Documentation
¶
Overview ¶
Package parser 提供 OFD 文件的打开、解析和文档对象访问能力。
Index ¶
- func DigestBase64(data []byte) string
- type ASN1Node
- type BitString
- type CertificateInfo
- type CertificateRevocationOptions
- type CertificateTrustOptions
- type DataHashResult
- type Document
- func (p *Document) AnnotationPageCount() int
- func (p *Document) DeleteVerificationError(id string)
- func (p *Document) DeleteVerificationResult(id string)
- func (p *Document) DocumentResourceList() []*models.Res
- func (p *Document) Fonts() map[models.StID]*models.Font
- func (p *Document) ForEachFont(fn func(id models.StID, font *models.Font) bool)
- func (p *Document) ForEachMedia(fn func(id models.StID, media *models.MultiMedia) bool)
- func (p *Document) ForEachPage(fn func(index int, page *Page) bool)
- func (p *Document) ForEachSignature(fn func(id string, signature *models.Signature) bool)
- func (p *Document) ForEachSignedValue(fn func(id string, value *SignedValue) bool)
- func (p *Document) GetAnnotation(pageID models.StID) *models.PageAnnot
- func (p *Document) GetAttachments() *models.Attachments
- func (p *Document) GetColorSpace(id models.StID) *models.ColorSpace
- func (p *Document) GetCompositeUnit(id models.StID) *models.CompositeGraphicUnit
- func (p *Document) GetCustomTags() *models.CustomTags
- func (p *Document) GetDigestResult(id string) *SignatureDigestResult
- func (p *Document) GetDrawParam(id models.StID) *models.DrawParam
- func (p *Document) GetExtensions() *models.Extensions
- func (p *Document) GetFont(id models.StID) *models.Font
- func (p *Document) GetMedia(id models.StID) *models.MultiMedia
- func (p *Document) GetPage(index int) (*Page, error)
- func (p *Document) GetSeals(pageID models.StID) []*SealInfo
- func (p *Document) GetSignature(id string) *models.Signature
- func (p *Document) GetSignedValue(id string) *SignedValue
- func (p *Document) GetSignedValueError(id string) error
- func (p *Document) GetTemplate(id models.StID) *models.PageContent
- func (p *Document) GetVerificationError(id string) error
- func (p *Document) GetVerificationResult(id string) *SignatureVerificationResult
- func (p *Document) GetVersion(id string) *models.DocVersion
- func (p *Document) Init(fileCache *core.Package, dir models.StLoc)
- func (p *Document) LoadAnnotation(pageID models.StID) (*models.PageAnnot, error)
- func (p *Document) LoadAttachments() (*models.Attachments, error)
- func (p *Document) LoadCustomTags() (*models.CustomTags, error)
- func (p *Document) LoadExtensions() (*models.Extensions, error)
- func (p *Document) LoadTemplate(id models.StID) (*models.PageContent, error)
- func (p *Document) LoadVersion(id string) (*models.DocVersion, error)
- func (p *Document) PageCount() int
- func (p *Document) PageList() []*Page
- func (p *Document) ParseSigns(file *models.StLoc) error
- func (p *Document) PublicResourceList() []*models.Res
- func (p *Document) SetVerificationError(id string, err error)
