| | | 1 | | namespace AsiBackbone.Signing.LocalDevelopment; |
| | | 2 | | |
| | | 3 | | /// <summary> |
| | | 4 | | /// Configures the local-development signing provider. |
| | | 5 | | /// </summary> |
| | | 6 | | /// <remarks> |
| | | 7 | | /// This provider is intended for local development, samples, and tests. It is not a production managed-key provider and |
| | | 8 | | /// </remarks> |
| | | 9 | | public sealed class LocalDevelopmentSigningOptions |
| | | 10 | | { |
| | | 11 | | /// <summary> |
| | | 12 | | /// Gets the minimum supported RSA key size for generated local-development keys. |
| | | 13 | | /// </summary> |
| | | 14 | | public const int MinimumKeySizeBits = 2048; |
| | | 15 | | |
| | | 16 | | /// <summary> |
| | | 17 | | /// Gets the default provider descriptor returned in signing metadata. |
| | | 18 | | /// </summary> |
| | | 19 | | public const string DefaultProviderName = "local-development"; |
| | | 20 | | |
| | | 21 | | /// <summary> |
| | | 22 | | /// Gets the default local-development key identifier. |
| | | 23 | | /// </summary> |
| | | 24 | | public const string DefaultKeyId = "local-dev-key"; |
| | | 25 | | |
| | | 26 | | /// <summary> |
| | | 27 | | /// Gets the default local-development key version. |
| | | 28 | | /// </summary> |
| | | 29 | | public const string DefaultKeyVersion = "dev"; |
| | | 30 | | |
| | | 31 | | /// <summary> |
| | | 32 | | /// Gets the default provider-neutral signature algorithm descriptor. |
| | | 33 | | /// </summary> |
| | | 34 | | public const string DefaultSignatureAlgorithm = "RSASSA-PSS-SHA256-LOCAL-DEV"; |
| | | 35 | | |
| | | 36 | | /// <summary> |
| | | 37 | | /// Gets the default RSA key size for generated local-development keys. |
| | | 38 | | /// </summary> |
| | | 39 | | public const int DefaultKeySizeBits = MinimumKeySizeBits; |
| | | 40 | | |
| | | 41 | | /// <summary> |
| | | 42 | | /// Gets or sets the provider descriptor returned in signing metadata. |
| | | 43 | | /// </summary> |
| | | 44 | | public string ProviderName { get; set; } = DefaultProviderName; |
| | | 45 | | |
| | | 46 | | /// <summary> |
| | | 47 | | /// Gets or sets the local-development key identifier returned in signing metadata. |
| | | 48 | | /// </summary> |
| | | 49 | | public string KeyId { get; set; } = DefaultKeyId; |
| | | 50 | | |
| | | 51 | | /// <summary> |
| | | 52 | | /// Gets or sets the local-development key version returned in signing metadata. |
| | | 53 | | /// </summary> |
| | | 54 | | public string KeyVersion { get; set; } = DefaultKeyVersion; |
| | | 55 | | |
| | | 56 | | /// <summary> |
| | | 57 | | /// Gets or sets the signature algorithm descriptor returned in signing metadata. |
| | | 58 | | /// </summary> |
| | | 59 | | public string SignatureAlgorithm { get; set; } = DefaultSignatureAlgorithm; |
| | | 60 | | |
| | | 61 | | /// <summary> |
| | | 62 | | /// Gets or sets the generated RSA key size in bits. |
| | | 63 | | /// </summary> |
| | | 64 | | /// <remarks> |
| | | 65 | | /// Values below <see cref="MinimumKeySizeBits" /> are invalid. Omitted configuration uses |
| | | 66 | | /// <see cref="DefaultKeySizeBits" />. |
| | | 67 | | /// </remarks> |
| | | 68 | | public int KeySizeBits { get; set; } = DefaultKeySizeBits; |
| | | 69 | | |
| | | 70 | | /// <summary> |
| | | 71 | | /// Gets or sets a value indicating whether signing failures should return unsigned metadata with explicit failure d |
| | | 72 | | /// </summary> |
| | | 73 | | public bool ReturnUnsignedOnFailure { get; set; } = true; |
| | | 74 | | |
| | | 75 | | /// <summary> |
| | | 76 | | /// Gets or sets a value indicating whether this provider may be registered while the host reports a production envi |
| | | 77 | | /// </summary> |
| | | 78 | | /// <remarks> |
| | | 79 | | /// The signing key is generated per process and never persisted, so signatures produced by this provider stop |
| | | 80 | | /// verifying after a restart and carry no key custody story. Registration therefore fails in production unless a ho |
| | | 81 | | /// states this intent explicitly. |
| | | 82 | | /// </remarks> |
| | | 83 | | public bool AllowInProduction { get; set; } |
| | | 84 | | |
| | | 85 | | /// <summary> |
