

For a single instance that needs nonce records to survive a restart, construct kv.NewFileStore(dir, kv.WithFileGCInterval(gcInterval)) and pass it as Config.NonceStore.

Documentation

Overview

Package httpsignature signs FH responses using the Ed25519 response profile implemented by pkg/httpsignature and the wire format defined by RFC 9421.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CheckAndStore

func CheckAndStore(store kv.Store, mu *sync.Mutex, key string, expiresAt time.Time, maxEntries int) (bool, error)

func New

func New(config Config) (fh.HandlerFunc, error)

Types

type Config

type Config struct {
	PrivateKey ed25519.PrivateKey
	KeyID      string
	Label      string
	// Origin is the externally visible request origin, such as
	// https://api.example.com. It is required so @target-uri is not derived from
	// attacker-controlled forwarding headers.
	Origin string
	// AllowedOrigins adds exact alternative external origins. The request Host
	// selects one of these validated origins; unlisted hosts fail closed.
	AllowedOrigins []string
	// AllowInsecureDevelopmentOrigins permits explicit HTTP origins outside
	// loopback. Use only for development servers intentionally exposed to a LAN.
	// The default is false, so production remains HTTPS-only.
	AllowInsecureDevelopmentOrigins bool

	Validity    time.Duration
	MaxBodySize int
	NonceStore  kv.Store
	Now         func() time.Time
	Skip        func(fh.Ctx) bool
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL