| | | 1 | | using AsiBackbone.Core.Signing; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.CapabilityGrants; |
| | | 4 | | |
| | | 5 | | public static class CapabilityGrantValidator |
| | | 6 | | { |
| | | 7 | | public static async ValueTask<CapabilityGrantValidationResult> ValidateAsync( |
| | | 8 | | SignedGovernanceArtifact<CapabilityGrant> signedGrant, |
| | | 9 | | CapabilityGrantValidationOptions? options = null, |
| | | 10 | | IGovernanceSignatureVerificationService? verificationService = null, |
| | | 11 | | ICapabilityGrantUseStore? useStore = null, |
| | | 12 | | CancellationToken cancellationToken = default) |
| | | 13 | | { |
| | 75 | 14 | | ArgumentNullException.ThrowIfNull(signedGrant); |
| | 74 | 15 | | cancellationToken.ThrowIfCancellationRequested(); |
| | | 16 | | |
| | 73 | 17 | | CapabilityGrant grant = signedGrant.Artifact; |
| | | 18 | | |
| | | 19 | | // The previous default built permissive options: no proof, no use check, and no issuer, audience, or scope |
| | | 20 | | // expectations, so the simplest call was the least safe one and returned Valid for anything unexpired. Validati |
| | | 21 | | // now requires the caller to state what it is validating against. |
| | 73 | 22 | | if (options is null) |
| | | 23 | | { |
| | 1 | 24 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 25 | | grant, |
| | 1 | 26 | | CapabilityGrantValidationCategory.Failed, |
| | 1 | 27 | | VerificationPolicyAction.Deny, |
| | 1 | 28 | | "capability.validation-options-required", |
| | 1 | 29 | | "Capability grant validation requires explicit options describing what the grant is validated against.") |
| | | 30 | | } |
| | | 31 | | |
| | 72 | 32 | | CapabilityGrantValidationOptions effectiveOptions = options; |
| | 72 | 33 | | DateTimeOffset validationUtc = (effectiveOptions.ValidationUtc ?? DateTimeOffset.UtcNow).ToUniversalTime(); |
| | | 34 | | |
| | 72 | 35 | | if (effectiveOptions.RequireProof) |
| | | 36 | | { |
| | 23 | 37 | | CapabilityGrantValidationResult? proofResult = await ValidateProofAsync( |
| | 23 | 38 | | signedGrant, |
| | 23 | 39 | | grant, |
| | 23 | 40 | | effectiveOptions, |
| | 23 | 41 | | verificationService, |
| | 23 | 42 | | cancellationToken).ConfigureAwait(false); |
| | | 43 | | |
| | 23 | 44 | | if (proofResult is not null) |
| | | 45 | | { |
| | 19 | 46 | | return proofResult; |
| | | 47 | | } |
| | | 48 | | } |
| | | 49 | | |
| | 53 | 50 | | CapabilityGrantValidationResult? metadataResult = ValidateMetadata(grant, effectiveOptions, validationUtc); |
| | | 51 | | |
| | 53 | 52 | | if (metadataResult is not null) |
| | | 53 | | { |
| | 29 | 54 | | return metadataResult; |
| | | 55 | | } |
| | | 56 | | |
| | 24 | 57 | | if (effectiveOptions.RequireUseCheck) |
| | | 58 | | { |
| | 17 | 59 | | CapabilityGrantValidationResult? useResult = await ValidateUseAsync( |
| | 17 | 60 | | grant, |
| | 17 | 61 | | effectiveOptions, |
| | 17 | 62 | | useStore, |
| | 17 | 63 | | validationUtc, |
| | 17 | 64 | | cancellationToken).ConfigureAwait(false); |
| | | 65 | | |
| | 17 | 66 | | if (useResult is not null) |
| | | 67 | | { |
| | 10 | 68 | | return useResult; |
| | | 69 | | } |
| | | 70 | | } |
| | | 71 | | |
| | 14 | 72 | | return CapabilityGrantValidationResult.Valid(grant); |
| | 73 | 73 | | } |
| | | 74 | | |
| | | 75 | | private static async ValueTask<CapabilityGrantValidationResult?> ValidateProofAsync( |
| | | 76 | | SignedGovernanceArtifact<CapabilityGrant> signedGrant, |
| | | 77 | | CapabilityGrant grant, |
| | | 78 | | CapabilityGrantValidationOptions options, |
| | | 79 | | IGovernanceSignatureVerificationService? verificationService, |
