| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | using AsiBackbone.Core.Signing; |
| | | 3 | | |
| | | 4 | | namespace AsiBackbone.Signing.ManagedKey; |
| | | 5 | | |
| | | 6 | | /// <summary> |
| | | 7 | | /// Represents a managed-key client request to sign a precomputed governance artifact hash. |
| | | 8 | | /// </summary> |
| | | 9 | | public sealed class ManagedKeySignRequest |
| | | 10 | | { |
| | | 11 | | private readonly byte[]? signatureInput; |
| | | 12 | | |
| | 1 | 13 | | private static readonly ReadOnlyDictionary<string, string> EmptyMetadata = |
| | 1 | 14 | | new(new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 15 | | |
| | | 16 | | /// <summary> |
| | | 17 | | /// Initializes a new instance of the <see cref="ManagedKeySignRequest" /> class. |
| | | 18 | | /// </summary> |
| | 53 | 19 | | public ManagedKeySignRequest( |
| | 53 | 20 | | string signingHash, |
| | 53 | 21 | | string hashAlgorithm, |
| | 53 | 22 | | string signatureAlgorithm, |
| | 53 | 23 | | string keyId, |
| | 53 | 24 | | string? keyVersion = null, |
| | 53 | 25 | | string? purpose = null, |
| | 53 | 26 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 27 | | { |
| | 53 | 28 | | ArgumentException.ThrowIfNullOrWhiteSpace(signingHash); |
| | 50 | 29 | | ArgumentException.ThrowIfNullOrWhiteSpace(hashAlgorithm); |
| | 47 | 30 | | ArgumentException.ThrowIfNullOrWhiteSpace(signatureAlgorithm); |
| | 44 | 31 | | ArgumentException.ThrowIfNullOrWhiteSpace(keyId); |
| | | 32 | | |
| | 41 | 33 | | SigningHash = signingHash.Trim(); |
| | 41 | 34 | | HashAlgorithm = NormalizeRequired(hashAlgorithm); |
| | 41 | 35 | | SignatureAlgorithm = NormalizeRequired(signatureAlgorithm); |
| | 41 | 36 | | KeyId = NormalizeRequired(keyId); |
| | 41 | 37 | | KeyVersion = NormalizeOptional(keyVersion); |
| | 41 | 38 | | Purpose = NormalizeOptional(purpose); |
| | 41 | 39 | | Metadata = NormalizeMetadata(metadata); |
| | 41 | 40 | | } |
| | | 41 | | |
| | | 42 | | /// <summary> |
| | | 43 | | /// Gets the precomputed hash to sign. |
| | | 44 | | /// </summary> |
| | | 45 | | public string SigningHash { get; } |
| | | 46 | | |
| | | 47 | | /// <summary> |
| | | 48 | | /// Gets the hash algorithm descriptor associated with <see cref="SigningHash" />. |
| | | 49 | | /// </summary> |
| | | 50 | | public string HashAlgorithm { get; } |
| | | 51 | | |
| | | 52 | | /// <summary> |
| | | 53 | | /// Gets the requested provider-neutral signature algorithm descriptor. |
| | | 54 | | /// </summary> |
| | | 55 | | public string SignatureAlgorithm { get; } |
| | | 56 | | |
| | | 57 | | /// <summary> |
| | | 58 | | /// Gets the managed key identifier or key URI reference. |
| | | 59 | | /// </summary> |
| | | 60 | | public string KeyId { get; } |
| | | 61 | | |
| | | 62 | | /// <summary> |
| | | 63 | | /// Gets the managed key version, when supplied. |
| | | 64 | | /// </summary> |
| | | 65 | | public string? KeyVersion { get; } |
| | | 66 | | |
| | | 67 | | /// <summary> |
| | | 68 | | /// Gets the host-defined signing purpose, when supplied. |
| | | 69 | | /// </summary> |
| | | 70 | | public string? Purpose { get; } |
| | | 71 | | |
| | | 72 | | /// <summary> |
| | | 73 | | /// Gets provider-neutral request metadata. |
| | | 74 | | /// </summary> |
| | | 75 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 76 | | |
| | | 77 | | /// <summary> |
| | | 78 | | /// Gets the exact bytes the managed key must sign. |
| | | 79 | | /// </summary> |
| | | 80 | | /// <remarks> |
| | | 81 | | /// <see cref="ManagedKeySigningService" /> copies <see cref="SigningRequest.SignatureInput" /> here. For artifacts |
| | | 82 | | /// signed through <see cref="GovernanceArtifactSigner" /> this is the version 1 input that binds the canonical |
| | | 83 | | /// descriptors, hash, and signing policy context. Clients must sign these bytes, not <see cref="SigningHash" />: pa |
| | | 84 | | /// them as the message to a message-signing API, or hash them with the key's digest algorithm before calling a |
| | | 85 | | /// digest-signing API. A client that signs the hash text produces signatures that fail version 1 verification. When |
| | | 86 | | /// input was supplied, this returns the pre-6.0 hash-only input. The supplied value is copied. |
| | | 87 | | /// </remarks> |
| | | 88 | | public ReadOnlyMemory<byte> SignatureInput |
| | | 89 | | { |
| | | 90 | | #pragma warning disable ASIB902 // Retained internal fallback for pre-6.0 provider-request compatibility. |
| | 8 | 91 | | get => signatureInput ?? GovernanceSignatureInput.CreateLegacy(SigningHash); |
| | | 92 | | #pragma warning restore ASIB902 |
| | 34 | 93 | | init => signatureInput = value.IsEmpty ? null : [.. value.Span]; |
| | | 94 | | } |
| | | 95 | | |
| | | 96 | | private static string NormalizeRequired(string value) |
| | | 97 | | { |
| | 123 | 98 | | return value.Trim(); |
| | | 99 | | } |
| | | 100 | | |
| | | 101 | | private static string? NormalizeOptional(string? value) |
| | | 102 | | { |
| | 82 | 103 | | return string.IsNullOrWhiteSpace(value) ? null : value.Trim(); |
| | | 104 | | } |
| | | 105 | | |
| | | 106 | | private static ReadOnlyDictionary<string, string> NormalizeMetadata(IReadOnlyDictionary<string, string>? metadata) |
| | | 107 | | { |
| | 41 | 108 | | if (metadata is null || metadata.Count == 0) |
| | | 109 | | { |
| | 35 | 110 | | return EmptyMetadata; |
| | | 111 | | } |
| | | 112 | | |
| | 6 | 113 | | Dictionary<string, string> normalized = new(StringComparer.Ordinal); |
| | | 114 | | |
| | 98 | 115 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 116 | | { |
| | 43 | 117 | | if (!string.IsNullOrWhiteSpace(item.Key)) |
| | | 118 | | { |
| | 40 | 119 | | normalized[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 120 | | } |
| | | 121 | | } |
| | | 122 | | |
| | 6 | 123 | | return normalized.Count == 0 ? EmptyMetadata : new ReadOnlyDictionary<string, string>(normalized); |
| | | 124 | | } |
| | | 125 | | } |