Table of Contents

Class SignatureVerificationRequest

Namespace
AsiBackbone.Core.Signing
Assembly
AsiBackbone.Core.dll

Represents a provider-neutral request to verify signing metadata against a precomputed artifact hash.

public sealed class SignatureVerificationRequest
Inheritance
SignatureVerificationRequest
Inherited Members

Constructors

SignatureVerificationRequest(string, SigningMetadata, string?, IReadOnlyDictionary<string, string>?)

Initializes a new instance of the SignatureVerificationRequest class.

public SignatureVerificationRequest(string signingHash, SigningMetadata signingMetadata, string? purpose = null, IReadOnlyDictionary<string, string>? metadata = null)

Parameters

signingHash string
signingMetadata SigningMetadata
purpose string
metadata IReadOnlyDictionary<string, string>

Properties

HasMetadata

Gets a value indicating whether metadata is present.

public bool HasMetadata { get; }

Property Value

bool

Metadata

Gets additional provider-neutral request metadata.

public IReadOnlyDictionary<string, string> Metadata { get; }

Property Value

IReadOnlyDictionary<string, string>

Purpose

Gets the host-defined verification purpose, when supplied.

public string? Purpose { get; }

Property Value

string

SignatureInput

Gets the exact bytes the verification provider must verify the signature against.

public ReadOnlyMemory<byte> SignatureInput { get; init; }

Property Value

ReadOnlyMemory<byte>

Remarks

GovernanceArtifactVerifier sets this to the version 1 input rebuilt from the artifact and its signing metadata, or to the pre-6.0 input when the verification context explicitly allows it. Verification providers must verify these bytes rather than SigningHash; verifying the hash text instead leaves the signing policy context unauthenticated. When no input was supplied, this returns the pre-6.0 input from CreateLegacy(string). The supplied value is copied.

SigningHash

Gets the precomputed artifact hash expected to have been signed.

public string SigningHash { get; }

Property Value

string

SigningMetadata

Gets the provider-neutral signing metadata to verify.

public SigningMetadata SigningMetadata { get; }

Property Value

SigningMetadata

UsesLegacySignatureInput

Gets a value indicating whether no explicit signature input was supplied, so SignatureInput is the pre-6.0 hash-only input.

public bool UsesLegacySignatureInput { get; }

Property Value

bool