| | | 80 | | CancellationToken cancellationToken) |
| | | 81 | | { |
| | 23 | 82 | | if (verificationService is null) |
| | | 83 | | { |
| | 2 | 84 | | return CapabilityGrantValidationResult.Failed( |
| | 2 | 85 | | grant, |
| | 2 | 86 | | CapabilityGrantValidationCategory.MissingProof, |
| | 2 | 87 | | VerificationPolicyAction.Deny, |
| | 2 | 88 | | "capability.proof-verifier-missing", |
| | 2 | 89 | | "A proof verifier is required for this validation context."); |
| | | 90 | | } |
| | | 91 | | |
| | 21 | 92 | | CapabilityGrantValidationResult? bindingResult = ValidateProofBinding(signedGrant, grant, options); |
| | | 93 | | |
| | 21 | 94 | | if (bindingResult is not null) |
| | | 95 | | { |
| | 4 | 96 | | return bindingResult; |
| | | 97 | | } |
| | | 98 | | |
| | 17 | 99 | | var verificationContext = VerificationPolicyContext.Create( |
| | 17 | 100 | | purpose: CanonicalArtifactTypes.CapabilityGrant, |
| | 17 | 101 | | expectedKeyId: options.ExpectedProofKeyId, |
| | 17 | 102 | | expectedKeyVersion: options.ExpectedProofKeyVersion, |
| | 17 | 103 | | expectedPolicyVersion: options.ExpectedProofPolicyVersion, |
| | 17 | 104 | | expectedPolicyHash: options.ExpectedProofPolicyHash, |
| | 17 | 105 | | requiredProvider: options.RequiredProofProvider, |
| | 17 | 106 | | requiredHashAlgorithm: options.RequiredProofHashAlgorithm); |
| | | 107 | | |
| | 17 | 108 | | VerificationPolicyOutcome verificationOutcome = await GovernanceArtifactVerifier.VerifyAsync( |
| | 17 | 109 | | signedGrant, |
| | 17 | 110 | | verificationService, |
| | 17 | 111 | | context: verificationContext, |
| | 17 | 112 | | cancellationToken: cancellationToken).ConfigureAwait(false); |
| | | 113 | | |
| | 17 | 114 | | if (verificationOutcome.ShouldAllow) |
| | | 115 | | { |
| | 4 | 116 | | return null; |
| | | 117 | | } |
| | | 118 | | |
| | | 119 | | // A grant whose signature was stripped is not a grant awaiting acknowledgment. Where proof is required, absent |
| | | 120 | | // proof denies, rather than inviting a host that treats RequireAcknowledgment as "proceed after a click" to |
| | | 121 | | // continue on a grant carrying no proof at all. The default verification policy now also denies a missing |
| | | 122 | | // signature; this override is retained so grant validation cannot be weakened by a future default change. |
| | 13 | 123 | | VerificationPolicyAction action = verificationOutcome.Category is SignatureVerificationCategory.MissingSignature |
| | 13 | 124 | | ? VerificationPolicyAction.Deny |
| | 13 | 125 | | : verificationOutcome.Action; |
| | | 126 | | |
| | 13 | 127 | | return CapabilityGrantValidationResult.Failed( |
| | 13 | 128 | | grant, |
| | 13 | 129 | | MapVerificationCategory(verificationOutcome.Category), |
| | 13 | 130 | | action, |
| | 13 | 131 | | verificationOutcome.FailureCode ?? "capability.proof-invalid", |
| | 13 | 132 | | verificationOutcome.FailureMessage); |
| | 23 | 133 | | } |
| | | 134 | | |
| | | 135 | | /// <summary> |
| | | 136 | | /// Binds the signed proof to the grant being validated by rebuilding the canonical payload from the grant itself. |
| | | 137 | | /// </summary> |
| | | 138 | | /// <remarks> |
| | | 139 | | /// Signature verification establishes that a signature covers a hash. It does not establish that the hash describes |
| | | 140 | | /// grant whose fields are about to be evaluated. Rebuilding the payload from <see cref="SignedGovernanceArtifact{TA |
| | | 141 | | /// and comparing hashes closes that gap, and the artifact descriptors are asserted so a proof issued for another ar |
