Documentation
¶
Overview ¶
Package parser 提供 OFD 文件的打开、解析和文档对象访问能力。
Index ¶
- func DigestBase64(data []byte) string
- type ASN1Node
- type BitString
- type CertificateInfo
- type CertificateRevocationOptions
- type CertificateTrustOptions
- type Common
- type DataHashResult
- type Document
- type ExtensionData
- type OFD
- type Page
- type ReferenceDigestResult
- type SESHeader
- type SESPicture
- type SESProperty
- type SESSignedValue
- type SESeal
- type SESealInfo
- type SM2SignatureFormat
- type SealData
- type SealInfo
- type Signature
- type SignatureComponentResult
- type SignatureDigestResult
- type SignatureVerificationOptions
- type SignatureVerificationResult
- func VerifySESSignedValue(value *SignedValue) (*SignatureVerificationResult, error)
- func VerifySESSignedValueWithOptions(value *SignedValue, options *SignatureVerificationOptions) (*SignatureVerificationResult, error)
- func VerifySESSignedValueWithTrust(value *SignedValue, options *CertificateTrustOptions) (*SignatureVerificationResult, error)
- type Signatures
- type SignedValue
- type TBSSign
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func DigestBase64 ¶ added in v0.1.0
DigestBase64 返回摘要的标准 Base64 表示,便于报告层输出。
Types ¶
type ASN1Node ¶ added in v0.1.0
type ASN1Node struct {
Class int
Tag int
Constructed bool
Bytes []byte
FullBytes []byte
Children []*ASN1Node
}
ASN1Node 是 SignedValue.dat 的通用 ASN.1 节点,用于保留标准结构之外的 厂商扩展,避免解析未知字段时丢失原始内容。
type CertificateInfo ¶ added in v0.1.0
type CertificateInfo struct {
SerialNumber string
Subject pkix.Name
Issuer pkix.Name
NotBefore time.Time
NotAfter time.Time
PublicKey string
}
CertificateInfo 是签名证书的可报告信息,不包含完整证书二进制。
type CertificateRevocationOptions ¶ added in v0.1.0
type CertificateRevocationOptions struct {
// CRLs 是 DER 或 PEM 编码的 X.509 CRL 列表。
CRLs [][]byte
// Issuers 是用于验证 CRL 签名的签发者证书 DER 列表。
Issuers [][]byte
// CurrentTime 是 CRL 有效期和吊销时间校验时间;为空时使用签名时间。
CurrentTime time.Time
}
CertificateRevocationOptions 配置离线 CRL 吊销校验。 校验不会访问 CRLDistributionPoints 或其他网络地址。
type CertificateTrustOptions ¶ added in v0.1.0
type CertificateTrustOptions struct {
// Roots 是信任根证书池。
Roots *gmx509.CertPool
// Intermediates 是额外的中间证书 DER;SES 内嵌证书会自动加入候选池。
Intermediates [][]byte
// CurrentTime 是证书链校验时间;为空时使用签名时间。
CurrentTime time.Time
}
CertificateTrustOptions 配置可选的证书链校验。 Roots 必须由调用方显式提供,避免解析器隐式依赖运行环境的系统根证书。
type DataHashResult ¶ added in v0.1.0
DataHashResult 是 SES 签名中 Signature.xml 数据摘要的校验结果。
type Document ¶
type Document struct {
Common
models.Document
Pages []*Page
Templates map[models.StID]*models.PageContent
DrawParams map[models.StID]*models.DrawParam
Res map[models.StID]*models.MultiMedia
FontRes map[models.StID]*models.Font
CompositeUnits map[models.StID]*models.CompositeGraphicUnit
PublicRes []*models.Res
DocumentRes []*models.Res
Signs map[string]*models.Signature
SignedValues map[string]*SignedValue
SignedValueErrors map[string]error
DigestResults map[string]*SignatureDigestResult
