| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.Signing; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Represents a provider-neutral request to sign a precomputed artifact hash. |
| | | 7 | | /// </summary> |
| | | 8 | | /// <remarks> |
| | | 9 | | /// The request is intentionally hash-oriented so production providers can use key-based signing APIs without exposing r |
| | | 10 | | /// </remarks> |
| | | 11 | | public sealed class SigningRequest |
| | | 12 | | { |
| | | 13 | | private readonly byte[]? signatureInput; |
| | | 14 | | |
| | 4 | 15 | | private static readonly IReadOnlyDictionary<string, string> EmptyMetadata = |
| | 4 | 16 | | new ReadOnlyDictionary<string, string>( |
| | 4 | 17 | | new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 18 | | |
| | | 19 | | /// <summary> |
| | | 20 | | /// Initializes a new instance of the <see cref="SigningRequest" /> class. |
| | | 21 | | /// </summary> |
| | 85 | 22 | | public SigningRequest( |
| | 85 | 23 | | string signingHash, |
| | 85 | 24 | | string? hashAlgorithm = null, |
| | 85 | 25 | | string? purpose = null, |
| | 85 | 26 | | string? keyId = null, |
| | 85 | 27 | | string? keyVersion = null, |
| | 85 | 28 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 29 | | { |
| | 85 | 30 | | ArgumentException.ThrowIfNullOrWhiteSpace(signingHash); |
| | | 31 | | |
| | 85 | 32 | | SigningHash = signingHash.Trim(); |
| | 85 | 33 | | HashAlgorithm = NormalizeOptional(hashAlgorithm); |
| | 85 | 34 | | Purpose = NormalizeOptional(purpose); |
| | 85 | 35 | | KeyId = NormalizeOptional(keyId); |
| | 85 | 36 | | KeyVersion = NormalizeOptional(keyVersion); |
| | 85 | 37 | | Metadata = NormalizeMetadata(metadata); |
| | 85 | 38 | | } |
| | | 39 | | |
| | | 40 | | /// <summary> |
| | | 41 | | /// Gets the precomputed artifact hash to sign. |
| | | 42 | | /// </summary> |
| | | 43 | | public string SigningHash { get; } |
| | | 44 | | |
| | | 45 | | /// <summary> |
| | | 46 | | /// Gets the hash algorithm or descriptor associated with <see cref="SigningHash" />, when supplied. |
| | | 47 | | /// </summary> |
| | | 48 | | public string? HashAlgorithm { get; } |
| | | 49 | | |
| | | 50 | | /// <summary> |
| | | 51 | | /// Gets the host-defined signing purpose, when supplied. |
| | | 52 | | /// </summary> |
| | | 53 | | public string? Purpose { get; } |
| | | 54 | | |
| | | 55 | | /// <summary> |
| | | 56 | | /// Gets the requested signing key identifier, when supplied. |
| | | 57 | | /// </summary> |
| | | 58 | | public string? KeyId { get; } |
| | | 59 | | |
| | | 60 | | /// <summary> |
| | | 61 | | /// Gets the requested signing key version, when supplied. |
| | | 62 | | /// </summary> |
| | | 63 | | public string? KeyVersion { get; } |
| | | 64 | | |
| | | 65 | | /// <summary> |
| | | 66 | | /// Gets additional provider-neutral request metadata. |
| | | 67 | | /// </summary> |
| | | 68 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 69 | | |
| | | 70 | | /// <summary> |
| | | 71 | | /// Gets a value indicating whether metadata is present. |
| | | 72 | | /// </summary> |
| | 1 | 73 | | public bool HasMetadata => Metadata.Count > 0; |
| | | 74 | | |
| | | 75 | | /// <summary> |
| | | 76 | | /// Gets the exact bytes the signing provider must sign. |
| | | 77 | | /// </summary> |
| | | 78 | | /// <remarks> |
| | | 79 | | /// <see cref="GovernanceArtifactSigner" /> sets this to the version 1 input from |
| | | 80 | | /// <see cref="GovernanceSignatureInput.CreateV1" />, which binds the canonical descriptors, hash, and signing polic |
| | | 81 | | /// context. Providers must sign these bytes rather than <see cref="SigningHash" />; a provider that signs the hash |
| | | 82 | | /// produces a signature that fails version 1 verification. When no input was supplied, this returns the pre-6.0 inp |
| | | 83 | | /// from <see cref="GovernanceSignatureInput.CreateLegacy" />. The supplied value is copied. |
| | | 84 | | /// </remarks> |
| | | 85 | | public ReadOnlyMemory<byte> SignatureInput |
| | | 86 | | { |
| | | 87 | | #pragma warning disable ASIB902 // Retained internal fallback for pre-6.0 provider-request compatibility. |
| | 56 | 88 | | get => signatureInput ?? GovernanceSignatureInput.CreateLegacy(SigningHash); |
| | | 89 | | #pragma warning restore ASIB902 |
| | 20 | 90 | | init => signatureInput = value.IsEmpty ? null : [.. value.Span]; |
| | | 91 | | } |
| | | 92 | | |
| | | 93 | | /// <summary> |
| | | 94 | | /// Gets a value indicating whether no explicit signature input was supplied, so <see cref="SignatureInput" /> is th |
| | | 95 | | /// pre-6.0 hash-only input. |
| | | 96 | | /// </summary> |
| | 3 | 97 | | public bool UsesLegacySignatureInput => signatureInput is null; |
| | | 98 | | |
| | | 99 | | private static string? NormalizeOptional(string? value) |
| | | 100 | | { |
| | 340 | 101 | | return string.IsNullOrWhiteSpace(value) |
| | 340 | 102 | | ? null |
| | 340 | 103 | | : value.Trim(); |
| | | 104 | | } |
| | | 105 | | |
| | | 106 | | private static IReadOnlyDictionary<string, string> NormalizeMetadata( |
| | | 107 | | IReadOnlyDictionary<string, string>? metadata) |
| | | 108 | | { |
| | 85 | 109 | | if (metadata is null || metadata.Count == 0) |
| | | 110 | | { |
| | 62 | 111 | | return EmptyMetadata; |
| | | 112 | | } |
| | | 113 | | |
| | 23 | 114 | | Dictionary<string, string> normalizedMetadata = new(StringComparer.Ordinal); |
| | | 115 | | |
| | 304 | 116 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 117 | | { |
| | 129 | 118 | | if (string.IsNullOrWhiteSpace(item.Key)) |
| | | 119 | | { |
| | | 120 | | continue; |
| | | 121 | | } |
| | | 122 | | |
| | 128 | 123 | | normalizedMetadata[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 124 | | } |
| | | 125 | | |
| | 23 | 126 | | return normalizedMetadata.Count == 0 |
| | 23 | 127 | | ? EmptyMetadata |
| | 23 | 128 | | : new ReadOnlyDictionary<string, string>(normalizedMetadata); |
| | | 129 | | } |
| | | 130 | | } |