| | | 142 | | /// type or token identifier cannot be presented alongside this grant. |
| | | 143 | | /// </remarks> |
| | | 144 | | private static CapabilityGrantValidationResult? ValidateProofBinding( |
| | | 145 | | SignedGovernanceArtifact<CapabilityGrant> signedGrant, |
| | | 146 | | CapabilityGrant grant, |
| | | 147 | | CapabilityGrantValidationOptions options) |
| | | 148 | | { |
| | 21 | 149 | | if (!string.Equals(signedGrant.ArtifactType, CanonicalArtifactTypes.CapabilityGrant, StringComparison.Ordinal)) |
| | | 150 | | { |
| | 1 | 151 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 152 | | grant, |
| | 1 | 153 | | CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 154 | | VerificationPolicyAction.Deny, |
| | 1 | 155 | | "capability.proof-artifact-type-mismatch", |
| | 1 | 156 | | "The signed artifact type is not a capability token grant."); |
| | | 157 | | } |
| | | 158 | | |
| | 20 | 159 | | if (!string.Equals(signedGrant.ArtifactId, grant.TokenId, StringComparison.Ordinal)) |
| | | 160 | | { |
| | 1 | 161 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 162 | | grant, |
| | 1 | 163 | | CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 164 | | VerificationPolicyAction.Deny, |
| | 1 | 165 | | "capability.proof-artifact-id-mismatch", |
| | 1 | 166 | | "The signed artifact identifier does not match the grant token identifier."); |
| | | 167 | | } |
| | | 168 | | |
| | | 169 | | CanonicalPayloadHash recomputedHash; |
| | | 170 | | |
| | | 171 | | try |
| | | 172 | | { |
| | 19 | 173 | | recomputedHash = CanonicalPayloadHasher.ComputeHash( |
| | 19 | 174 | | CanonicalPayloadBuilder.ForCapabilityGrant(grant, options.ProofPayloadOptions), |
| | 19 | 175 | | signedGrant.HashAlgorithm); |
| | 19 | 176 | | } |
| | 0 | 177 | | catch (NotSupportedException) |
| | | 178 | | { |
| | 0 | 179 | | return CapabilityGrantValidationResult.Failed( |
| | 0 | 180 | | grant, |
| | 0 | 181 | | CapabilityGrantValidationCategory.InvalidProof, |
| | 0 | 182 | | VerificationPolicyAction.Deny, |
| | 0 | 183 | | "capability.proof-hash-algorithm-unsupported", |
| | 0 | 184 | | "The grant canonical payload cannot be rebuilt with the built-in hasher, so the proof is not bound to th |
| | | 185 | | } |
| | | 186 | | |
| | 19 | 187 | | return string.Equals(recomputedHash.HashValue, signedGrant.CanonicalHash.HashValue, StringComparison.Ordinal) |
| | 19 | 188 | | ? null |
| | 19 | 189 | | : CapabilityGrantValidationResult.Failed( |
| | 19 | 190 | | grant, |
| | 19 | 191 | | CapabilityGrantValidationCategory.InvalidProof, |
| | 19 | 192 | | VerificationPolicyAction.Deny, |
| | 19 | 193 | | "capability.proof-content-mismatch", |
| | 19 | 194 | | "The grant does not hash to the signed canonical hash value."); |
| | 0 | 195 | | } |
| | | 196 | | |
| | | 197 | | #pragma warning disable IDE0046 // Preserve explicit ordered guard clauses for auditability. |
| | | 198 | | private static CapabilityGrantValidationResult? ValidateMetadata( |
| | | 199 | | CapabilityGrant grant, |
| | | 200 | | CapabilityGrantValidationOptions options, |
| | | 201 | | DateTimeOffset validationUtc) |
| | | 202 | | { |
| | 53 | 203 | | if (options.Issuer is not null |
| | 53 | 204 | | && !string.Equals(options.Issuer, grant.Issuer, StringComparison.Ordinal)) |
| | | 205 | | { |
| | 2 | 206 | | return CapabilityGrantValidationResult.Failed( |
| | 2 | 207 | | grant, |
| | 2 | 208 | | CapabilityGrantValidationCategory.WrongIssuer, |
| | 2 | 209 | | VerificationPolicyAction.Deny, |
| | 2 | 210 | | "capability.issuer-mismatch"); |
| | | 211 | | } |
| | | 212 | | |
| | 51 | 213 | | if (options.Audience is not null |
| | 51 | 214 | | && !string.Equals(options.Audience, grant.Audience, StringComparison.Ordinal)) |
| | | 215 | | { |
| | 1 | 216 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 217 | | grant, |
| | 1 | 218 | | CapabilityGrantValidationCategory.WrongAudience, |
| | 1 | 219 | | VerificationPolicyAction.Deny, |
| | 1 | 220 | | "capability.audience-mismatch"); |
| | | 221 | | } |
| | | 222 | | |
| | 50 | 223 | | if (options.ExpectedSubjectId is not null |
| | 50 | 224 | | && !string.Equals(options.ExpectedSubjectId, grant.SubjectId, StringComparison.Ordinal)) |
| | | 225 | | { |
| | 4 | 226 | | return CapabilityGrantValidationResult.Failed( |
| | 4 | 227 | | grant, |
| | 4 | 228 | | CapabilityGrantValidationCategory.SubjectMismatch, |
| | 4 | 229 | | VerificationPolicyAction.Deny, |
| | 4 | 230 | | "capability.subject-mismatch"); |
| | | 231 | | } |
| | | 232 | | |
| | 46 | 233 | | if (options.ExpectedOperationName is not null |
| | 46 | 234 | | && !string.Equals(options.ExpectedOperationName, grant.OperationName, StringComparison.Ordinal)) |
| | | 235 | | { |
| | 3 | 236 | | return CapabilityGrantValidationResult.Failed( |
| | 3 | 237 | | grant, |
| | 3 | 238 | | CapabilityGrantValidationCategory.OperationMismatch, |
| | 3 | 239 | | VerificationPolicyAction.Deny, |
| | 3 | 240 | | "capability.operation-mismatch"); |
| | | 241 | | } |
| | | 242 | | |
| | 43 | 243 | | if (IsNotYetValid(grant, validationUtc, options.AllowedClockSkew)) |
| | | 244 | | { |
| | 3 | 245 | | return CapabilityGrantValidationResult.Failed( |
| | 3 | 246 | | grant, |
| | 3 | 247 | | CapabilityGrantValidationCategory.NotYetValid, |
| | 3 | 248 | | VerificationPolicyAction.Defer, |
| | 3 | 249 | | "capability.not-yet-valid"); |
| | | 250 | | } |
| | | 251 | | |
| | 40 | 252 | | if (IsExpired(grant, validationUtc, options.AllowedClockSkew)) |
| | | 253 | | { |
| | 4 | 254 | | return CapabilityGrantValidationResult.Failed( |
| | 4 | 255 | | grant, |
| | 4 | 256 | | CapabilityGrantValidationCategory.Expired, |
| | 4 | 257 | | VerificationPolicyAction.Deny, |
| | 4 | 258 | | "capability.expired"); |
| | | 259 | | } |
| | | 260 | | |
| | 36 | 261 | | if (options.Scopes.Count > 0 |
| | 36 | 262 | | && !ContainsRequiredScopes(grant.Scopes, options.Scopes)) |
| | | 263 | | { |
| | 3 | 264 | | return CapabilityGrantValidationResult.Failed( |
| | 3 | 265 | | grant, |
| | 3 | 266 | | CapabilityGrantValidationCategory.WrongScope, |
| | 3 | 267 | | VerificationPolicyAction.Deny, |
| | 3 | 268 | | "capability.scope-missing"); |
| | | 269 | | } |
| | | 270 | | |
| | 33 | 271 | | if ((options.PolicyVersion is not null |
| | 33 | 272 | | && !string.Equals(options.PolicyVersion, grant.PolicyVersion, StringComparison.Ordinal)) |
| | 33 | 273 | | || (options.PolicyHash is not null |
| | 33 | 274 | | && !string.Equals(options.PolicyHash, grant.PolicyHash, StringComparison.Ordinal))) |
| | | 275 | | { |
| | 2 | 276 | | return CapabilityGrantValidationResult.Failed( |
| | 2 | 277 | | grant, |
| | 2 | 278 | | CapabilityGrantValidationCategory.PolicyMismatch, |
| | 2 | 279 | | VerificationPolicyAction.Deny, |
| | 2 | 280 | | "capability.policy-mismatch"); |
| | | 281 | | } |
| | | 282 | | |
| | 31 | 283 | | if (options.RequireAcknowledgmentReference && !grant.HasAcknowledgmentReference) |
| | | 284 | | { |
| | 2 | 285 | | return CapabilityGrantValidationResult.Failed( |
| | 2 | 286 | | grant, |
| | 2 | 287 | | CapabilityGrantValidationCategory.MissingAcknowledgmentReference, |
| | 2 | 288 | | VerificationPolicyAction.RequireAcknowledgment, |