VerificationResults map[string]*SignatureVerificationResult
VerificationErrors map[string]error
Seals map[models.StID][]*SealInfo
Annotations map[models.StID]*models.PageAnnot
Attachments *models.Attachments
CustomTags *models.CustomTags
Extensions *models.Extensions
Versions map[string]*models.DocVersion
}
type ExtensionData ¶ added in v0.1.0
type ExtensionData struct {
OID asn1.ObjectIdentifier
Critical bool
Value []byte
}
ExtensionData 是 ASN.1 扩展数据项。
type ReferenceDigestResult ¶ added in v0.1.0
type ReferenceDigestResult struct {
FileRef string
ResolvedPath string
Expected []byte
Actual []byte
Exists bool
Match bool
Error string
}
ReferenceDigestResult 是单个 Reference 的摘要校验结果。
type SESPicture ¶ added in v0.1.0
SESPicture 是电子印章的图像信息。
type SESProperty ¶ added in v0.1.0
type SESProperty struct {
Type int64
Name string
CertificateType int64
Certificates [][]byte
CertificateValues []ASN1Node
CreateTime time.Time
ValidFrom time.Time
ValidTo time.Time
}
SESProperty 是电子印章的属性信息。
type SESSignedValue ¶ added in v0.1.0
type SESSignedValue struct {
TBS TBSSign
Certificate []byte
SignatureAlgorithm asn1.ObjectIdentifier
Signature BitString
}
SESSignedValue 是 OFD 和 GM/T 电子印章签名结构。
type SESeal ¶ added in v0.1.0
type SESeal struct {
// Raw 是 SESeal 的完整 DER 编码,是印章内部签名的待验证数据。
Raw []byte
SealInfo SESealInfo
Certificate []byte
SignatureAlgorithm asn1.ObjectIdentifier
Signature BitString
}
SESeal 是电子印章内部的签名对象。
type SESealInfo ¶ added in v0.1.0
type SESealInfo struct {
// Raw 是 SES_Seal_Info 的完整 DER 编码,是印章内部签名的待验证数据。
Raw []byte
Header SESHeader
ESID string
Property SESProperty
Picture SESPicture
Extensions []ExtensionData
}
SESealInfo 是电子印章的主体信息。
type SM2SignatureFormat ¶ added in v0.1.0
type SM2SignatureFormat string
SM2SignatureFormat 指定 BIT STRING 中 SM2 签名值的编码格式。
const ( // SM2SignatureFormatAuto 自动识别 DER SEQUENCE 或 64 字节 r||s。 SM2SignatureFormatAuto SM2SignatureFormat = "auto" // SM2SignatureFormatDER 表示 DER 编码的 SEQUENCE { r, s }。 SM2SignatureFormatDER SM2SignatureFormat = "der" // SM2SignatureFormatRaw 表示固定 64 字节的 r||s 编码。 SM2SignatureFormatRaw SM2SignatureFormat = "raw" )
type SealData ¶
SealData 存储提取的签章数据。
func ExtractSealData ¶
ExtractSealData 从签章数据中提取文件类型与内容,支持文件路径(string)、字节数据([]byte) 或 io.Reader 输入。
type SealInfo ¶
type SealInfo struct {
StampAnnot *models.StampAnnot
SealData *SealData
}
type SignatureComponentResult ¶ added in v0.1.0
type SignatureComponentResult struct {
// Valid 表示签名值通过公钥验证。
Valid bool
// Algorithm 是签名算法 OID。
Algorithm string
// SignatureFormat 是签名值实际使用的编码格式。
SignatureFormat string
// Certificate 是签名证书信息。
Certificate *CertificateInfo
// CertificateValid 表示证书在签名时间点有效。
CertificateValid bool
// TrustChecked 表示是否执行了证书链校验。
TrustChecked bool
// Trusted 表示证书链校验通过。
Trusted bool
// TrustError 是证书链校验失败原因。
TrustError string
// RevocationChecked 表示是否执行了证书吊销校验。
RevocationChecked bool
// RevocationStatus 是吊销状态:good、revoked、unknown 或 error。
RevocationStatus string
// RevocationError 是吊销校验失败原因。
RevocationError string