- func (p *Document) SetVerificationResult(id string, value *SignatureVerificationResult)
- func (p *Document) SignedValuesSnapshot() map[string]*SignedValue
- type ExtensionData
- type OFD
- type Options
- type Page
- func (p *Page) AcquireLease() (*PageLease, error)
- func (p *Page) Actions() *models.Actions
- func (p *Page) Area() *models.CtPageArea
- func (p *Page) Content() *models.Content
- func (p *Page) EnsureLoaded() error
- func (p *Page) PageRes() []models.StLoc
- func (p *Page) PageResourceLocations() []models.StLoc
- func (p *Page) PhysicalBox() (models.StBox, error)
- func (p *Page) PhysicalBoxMetadata() (models.StBox, error)
- func (p *Page) Template() []models.Template
- func (p *Page) WithPageContent(fn func(*models.PageContent) error) error
- type PageLease
- type ReferenceDigestResult
- type SESHeader
- type SESPicture
- type SESProperty
- type SESSignedValue
- type SESeal
- type SESealInfo
- type SM2SignatureFormat
- type SealData
- type SealInfo
- type Signature
- type SignatureComponentResult
- type SignatureDigestResult
- type SignatureVerificationOptions
- type SignatureVerificationResult
- func VerifySESSignedValue(value *SignedValue) (*SignatureVerificationResult, error)
- func VerifySESSignedValueWithOptions(value *SignedValue, options *SignatureVerificationOptions) (*SignatureVerificationResult, error)
- func VerifySESSignedValueWithTrust(value *SignedValue, options *CertificateTrustOptions) (*SignatureVerificationResult, error)
- type Signatures
- type SignedValue
- type TBSSign
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func DigestBase64 ¶ added in v0.1.0
DigestBase64 返回摘要的标准 Base64 表示,便于报告层输出。
Types ¶
type ASN1Node ¶ added in v0.1.0
type ASN1Node struct {
Class int
Tag int
Constructed bool
Bytes []byte
FullBytes []byte
Children []*ASN1Node
}
ASN1Node 是 SignedValue.dat 的通用 ASN.1 节点,用于保留标准结构之外的 厂商扩展,避免解析未知字段时丢失原始内容。
type CertificateInfo ¶ added in v0.1.0
type CertificateInfo struct {
SerialNumber string
Subject pkix.Name
Issuer pkix.Name
NotBefore time.Time
NotAfter time.Time
PublicKey string
// RawDER 是证书的 DER 编码内容。
RawDER []byte
}
CertificateInfo 是签名证书的可报告信息,并保留原始 DER 以便导出。
type CertificateRevocationOptions ¶ added in v0.1.0
type CertificateRevocationOptions struct {
// CRLs 是 DER 或 PEM 编码的 X.509 CRL 列表。
CRLs [][]byte
// Issuers 是用于验证 CRL 签名的签发者证书 DER 列表。
Issuers [][]byte
// CurrentTime 是 CRL 有效期和吊销时间校验时间;为空时使用签名时间。
CurrentTime time.Time
}
CertificateRevocationOptions 配置离线 CRL 吊销校验。 校验不会访问 CRLDistributionPoints 或其他网络地址。
type CertificateTrustOptions ¶ added in v0.1.0
type CertificateTrustOptions struct {
// Roots 是信任根证书池。
Roots *gmx509.CertPool
// Intermediates 是额外的中间证书 DER;SES 内嵌证书会自动加入候选池。
Intermediates [][]byte
// CurrentTime 是证书链校验时间;为空时使用签名时间。
CurrentTime time.Time
}
CertificateTrustOptions 配置可选的证书链校验。 Roots 必须由调用方显式提供,避免解析器隐式依赖运行环境的系统根证书。
type DataHashResult ¶ added in v0.1.0
DataHashResult 是 SES 签名中 Signature.xml 数据摘要的校验结果。