| | 2 | 289 | | "capability.acknowledgment-missing"); |
| | | 290 | | } |
| | | 291 | | |
| | 29 | 292 | | if (options.AcknowledgmentId is not null |
| | 29 | 293 | | && !string.Equals(options.AcknowledgmentId, grant.AcknowledgmentId, StringComparison.Ordinal)) |
| | | 294 | | { |
| | 1 | 295 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 296 | | grant, |
| | 1 | 297 | | CapabilityGrantValidationCategory.AcknowledgmentMismatch, |
| | 1 | 298 | | VerificationPolicyAction.Deny, |
| | 1 | 299 | | "capability.acknowledgment-mismatch"); |
| | | 300 | | } |
| | | 301 | | |
| | 28 | 302 | | if (options.HandshakeId is not null |
| | 28 | 303 | | && !string.Equals(options.HandshakeId, grant.HandshakeId, StringComparison.Ordinal)) |
| | | 304 | | { |
| | 1 | 305 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 306 | | grant, |
| | 1 | 307 | | CapabilityGrantValidationCategory.HandshakeMismatch, |
| | 1 | 308 | | VerificationPolicyAction.Deny, |
| | 1 | 309 | | "capability.handshake-mismatch"); |
| | | 310 | | } |
| | | 311 | | |
| | 27 | 312 | | if (options.GatewayBinding is not null |
| | 27 | 313 | | && !string.Equals(options.GatewayBinding, grant.GatewayBinding, StringComparison.Ordinal)) |
| | | 314 | | { |
| | 2 | 315 | | return CapabilityGrantValidationResult.Failed( |
| | 2 | 316 | | grant, |
| | 2 | 317 | | CapabilityGrantValidationCategory.GatewayMismatch, |
| | 2 | 318 | | VerificationPolicyAction.Deny, |
| | 2 | 319 | | "capability.gateway-mismatch"); |
| | | 320 | | } |
| | | 321 | | |
| | 25 | 322 | | if (options.ResourceBinding is not null |
| | 25 | 323 | | && !string.Equals(options.ResourceBinding, grant.ResourceBinding, StringComparison.Ordinal)) |
| | | 324 | | { |
| | 1 | 325 | | return CapabilityGrantValidationResult.Failed( |
| | 1 | 326 | | grant, |
| | 1 | 327 | | CapabilityGrantValidationCategory.ResourceMismatch, |
| | 1 | 328 | | VerificationPolicyAction.Deny, |
| | 1 | 329 | | "capability.resource-mismatch"); |
| | | 330 | | } |
| | | 331 | | |
| | 24 | 332 | | return null; |
| | | 333 | | } |
| | | 334 | | #pragma warning restore IDE0046 |
| | | 335 | | |
| | | 336 | | private static bool IsNotYetValid(CapabilityGrant grant, DateTimeOffset validationUtc, TimeSpan allowedClockSkew) |
| | | 337 | | { |
| | 43 | 338 | | return grant.NotBeforeUtc.HasValue |
| | 43 | 339 | | && grant.NotBeforeUtc.Value > validationUtc |
| | 43 | 340 | | && grant.NotBeforeUtc.Value - validationUtc > allowedClockSkew; |
| | | 341 | | } |
| | | 342 | | |
| | | 343 | | private static bool IsExpired(CapabilityGrant grant, DateTimeOffset validationUtc, TimeSpan allowedClockSkew) |
| | | 344 | | { |
| | 40 | 345 | | return validationUtc >= grant.ExpiresUtc |
| | 40 | 346 | | && validationUtc - grant.ExpiresUtc >= allowedClockSkew; |
| | | 347 | | } |
| | | 348 | | |
| | | 349 | | private static async ValueTask<CapabilityGrantValidationResult?> ValidateUseAsync( |
| | | 350 | | CapabilityGrant grant, |
| | | 351 | | CapabilityGrantValidationOptions options, |
| | | 352 | | ICapabilityGrantUseStore? useStore, |
| | | 353 | | DateTimeOffset validationUtc, |
| | | 354 | | CancellationToken cancellationToken) |
| | | 355 | | { |
| | 17 | 356 | | if (useStore is null) |
| | | 357 | | { |
| | 2 | 358 | | return CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory.ReplayStoreUnavailabl |
| | | 359 | | } |
| | | 360 | | |
| | | 361 | | // A limit the caller supplies is local policy; a limit the issuer bound into the signed payload is authority. |
| | | 362 | | // Taking the narrower of the two lets a relying party tighten the limit but never widen what was issued. |