// Error 是验证失败原因。
Error string
}
SignatureComponentResult 是一层签名的证书和数学验证结果。
type SignatureDigestResult ¶ added in v0.1.0
type SignatureDigestResult struct {
// Method 是 References 声明的摘要算法。
Method string
// References 是被签名文件的逐项校验结果。
References []ReferenceDigestResult
// DataHash 是 TBS_Sign.DataHash 的校验结果;非 SES 签名时为空。
DataHash *DataHashResult
// Valid 表示所有可校验项目均通过。
Valid bool
}
SignatureDigestResult 是一个签名的摘要校验结果。
func VerifySignatureDigest ¶ added in v0.1.0
func VerifySignatureDigest(fileCache *core.Package, signaturePath string, signature *models.Signature, signedValue *SignedValue) (*SignatureDigestResult, error)
VerifySignatureDigest 校验 Signature.xml 的 References 摘要,以及 SES 签名中的 TBS_Sign.DataHash。DataHash 按 References 使用的摘要算法计算, 数据源是签名 XML 文件本身的包内字节。
type SignatureVerificationOptions ¶ added in v0.1.0
type SignatureVerificationOptions struct {
// UID 是 SM2 签名用户标识;为空时使用国密库默认标识。
UID []byte
// SignatureFormat 是签名值编码格式;为空时自动识别。
SignatureFormat SM2SignatureFormat
// Trust 是可选的证书链校验配置;为空时不执行证书链校验。
Trust *CertificateTrustOptions
// Revocation 是可选的离线 CRL 吊销校验配置;为空时不执行吊销校验。
Revocation *CertificateRevocationOptions
}
SignatureVerificationOptions 配置 SES 签名的 SM2 验证兼容行为。
type SignatureVerificationResult ¶ added in v0.1.0
type SignatureVerificationResult struct {
// Valid 表示印章内部签名和外层签名均通过。
Valid bool
// TrustChecked 表示是否使用显式信任根执行了证书链校验。
TrustChecked bool
// Trusted 表示两层签名证书均通过证书链校验。
Trusted bool
// RevocationChecked 表示是否执行了证书吊销校验。
RevocationChecked bool
// RevocationValid 表示两层证书均未被显式提供的 CRL 吊销。
RevocationValid bool
// VerificationTime 是验证证书有效期使用的签名时间。
VerificationTime time.Time
// Seal 是印章内部签名结果。
Seal SignatureComponentResult
// Outer 是 SignedValue 外层签名结果。
Outer SignatureComponentResult
}
SignatureVerificationResult 是 SES 签名的密码学验证结果。
func VerifySESSignedValue ¶ added in v0.1.0
func VerifySESSignedValue(value *SignedValue) (*SignatureVerificationResult, error)
VerifySESSignedValue 验证 SES 电子印章的两层 SM2 签名。 印章内部签名验证 SES_Seal_Info,外层签名验证 TBS_Sign;两层分别使用各自证书。
func VerifySESSignedValueWithOptions ¶ added in v0.1.0
func VerifySESSignedValueWithOptions(value *SignedValue, options *SignatureVerificationOptions) (*SignatureVerificationResult, error)
VerifySESSignedValueWithOptions 使用显式 SM2 UID 和签名值编码格式验证 SES 签名。
func VerifySESSignedValueWithTrust ¶ added in v0.1.0
func VerifySESSignedValueWithTrust(value *SignedValue, options *CertificateTrustOptions) (*SignatureVerificationResult, error)
VerifySESSignedValueWithTrust 使用显式信任根验证 SES 两层签名和证书链。 Trusted 与 Valid 分离:证书链不可信不会改变签名数学验证结果。
type Signatures ¶
type SignedValue ¶ added in v0.1.0
type SignedValue struct {
Raw []byte
ASN1 *ASN1Node
Format string
SES *SESSignedValue
}
SignedValue 是 OFD SignedValue.dat 的解析结果。 Raw 和 ASN1 保留完整原始内容,识别为 SES 后同时提供结构化字段。
func ParseSignedValue ¶ added in v0.1.0
func ParseSignedValue(data []byte) (*SignedValue, error)
ParseSignedValue 解析 SignedValue.dat。 合法但不是 SES 电子印章格式的 ASN.1 文件仍会返回结果,并通过 Format="ASN.1" 保留完整通用树;只有二进制不是完整 ASN.1 数据时才返回错误。