sign

package
v0.1.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: Apache-2.0 Imports: 17 Imported by: 0

Documentation

Overview

Package sign 通过外部命令为 OFD 文档追加签名。

签名在包内容最终确定后追加:本包为每个文档体计算被引用文件的摘要并生成 Signature.xml(SignedInfo),把该文件字节通过标准输入交给外部命令,命令在 标准输出返回 SignedValue.dat 字节,本包再写回 Signatures.xml 与 OFD.xml。 签名算法与私钥由外部命令负责,本包不接触密钥。

Index

Constants

View Source
const (
	// DefaultSignatureMethod 是 SM2 + SM3 的签名算法 OID。
	DefaultSignatureMethod = "1.2.156.10197.1.501"
	// DefaultCheckMethod 是默认摘要算法。
	DefaultCheckMethod = "SM3"
)

Variables

This section is empty.

Functions

func Sign

func Sign(input any, w io.Writer, options Options) error

Sign 读取 input(文件路径、字节数据或 io.Reader),为每个文档体追加签名后写入 w。

Types

type Options

type Options struct {
	// Command 是外部签名命令,按空白拆分参数,不支持引号或 shell 语法。
	// 命令从标准输入读取 Signature.xml 字节,向标准输出写 SignedValue.dat 字节。
	Command string
	// ID 是签名标识,空值时使用 "sign-1"。
	ID string
	// ProviderName、ProviderVersion、Company 写入 SignedInfo 的 Provider。
	ProviderName    string
	ProviderVersion string
	Company         string
	// SignatureMethod 是签名算法 OID,空值时使用 DefaultSignatureMethod。
	SignatureMethod string
	// CheckMethod 是摘要算法,空值时使用 DefaultCheckMethod。
	CheckMethod string
	// Date 是签名时间,零值时使用当前时间。
	Date time.Time
	// Deterministic 使用固定 ZIP 时间,生成可复现的签名结果。
	// 需要 Date 固定时配合设置,否则 Signature.xml 中的签名时间仍会变化。
	Deterministic bool
	// Stamp 控制是否在 Signature.xml 写入 StampAnnot,让阅读器把印章图片绘制到页面上。
	// 为 nil 时不写入 StampAnnot(只验签,不显示印章)。
	Stamp *StampOptions
	// References 控制 SignedInfo/References 覆盖的文件集合;为 nil 时签名文档体目录下的全部文件(不含 OFD.xml)。
	References *ReferenceOptions
	// Environment 是传递给外部命令的额外环境变量,格式为 KEY=VALUE。
	Environment []string
}

Options 控制外部命令签名。

type ReferenceOptions

type ReferenceOptions struct {
	Include      []string
	Exclude      []string
	RootDocument bool
}

ReferenceOptions 选择 SignedInfo/References 覆盖的文件。 Include/Exclude 是不区分大小写的 glob(相对文档体目录,如 "Pages/**"、"*.xml"), 为空表示包含全部文件。RootDocument 为真时把 OFD.xml 纳入引用。

type StampOptions

type StampOptions struct {
	// PageRef 是 StampAnnot@PageRef 引用的页面 ID;为空时使用首个文档体的首页。
	PageRef string
	// Boundary 是 StampAnnot@Boundary,格式为 "x y width height";为空时在首页右下角放置默认大小印章。
	Boundary string
}

StampOptions 描述签章在页面上的位置。

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL