| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.Signing; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Provides host expectations used while evaluating signature verification policy. |
| | | 7 | | /// </summary> |
| | | 8 | | /// <remarks> |
| | | 9 | | /// The context is provider-neutral. It can carry expected key references, policy identifiers, and request metadata with |
| | | 10 | | /// </remarks> |
| | | 11 | | public sealed class VerificationPolicyContext |
| | | 12 | | { |
| | 2 | 13 | | private static readonly IReadOnlyDictionary<string, string> EmptyMetadata = |
| | 2 | 14 | | new ReadOnlyDictionary<string, string>( |
| | 2 | 15 | | new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 16 | | |
| | 35 | 17 | | private VerificationPolicyContext( |
| | 35 | 18 | | string? purpose, |
| | 35 | 19 | | string? expectedKeyId, |
| | 35 | 20 | | string? expectedKeyVersion, |
| | 35 | 21 | | string? expectedPolicyVersion, |
| | 35 | 22 | | string? expectedPolicyHash, |
| | 35 | 23 | | string? requiredProvider, |
| | 35 | 24 | | string? requiredHashAlgorithm, |
| | 35 | 25 | | IReadOnlyDictionary<string, string> metadata) |
| | | 26 | | { |
| | 35 | 27 | | Purpose = NormalizeOptional(purpose); |
| | 35 | 28 | | ExpectedKeyId = NormalizeOptional(expectedKeyId); |
| | 35 | 29 | | ExpectedKeyVersion = NormalizeOptional(expectedKeyVersion); |
| | 35 | 30 | | ExpectedPolicyVersion = NormalizeOptional(expectedPolicyVersion); |
| | 35 | 31 | | ExpectedPolicyHash = NormalizeOptional(expectedPolicyHash); |
| | 35 | 32 | | RequiredProvider = NormalizeOptional(requiredProvider); |
| | 35 | 33 | | RequiredHashAlgorithm = NormalizeOptional(requiredHashAlgorithm); |
| | 35 | 34 | | Metadata = metadata; |
| | 35 | 35 | | } |
| | | 36 | | |
| | | 37 | | /// <summary> |
| | | 38 | | /// Gets a context with no additional host expectations. |
| | | 39 | | /// </summary> |
| | | 40 | | public static VerificationPolicyContext Default { get; } = new(null, null, null, null, null, null, null, EmptyMetada |
| | | 41 | | |
| | | 42 | | /// <summary> |
| | | 43 | | /// Gets the host-defined verification purpose. |
| | | 44 | | /// </summary> |
| | | 45 | | public string? Purpose { get; } |
| | | 46 | | |
| | | 47 | | /// <summary> |
| | | 48 | | /// Gets the expected signing key identifier, when required by host policy. |
| | | 49 | | /// </summary> |
| | | 50 | | public string? ExpectedKeyId { get; } |
| | | 51 | | |
| | | 52 | | /// <summary> |
| | | 53 | | /// Gets the expected signing key version, when required by host policy. |
| | | 54 | | /// </summary> |
| | | 55 | | public string? ExpectedKeyVersion { get; } |
| | | 56 | | |
| | | 57 | | /// <summary> |
| | | 58 | | /// Gets the expected policy version, when the signed metadata is expected to carry one. |
| | | 59 | | /// </summary> |
| | | 60 | | public string? ExpectedPolicyVersion { get; } |
| | | 61 | | |
| | | 62 | | /// <summary> |
| | | 63 | | /// Gets the expected policy hash, when the signed metadata is expected to carry one. |
| | | 64 | | /// </summary> |
| | | 65 | | public string? ExpectedPolicyHash { get; } |
| | | 66 | | |
| | | 67 | | /// <summary> |
| | | 68 | | /// Gets the required signing provider descriptor, when required by host policy. |
| | | 69 | | /// </summary> |
| | | 70 | | public string? RequiredProvider { get; } |
| | | 71 | | |
| | | 72 | | /// <summary> |
| | | 73 | | /// Gets the required hash algorithm descriptor, when required by host policy. |
| | | 74 | | /// </summary> |
| | | 75 | | public string? RequiredHashAlgorithm { get; } |
| | | 76 | | |
| | | 77 | | /// <summary> |
| | | 78 | | /// Gets additional provider-neutral verification request metadata. |
| | | 79 | | /// </summary> |
| | | 80 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 81 | | |
| | | 82 | | /// <summary> |
| | | 83 | | /// Gets a value indicating whether additional metadata is present. |
| | | 84 | | /// </summary> |
| | 3 | 85 | | public bool HasMetadata => Metadata.Count > 0; |
| | | 86 | | |
| | | 87 | | /// <summary> |
| | | 88 | | /// Gets a value indicating whether verification may fall back to the pre-6.0 hash-only signature input. |
| | | 89 | | /// </summary> |
| | | 90 | | /// <remarks> |
| | | 91 | | /// Defaults to <see langword="false" />. When enabled, an artifact whose version 1 verification fails as an invalid |