| | 15 | 363 | | int effectiveMaxUseCount = grant.MaxUseCount.HasValue |
| | 15 | 364 | | ? Math.Min(grant.MaxUseCount.Value, options.MaxUseCount) |
| | 15 | 365 | | : options.MaxUseCount; |
| | | 366 | | |
| | 15 | 367 | | CapabilityGrantUseResult result = await useStore |
| | 15 | 368 | | .TryConsumeAsync(grant, effectiveMaxUseCount, validationUtc, cancellationToken) |
| | 15 | 369 | | .ConfigureAwait(false); |
| | | 370 | | |
| | 15 | 371 | | return result.State switch |
| | 15 | 372 | | { |
| | 0 | 373 | | GrantUseState.Unspecified => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory |
| | 7 | 374 | | GrantUseState.Accepted => null, |
| | 3 | 375 | | GrantUseState.UseLimitExceeded => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCat |
| | 1 | 376 | | GrantUseState.Stopped => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory.Rev |
| | 1 | 377 | | GrantUseState.Cancelled => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory.C |
| | 2 | 378 | | GrantUseState.Unavailable => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory |
| | 1 | 379 | | _ => CapabilityGrantValidationResult.Failed(grant, CapabilityGrantValidationCategory.Failed, VerificationPol |
| | 15 | 380 | | }; |
| | 17 | 381 | | } |
| | | 382 | | |
| | | 383 | | private static bool ContainsRequiredScopes(IReadOnlyList<string> actualScopes, IReadOnlyList<string> requiredScopes) |
| | | 384 | | { |
| | 30 | 385 | | HashSet<string> actualScopeSet = new(actualScopes, StringComparer.Ordinal); |
| | | 386 | | |
| | 119 | 387 | | foreach (string requiredScope in requiredScopes) |
| | | 388 | | { |
| | 31 | 389 | | if (!actualScopeSet.Contains(requiredScope)) |
| | | 390 | | { |
| | 3 | 391 | | return false; |
| | | 392 | | } |
| | | 393 | | } |
| | | 394 | | |
| | 27 | 395 | | return true; |
| | 3 | 396 | | } |
| | | 397 | | |
| | | 398 | | private static CapabilityGrantValidationCategory MapVerificationCategory(SignatureVerificationCategory category) |
| | | 399 | | { |
| | 13 | 400 | | return category switch |
| | 13 | 401 | | { |
| | 0 | 402 | | SignatureVerificationCategory.Unspecified => CapabilityGrantValidationCategory.Failed, |
| | 1 | 403 | | SignatureVerificationCategory.MissingSignature => CapabilityGrantValidationCategory.MissingProof, |
| | 0 | 404 | | SignatureVerificationCategory.Valid => CapabilityGrantValidationCategory.Valid, |
| | 1 | 405 | | SignatureVerificationCategory.InvalidSignature => CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 406 | | SignatureVerificationCategory.HashMismatch => CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 407 | | SignatureVerificationCategory.RevokedKey => CapabilityGrantValidationCategory.Revoked, |
| | 1 | 408 | | SignatureVerificationCategory.UntrustedKey => CapabilityGrantValidationCategory.InvalidProof, |
| | 3 | 409 | | SignatureVerificationCategory.UntrustedSigningContext => CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 410 | | SignatureVerificationCategory.ProviderUnavailable => CapabilityGrantValidationCategory.Failed, |
| | 1 | 411 | | SignatureVerificationCategory.UnknownKeyVersion => CapabilityGrantValidationCategory.Failed, |
| | 1 | 412 | | SignatureVerificationCategory.CanonicalizationMismatch => CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 413 | | SignatureVerificationCategory.UnsupportedAlgorithm => CapabilityGrantValidationCategory.InvalidProof, |
| | 1 | 414 | | SignatureVerificationCategory.Failed => CapabilityGrantValidationCategory.Failed, |
| | 0 | 415 | | _ => CapabilityGrantValidationCategory.Failed |
| | 13 | 416 | | }; |
| | | 417 | | } |
| | | 418 | | } |