type Document ¶
type Document struct {
BaseLoc models.StLoc
FileCache *core.Package
models.Document
Pages []*Page
// contains filtered or unexported fields
}
func (*Document) AnnotationPageCount ¶ added in v0.1.3
AnnotationPageCount 返回声明了注解的页面数量(不读取注解内容)。
func (*Document) DeleteVerificationError ¶ added in v0.1.1
DeleteVerificationError 删除签名验证错误。
func (*Document) DeleteVerificationResult ¶ added in v0.1.1
DeleteVerificationResult 删除签名验证结果。
func (*Document) DocumentResourceList ¶ added in v0.1.1
DocumentResourceList 返回文档资源文件的快照。
func (*Document) ForEachFont ¶ added in v0.1.1
ForEachFont 遍历当前文档已登记的字体资源。 回调返回 false 时停止遍历。
func (*Document) ForEachMedia ¶ added in v0.1.1
ForEachMedia 遍历当前文档已登记的多媒体资源。 回调返回 false 时停止遍历。
func (*Document) ForEachPage ¶ added in v0.1.1
ForEachPage 按文档顺序遍历页面。 回调返回 false 时停止遍历。
func (*Document) ForEachSignature ¶ added in v0.1.3
ForEachSignature 遍历当前文档的签名。回调返回 false 时停止遍历。
func (*Document) ForEachSignedValue ¶ added in v0.1.1
func (p *Document) ForEachSignedValue(fn func(id string, value *SignedValue) bool)
ForEachSignedValue 遍历已解析的签名值。 回调返回 false 时停止遍历。
func (*Document) GetAnnotation ¶ added in v0.1.1
GetAnnotation 按需读取指定页面的注解,读取失败时返回 nil。
func (*Document) GetAttachments ¶ added in v0.1.1
func (p *Document) GetAttachments() *models.Attachments
GetAttachments 返回附件清单,读取失败时返回 nil。
func (*Document) GetColorSpace ¶ added in v0.1.3
func (p *Document) GetColorSpace(id models.StID) *models.ColorSpace
GetColorSpace 返回指定 ID 的颜色空间资源。
func (*Document) GetCompositeUnit ¶ added in v0.1.1
func (p *Document) GetCompositeUnit(id models.StID) *models.CompositeGraphicUnit
GetCompositeUnit 返回指定 ID 的复合图元资源。
func (*Document) GetCustomTags ¶ added in v0.1.1
func (p *Document) GetCustomTags() *models.CustomTags
GetCustomTags 返回自定义标签,读取失败时返回 nil。
func (*Document) GetDigestResult ¶ added in v0.1.1
func (p *Document) GetDigestResult(id string) *SignatureDigestResult
GetDigestResult 返回指定签名的摘要校验结果。
func (*Document) GetDrawParam ¶
GetDrawParam 返回指定 ID 的绘制参数,并解析继承关系。
func (*Document) GetExtensions ¶ added in v0.1.1
func (p *Document) GetExtensions() *models.Extensions
GetExtensions 返回扩展数据,读取失败时返回 nil。
func (*Document) GetMedia ¶ added in v0.1.1
func (p *Document) GetMedia(id models.StID) *models.MultiMedia
GetMedia 返回指定 ID 的多媒体资源。
func (*Document) GetSignature ¶ added in v0.1.1
GetSignature 返回指定签名。
func (*Document) GetSignedValue ¶ added in v0.1.1
func (p *Document) GetSignedValue(id string) *SignedValue
GetSignedValue 返回指定签名的解析值。
func (*Document) GetSignedValueError ¶ added in v0.1.1
GetSignedValueError 返回指定签名值的解析错误。
func (*Document) GetTemplate ¶ added in v0.1.1
func (p *Document) GetTemplate(id models.StID) *models.PageContent
GetTemplate 返回指定模板页,读取失败时返回 nil。
func (*Document) GetVerificationError ¶ added in v0.1.1
GetVerificationError 返回指定签名的验证错误。
func (*Document) GetVerificationResult ¶ added in v0.1.1
func (p *Document) GetVerificationResult(id string) *SignatureVerificationResult