| | | 92 | | /// signature is verified again against <see cref="GovernanceSignatureInput.CreateLegacy" />. A legacy signature |
| | | 93 | | /// authenticates the canonical payload hash only, so it cannot satisfy <see cref="ExpectedPolicyVersion" /> or |
| | | 94 | | /// <see cref="ExpectedPolicyHash" />; such pins deny with <c>signature.policy-context-not-authenticated</c>. |
| | | 95 | | /// </remarks> |
| | | 96 | | public bool AllowLegacySignatureInput { get; private init; } |
| | | 97 | | |
| | | 98 | | /// <summary> |
| | | 99 | | /// Creates a copy of this context that accepts artifacts signed with the pre-6.0 hash-only signature input. |
| | | 100 | | /// </summary> |
| | | 101 | | /// <remarks> |
| | | 102 | | /// Use this only for reviewing or migrating artifacts signed before 6.0. Signing metadata labels on such artifacts, |
| | | 103 | | /// including the policy version and policy hash, are not covered by the signature. |
| | | 104 | | /// <para> |
| | | 105 | | /// This opt-in is a supported verification path, not a deprecated one. Governance evidence signed before 6.0 must |
| | | 106 | | /// stay verifiable for its audit-retention period, and removing this method would leave no way to verify it. |
| | | 107 | | /// Producing new hash-only signatures is deprecated separately through |
| | | 108 | | /// <see cref="GovernanceSignatureInput.CreateLegacy" /> (<c>ASIB902</c>). |
| | | 109 | | /// </para> |
| | | 110 | | /// </remarks> |
| | | 111 | | /// <returns>A context identical to this one with <see cref="AllowLegacySignatureInput" /> set.</returns> |
| | | 112 | | public VerificationPolicyContext WithLegacySignatureInputAllowed() |
| | | 113 | | { |
| | 3 | 114 | | return new VerificationPolicyContext( |
| | 3 | 115 | | Purpose, |
| | 3 | 116 | | ExpectedKeyId, |
| | 3 | 117 | | ExpectedKeyVersion, |
| | 3 | 118 | | ExpectedPolicyVersion, |
| | 3 | 119 | | ExpectedPolicyHash, |
| | 3 | 120 | | RequiredProvider, |
| | 3 | 121 | | RequiredHashAlgorithm, |
| | 3 | 122 | | Metadata) |
| | 3 | 123 | | { |
| | 3 | 124 | | AllowLegacySignatureInput = true |
| | 3 | 125 | | }; |
| | | 126 | | } |
| | | 127 | | |
| | | 128 | | /// <summary> |
| | | 129 | | /// Creates a provider-neutral verification policy context. |
| | | 130 | | /// </summary> |
| | | 131 | | public static VerificationPolicyContext Create( |
| | | 132 | | string? purpose = null, |
| | | 133 | | string? expectedKeyId = null, |
| | | 134 | | string? expectedKeyVersion = null, |
| | | 135 | | string? expectedPolicyVersion = null, |
| | | 136 | | string? expectedPolicyHash = null, |
| | | 137 | | string? requiredProvider = null, |
| | | 138 | | string? requiredHashAlgorithm = null, |
| | | 139 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 140 | | { |
| | 30 | 141 | | return new VerificationPolicyContext( |
| | 30 | 142 | | purpose, |
| | 30 | 143 | | expectedKeyId, |
| | 30 | 144 | | expectedKeyVersion, |
| | 30 | 145 | | expectedPolicyVersion, |
| | 30 | 146 | | expectedPolicyHash, |
| | 30 | 147 | | requiredProvider, |
| | 30 | 148 | | requiredHashAlgorithm, |
| | 30 | 149 | | NormalizeMetadata(metadata)); |
| | | 150 | | } |
| | | 151 | | |
| | | 152 | | private static string? NormalizeOptional(string? value) |
| | | 153 | | { |
| | 245 | 154 | | return string.IsNullOrWhiteSpace(value) |
| | 245 | 155 | | ? null |
| | 245 | 156 | | : value.Trim(); |
| | | 157 | | } |
| | | 158 | | |
| | | 159 | | private static IReadOnlyDictionary<string, string> NormalizeMetadata( |
| | | 160 | | IReadOnlyDictionary<string, string>? metadata) |
| | | 161 | | { |
| | 30 | 162 | | if (metadata is null || metadata.Count == 0) |
| | | 163 | | { |
| | 27 | 164 | | return EmptyMetadata; |
| | | 165 | | } |
| | | 166 | | |
| | 3 | 167 | | Dictionary<string, string> normalizedMetadata = new(StringComparer.Ordinal); |
| | | 168 | | |
| | 16 | 169 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 170 | | { |
| | 5 | 171 | | if (string.IsNullOrWhiteSpace(item.Key)) |
| | | 172 | | { |
| | | 173 | | continue; |
| | | 174 | | } |
| | | 175 | | |
| | 3 | 176 | | normalizedMetadata[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 177 | | } |
| | | 178 | | |
| | 3 | 179 | | return normalizedMetadata.Count == 0 |
| | 3 | 180 | | ? EmptyMetadata |
| | 3 | 181 | | : new ReadOnlyDictionary<string, string>(normalizedMetadata); |
| | | 182 | | } |
| | | 183 | | } |