| | | 86 | | /// Gets or sets the environment name used by the production guard, overriding the ambient environment variables. |
| | | 87 | | /// </summary> |
| | | 88 | | /// <remarks> |
| | | 89 | | /// When null, the guard reads <c>DOTNET_ENVIRONMENT</c> and then <c>ASPNETCORE_ENVIRONMENT</c>. This package does n |
| | | 90 | | /// depend on the hosting abstractions, so a host that determines its environment another way supplies the name here |
| | | 91 | | /// </remarks> |
| | | 92 | | public string? EnvironmentName { get; set; } |
| | | 93 | | |
| | | 94 | | /// <summary> |
| | | 95 | | /// Validates the configured local-development signing options. |
| | | 96 | | /// </summary> |
| | | 97 | | /// <exception cref="InvalidOperationException"> |
| | | 98 | | /// Thrown when <see cref="KeySizeBits" /> is below <see cref="MinimumKeySizeBits" />. |
| | | 99 | | /// </exception> |
| | | 100 | | public void Validate() |
| | | 101 | | { |
| | 45 | 102 | | if (KeySizeBits < MinimumKeySizeBits) |
| | | 103 | | { |
| | 11 | 104 | | throw new InvalidOperationException( |
| | 11 | 105 | | $"Local-development RSA key size must be at least {MinimumKeySizeBits} bits. Configured value: {KeySizeB |
| | | 106 | | } |
| | 34 | 107 | | } |
| | | 108 | | |
| | | 109 | | /// <summary> |
| | | 110 | | /// Creates an independent copy of these options. |
| | | 111 | | /// </summary> |
| | | 112 | | /// <remarks> |
| | | 113 | | /// Registration and the signing service each hold a snapshot rather than the caller's instance. Every property has |
| | | 114 | | /// public setter, so holding the caller's instance would let a later assignment, such as setting |
| | | 115 | | /// <see cref="AllowInProduction" /> after the production guard ran, change a registered service's behavior. |
| | | 116 | | /// </remarks> |
| | | 117 | | /// <returns>A copy whose later changes do not affect this instance, and the reverse.</returns> |
| | | 118 | | internal LocalDevelopmentSigningOptions Snapshot() |
| | | 119 | | { |
| | 46 | 120 | | return new LocalDevelopmentSigningOptions |
| | 46 | 121 | | { |
| | 46 | 122 | | ProviderName = ProviderName, |
| | 46 | 123 | | KeyId = KeyId, |
| | 46 | 124 | | KeyVersion = KeyVersion, |
| | 46 | 125 | | SignatureAlgorithm = SignatureAlgorithm, |
| | 46 | 126 | | KeySizeBits = KeySizeBits, |
| | 46 | 127 | | ReturnUnsignedOnFailure = ReturnUnsignedOnFailure, |
| | 46 | 128 | | AllowInProduction = AllowInProduction, |
| | 46 | 129 | | EnvironmentName = EnvironmentName |
| | 46 | 130 | | }; |
| | | 131 | | } |
| | | 132 | | |
| | | 133 | | /// <summary> |
| | | 134 | | /// Creates options for the local-development signing provider. |
| | | 135 | | /// </summary> |
| | | 136 | | public static LocalDevelopmentSigningOptions Create( |
| | | 137 | | string? providerName = null, |
| | | 138 | | string? keyId = null, |
| | | 139 | | string? keyVersion = null, |
| | | 140 | | string? signatureAlgorithm = null, |
| | | 141 | | int keySizeBits = DefaultKeySizeBits, |
| | | 142 | | bool returnUnsignedOnFailure = true, |
| | | 143 | | bool allowInProduction = false, |
| | | 144 | | string? environmentName = null) |
| | | 145 | | { |
| | 35 | 146 | | return new LocalDevelopmentSigningOptions |
| | 35 | 147 | | { |
| | 35 | 148 | | AllowInProduction = allowInProduction, |
| | 35 | 149 | | EnvironmentName = string.IsNullOrWhiteSpace(environmentName) ? null : environmentName.Trim(), |
| | 35 | 150 | | ProviderName = string.IsNullOrWhiteSpace(providerName) |
| | 35 | 151 | | ? DefaultProviderName |
| | 35 | 152 | | : providerName.Trim(), |
| | 35 | 153 | | KeyId = string.IsNullOrWhiteSpace(keyId) |
| | 35 | 154 | | ? DefaultKeyId |
| | 35 | 155 | | : keyId.Trim(), |
| | 35 | 156 | | KeyVersion = string.IsNullOrWhiteSpace(keyVersion) |
| | 35 | 157 | | ? DefaultKeyVersion |
| | 35 | 158 | | : keyVersion.Trim(), |
| | 35 | 159 | | SignatureAlgorithm = string.IsNullOrWhiteSpace(signatureAlgorithm) |
| | 35 | 160 | | ? DefaultSignatureAlgorithm |
| | 35 | 161 | | : signatureAlgorithm.Trim(), |
| | 35 | 162 | | KeySizeBits = keySizeBits, |
| | 35 | 163 | | ReturnUnsignedOnFailure = returnUnsignedOnFailure |
| | 35 | 164 | | }; |
| | | 165 | | } |
| | | 166 | | } |