GetVerificationResult 返回指定签名的验证结果。
func (*Document) GetVersion ¶ added in v0.1.1
func (p *Document) GetVersion(id string) *models.DocVersion
GetVersion 返回指定版本,读取失败时返回 nil。
func (*Document) LoadAnnotation ¶ added in v0.1.1
GetAnnotation 按需读取指定页面的注解。
func (*Document) LoadAttachments ¶ added in v0.1.1
func (p *Document) LoadAttachments() (*models.Attachments, error)
LoadAttachments 按需读取文档附件清单。
func (*Document) LoadCustomTags ¶ added in v0.1.1
func (p *Document) LoadCustomTags() (*models.CustomTags, error)
LoadCustomTags 按需读取自定义标签。
func (*Document) LoadExtensions ¶ added in v0.1.1
func (p *Document) LoadExtensions() (*models.Extensions, error)
LoadExtensions 按需读取扩展数据。
func (*Document) LoadTemplate ¶ added in v0.1.1
LoadTemplate 按需读取并缓存指定模板页。
func (*Document) LoadVersion ¶ added in v0.1.1
func (p *Document) LoadVersion(id string) (*models.DocVersion, error)
LoadVersion 按需读取指定版本。
func (*Document) PublicResourceList ¶ added in v0.1.1
PublicResourceList 返回公共资源文件的快照。
func (*Document) SetVerificationError ¶ added in v0.1.1
SetVerificationError 保存签名验证错误。
func (*Document) SetVerificationResult ¶ added in v0.1.1
func (p *Document) SetVerificationResult(id string, value *SignatureVerificationResult)
SetVerificationResult 保存签名验证结果。
func (*Document) SignedValuesSnapshot ¶ added in v0.1.1
func (p *Document) SignedValuesSnapshot() map[string]*SignedValue
SignedValuesSnapshot 返回签名值的快照。
type ExtensionData ¶ added in v0.1.0
type ExtensionData struct {
OID asn1.ObjectIdentifier
Critical bool
Value []byte
}
ExtensionData 是 ASN.1 扩展数据项。
type OFD ¶
OFD 表示一个OFD文档解析器
func NewOFDWithOptions ¶ added in v0.1.1
NewOFDWithOptions 打开 OFD 文档并使用指定的页面缓存配置。
type Options ¶ added in v0.1.1
type Options struct {
// PageCacheCapacity 是页面缓存最多保留的页面数量,0 表示使用默认值。
PageCacheCapacity int
// PageCacheBytes 是页面缓存允许使用的估算字节数,0 表示使用默认值。
PageCacheBytes int64
// MaxInputBytes 是原始 OFD 输入允许的最大字节数,0 表示使用默认值。
MaxInputBytes int64
}
Options 控制解析器的页面缓存和输入大小限制。
type Page ¶
func NewPage ¶ added in v0.1.1
func NewPage(content models.PageContent) *Page
NewPage 创建一个已加载的页面,主要用于构造测试页面。
func (*Page) AcquireLease ¶ added in v0.1.1
AcquireLease 加载并固定页面,返回可显式释放的页面租约。 租约持有期间页面内容不会被缓存淘汰或文档清理。
func (*Page) EnsureLoaded ¶ added in v0.1.1
EnsureLoaded 在首次访问页面时读取页面内容,并缓存读取结果。
func (*Page) PageResourceLocations ¶ added in v0.1.1
PageResourceLocations 返回已经解析为包内路径的页面资源文件位置。
func (*Page) PhysicalBox ¶ added in v0.1.1
PhysicalBox 返回页面物理区域的值副本,不暴露页面内部指针。
func (*Page) PhysicalBoxMetadata ¶ added in v0.1.1
PhysicalBoxMetadata 只读取页面 XML 中的 Area/PhysicalBox,不加载页面内容或资源。 返回零值表示页面没有定义自己的物理区域,由调用方决定回退到文档默认尺寸。
func (*Page) WithPageContent ¶ added in v0.1.1
func (p *Page) WithPageContent(fn func(*models.PageContent) error) error
WithPageContent 在页面租约期间访问页面内容。 回调返回的错误会原样返回给调用方。
type PageLease ¶ added in v0.1.1
type PageLease struct {
// contains filtered or unexported fields
}
PageLease 表示页面的一次使用租约。 租约使用完毕后必须调用 Release,推荐使用 defer lease.Release()。 未释放的租约会阻止所属文档关闭,以避免正在使用的页面内容被清理。
