Class SigningRequest
Represents a provider-neutral request to sign a precomputed artifact hash.
public sealed class SigningRequest
- Inheritance
-
SigningRequest
- Inherited Members
Remarks
The request is intentionally hash-oriented so production providers can use key-based signing APIs without exposing raw signing secrets to Core.
Constructors
SigningRequest(string, string?, string?, string?, string?, IReadOnlyDictionary<string, string>?)
Initializes a new instance of the SigningRequest class.
public SigningRequest(string signingHash, string? hashAlgorithm = null, string? purpose = null, string? keyId = null, string? keyVersion = null, IReadOnlyDictionary<string, string>? metadata = null)
Parameters
signingHashstringhashAlgorithmstringpurposestringkeyIdstringkeyVersionstringmetadataIReadOnlyDictionary<string, string>
Properties
HasMetadata
Gets a value indicating whether metadata is present.
public bool HasMetadata { get; }
Property Value
HashAlgorithm
Gets the hash algorithm or descriptor associated with SigningHash, when supplied.
public string? HashAlgorithm { get; }
Property Value
KeyId
Gets the requested signing key identifier, when supplied.
public string? KeyId { get; }
Property Value
KeyVersion
Gets the requested signing key version, when supplied.
public string? KeyVersion { get; }
Property Value
Metadata
Gets additional provider-neutral request metadata.
public IReadOnlyDictionary<string, string> Metadata { get; }
Property Value
Purpose
Gets the host-defined signing purpose, when supplied.
public string? Purpose { get; }
Property Value
SignatureInput
Gets the exact bytes the signing provider must sign.
public ReadOnlyMemory<byte> SignatureInput { get; init; }
Property Value
Remarks
GovernanceArtifactSigner sets this to the version 1 input from CreateV1(CanonicalPayloadHash, IReadOnlyDictionary<string, string>?), which binds the canonical descriptors, hash, and signing policy context. Providers must sign these bytes rather than SigningHash; a provider that signs the hash text produces a signature that fails version 1 verification. When no input was supplied, this returns the pre-6.0 input from CreateLegacy(string). The supplied value is copied.
SigningHash
Gets the precomputed artifact hash to sign.
public string SigningHash { get; }
Property Value
UsesLegacySignatureInput
Gets a value indicating whether no explicit signature input was supplied, so SignatureInput is the pre-6.0 hash-only input.
public bool UsesLegacySignatureInput { get; }