func (*PageLease) Content ¶ added in v0.1.1
func (l *PageLease) Content() *models.PageContent
Content 返回租约保护中的页面内容。 返回指针只能在租约释放前使用;并发修改页面时应使用 WithContent。
func (*PageLease) Release ¶ added in v0.1.1
func (l *PageLease) Release()
Release 释放页面租约。重复调用 Release 是安全的。
func (*PageLease) WithContent ¶ added in v0.1.1
func (l *PageLease) WithContent(fn func(*models.PageContent) error) error
WithContent 在租约保护和页面锁保护下访问页面内容。
type ReferenceDigestResult ¶ added in v0.1.0
type ReferenceDigestResult struct {
FileRef string
ResolvedPath string
Expected []byte
Actual []byte
Exists bool
Match bool
Error string
}
ReferenceDigestResult 是单个 Reference 的摘要校验结果。
type SESPicture ¶ added in v0.1.0
SESPicture 是电子印章的图像信息。
type SESProperty ¶ added in v0.1.0
type SESProperty struct {
Type int64
Name string
CertificateType int64
Certificates [][]byte
CertificateValues []ASN1Node
CreateTime time.Time
ValidFrom time.Time
ValidTo time.Time
}
SESProperty 是电子印章的属性信息。
type SESSignedValue ¶ added in v0.1.0
type SESSignedValue struct {
TBS TBSSign
Certificate []byte
SignatureAlgorithm asn1.ObjectIdentifier
Signature BitString
}
SESSignedValue 是 OFD 和 GM/T 电子印章签名结构。
type SESeal ¶ added in v0.1.0
type SESeal struct {
// Raw 是 SESeal 的完整 DER 编码,是印章内部签名的待验证数据。
Raw []byte
SealInfo SESealInfo
Certificate []byte
SignatureAlgorithm asn1.ObjectIdentifier
Signature BitString
}
SESeal 是电子印章内部的签名对象。
type SESealInfo ¶ added in v0.1.0
type SESealInfo struct {
// Raw 是 SES_Seal_Info 的完整 DER 编码,是印章内部签名的待验证数据。
Raw []byte
Header SESHeader
ESID string
Property SESProperty
Picture SESPicture
Extensions []ExtensionData
}
SESealInfo 是电子印章的主体信息。
type SM2SignatureFormat ¶ added in v0.1.0
type SM2SignatureFormat string
SM2SignatureFormat 指定 BIT STRING 中 SM2 签名值的编码格式。
const ( // SM2SignatureFormatAuto 自动识别 DER SEQUENCE 或 64 字节 r||s。 SM2SignatureFormatAuto SM2SignatureFormat = "auto" // SM2SignatureFormatDER 表示 DER 编码的 SEQUENCE { r, s }。 SM2SignatureFormatDER SM2SignatureFormat = "der" // SM2SignatureFormatRaw 表示固定 64 字节的 r||s 编码。 SM2SignatureFormatRaw SM2SignatureFormat = "raw" )
type SealData ¶
SealData 存储提取的签章数据。
func ExtractSealData ¶
ExtractSealData 从签章数据中提取文件类型与内容,支持文件路径(string)、字节数据([]byte) 或 io.Reader 输入。
type SealInfo ¶
type SealInfo struct {
StampAnnot *models.StampAnnot
SealData *SealData
}
type SignatureComponentResult ¶ added in v0.1.0
type SignatureComponentResult struct {
// Valid 表示签名值通过公钥验证。
Valid bool
// Algorithm 是签名算法 OID。
Algorithm string
// SignatureFormat 是签名值实际使用的编码格式。
SignatureFormat string
// Certificate 是签名证书信息。
Certificate *CertificateInfo
// CertificateValid 表示证书在签名时间点有效。
CertificateValid bool
// TrustChecked 表示是否执行了证书链校验。
TrustChecked bool
// Trusted 表示证书链校验通过。
Trusted bool
// TrustError 是证书链校验失败原因。
TrustError string
// RevocationChecked 表示是否执行了证书吊销校验。
RevocationChecked bool
// RevocationStatus 是吊销状态:good、revoked、unknown 或 error。
RevocationStatus string
// RevocationError 是吊销校验失败原因。
RevocationError string
// Error 是验证失败原因。
Error string
}
SignatureComponentResult 是一层签名的证书和数学验证结果。
type SignatureDigestResult ¶ added in v0.1.0
type SignatureDigestResult struct {
// Method 是 References 声明的摘要算法。
Method string
// References 是被签名文件的逐项校验结果。
References []ReferenceDigestResult
// DataHash 是 TBS_Sign.DataHash 的校验结果;非 SES 签名时为空。
DataHash *DataHashResult
// Valid 表示所有可校验项目均通过。
Valid bool
}
SignatureDigestResult 是一个签名的摘要校验结果。
func VerifySignatureDigest ¶ added in v0.1.0
func VerifySignatureDigest(fileCache *core.Package, signaturePath string, signature *models.Signature, signedValue *SignedValue) (*SignatureDigestResult, error)
VerifySignatureDigest 校验 Signature.xml 的 References 摘要,以及 SES 签名中的 TBS_Sign.DataHash。DataHash 按 References 使用的摘要算法计算, 数据源是签名 XML 文件本身的包内字节。
type SignatureVerificationOptions ¶ added in v0.1.0
type SignatureVerificationOptions struct {
// UID 是 SM2 签名用户标识;为空时使用国密库默认标识。
UID []byte
// SignatureFormat 是签名值编码格式;为空时自动识别。
SignatureFormat SM2SignatureFormat
// Trust 是可选的证书链校验配置;为空时不执行证书链校验。
Trust *CertificateTrustOptions
// Revocation 是可选的离线 CRL 吊销校验配置;为空时不执行吊销校验。
Revocation *CertificateRevocationOptions
}
SignatureVerificationOptions 配置 SES 签名的 SM2 验证兼容行为。
type SignatureVerificationResult ¶ added in v0.1.0
type SignatureVerificationResult struct {
// Valid 表示印章内部签名和外层签名均通过。
Valid bool
// TrustChecked 表示是否使用显式信任根执行了证书链校验。
TrustChecked bool
// Trusted 表示两层签名证书均通过证书链校验。
Trusted bool
// RevocationChecked 表示是否执行了证书吊销校验。
RevocationChecked bool
// RevocationValid 表示两层证书均未被显式提供的 CRL 吊销。
RevocationValid bool
// VerificationTime 是验证证书有效期使用的签名时间。
VerificationTime time.Time
// Seal 是印章内部签名结果。
Seal SignatureComponentResult
// Outer 是 SignedValue 外层签名结果。
Outer SignatureComponentResult
}
SignatureVerificationResult 是 SES 签名的密码学验证结果。
func VerifySESSignedValue ¶ added in v0.1.0
func VerifySESSignedValue(value *SignedValue) (*SignatureVerificationResult, error)
VerifySESSignedValue 验证 SES 电子印章的两层 SM2 签名。 印章内部签名验证 SES_Seal_Info,外层签名验证 TBS_Sign;两层分别使用各自证书。
func VerifySESSignedValueWithOptions ¶ added in v0.1.0
func VerifySESSignedValueWithOptions(value *SignedValue, options *SignatureVerificationOptions) (*SignatureVerificationResult, error)
VerifySESSignedValueWithOptions 使用显式 SM2 UID 和签名值编码格式验证 SES 签名。
func VerifySESSignedValueWithTrust ¶ added in v0.1.0
func VerifySESSignedValueWithTrust(value *SignedValue, options *CertificateTrustOptions) (*SignatureVerificationResult, error)
VerifySESSignedValueWithTrust 使用显式信任根验证 SES 两层签名和证书链。 Trusted 与 Valid 分离:证书链不可信不会改变签名数学验证结果。
type Signatures ¶
type SignedValue ¶ added in v0.1.0
type SignedValue struct {
Raw []byte
ASN1 *ASN1Node
Format string
SES *SESSignedValue
}
SignedValue 是 OFD SignedValue.dat 的解析结果。 Raw 和 ASN1 保留完整原始内容,识别为 SES 后同时提供结构化字段。
func ParseSignedValue ¶ added in v0.1.0
func ParseSignedValue(data []byte) (*SignedValue, error)
ParseSignedValue 解析 SignedValue.dat。 合法但不是 SES 电子印章格式的 ASN.1 文件仍会返回结果,并通过 Format="ASN.1" 保留完整通用树;只有二进制不是完整 ASN.1 数据时才返回错误。