| | | 1 | | using AsiBackbone.Core.Signing; |
| | | 2 | | using Microsoft.Extensions.DependencyInjection; |
| | | 3 | | |
| | | 4 | | namespace AsiBackbone.Signing.ManagedKey; |
| | | 5 | | |
| | | 6 | | /// <summary> |
| | | 7 | | /// Provides dependency injection registration helpers for managed-key signing. |
| | | 8 | | /// </summary> |
| | | 9 | | public static class ManagedKeySigningServiceCollectionExtensions |
| | | 10 | | { |
| | | 11 | | /// <summary> |
| | | 12 | | /// Adds production-oriented managed-key signing with a host-owned managed-key client factory. |
| | | 13 | | /// </summary> |
| | | 14 | | /// <remarks> |
| | | 15 | | /// The production-oriented registration fails closed by default because <see cref="ManagedKeySigningOptions.ReturnU |
| | | 16 | | /// defaults to <see langword="false" />. |
| | | 17 | | /// </remarks> |
| | | 18 | | public static IServiceCollection AddAsiBackboneManagedKeySigning( |
| | | 19 | | this IServiceCollection services, |
| | | 20 | | Action<ManagedKeySigningOptions> configure, |
| | | 21 | | Func<IServiceProvider, IManagedKeySigningClient> clientFactory) |
| | | 22 | | { |
| | 6 | 23 | | ArgumentNullException.ThrowIfNull(services); |
| | 5 | 24 | | ArgumentNullException.ThrowIfNull(configure); |
| | 4 | 25 | | ArgumentNullException.ThrowIfNull(clientFactory); |
| | | 26 | | |
| | 3 | 27 | | ManagedKeySigningOptions options = new(); |
| | 3 | 28 | | configure(options); |
| | 3 | 29 | | options.Validate(); |
| | | 30 | | |
| | 3 | 31 | | return AddManagedKeySigningCore(services, options, clientFactory); |
| | | 32 | | } |
| | | 33 | | |
| | | 34 | | /// <summary> |
| | | 35 | | /// Adds production-oriented managed-key signing using an already-registered <see cref="IManagedKeySigningClient" /> |
| | | 36 | | /// </summary> |
| | | 37 | | /// <remarks> |
| | | 38 | | /// The production-oriented registration fails closed by default because <see cref="ManagedKeySigningOptions.ReturnU |
| | | 39 | | /// defaults to <see langword="false" />. |
| | | 40 | | /// </remarks> |
| | | 41 | | public static IServiceCollection AddAsiBackboneManagedKeySigning( |
| | | 42 | | this IServiceCollection services, |
| | | 43 | | Action<ManagedKeySigningOptions> configure) |
| | | 44 | | { |
| | 9 | 45 | | ArgumentNullException.ThrowIfNull(services); |
| | 8 | 46 | | ArgumentNullException.ThrowIfNull(configure); |
| | | 47 | | |
| | 7 | 48 | | ManagedKeySigningOptions options = new(); |
| | 7 | 49 | | configure(options); |
| | 7 | 50 | | options.Validate(); |
| | | 51 | | |
| | 6 | 52 | | return AddManagedKeySigningCore(services, options); |
| | | 53 | | } |
| | | 54 | | |
| | | 55 | | /// <summary> |
| | | 56 | | /// Adds local-validation managed-key signing with a host-owned managed-key client factory. |
| | | 57 | | /// </summary> |
| | | 58 | | /// <remarks> |
| | | 59 | | /// This helper explicitly sets <see cref="ManagedKeySigningOptions.ReturnUnsignedOnFailure" /> to <see langword="tr |
| | | 60 | | /// so samples, tests, and diagnostics can inspect unsigned failure metadata. Do not use this helper as the default |
| | | 61 | | /// production registration unless host policy explicitly routes unsigned failure metadata. |
| | | 62 | | /// </remarks> |
| | | 63 | | public static IServiceCollection AddAsiBackboneManagedKeySigningForLocalValidation( |
| | | 64 | | this IServiceCollection services, |
| | | 65 | | Action<ManagedKeySigningOptions> configure, |
| | | 66 | | Func<IServiceProvider, IManagedKeySigningClient> clientFactory) |
| | | 67 | | { |
| | 5 | 68 | | ArgumentNullException.ThrowIfNull(services); |
| | 4 | 69 | | ArgumentNullException.ThrowIfNull(configure); |
| | 3 | 70 | | ArgumentNullException.ThrowIfNull(clientFactory); |
| | | 71 | | |
| | 2 | 72 | | ManagedKeySigningOptions options = new(); |
| | 2 | 73 | | configure(options); |
| | 2 | 74 | | options.ReturnUnsignedOnFailure = true; |
| | 2 | 75 | | options.Validate(); |
| | | 76 | | |
| | 2 | 77 | | return AddManagedKeySigningCore(services, options, clientFactory); |
| | | 78 | | } |
| | | 79 | | |
| | | 80 | | /// <summary> |
| | | 81 | | /// Adds local-validation managed-key signing using an already-registered <see cref="IManagedKeySigningClient" />. |
| | | 82 | | /// </summary> |
| | | 83 | | /// <remarks> |
| | | 84 | | /// This helper explicitly sets <see cref="ManagedKeySigningOptions.ReturnUnsignedOnFailure" /> to <see langword="tr |
| | | 85 | | /// so samples, tests, and diagnostics can inspect unsigned failure metadata. Do not use this helper as the default |
| | | 86 | | /// production registration unless host policy explicitly routes unsigned failure metadata. |
| | | 87 | | /// </remarks> |
| | | 88 | | public static IServiceCollection AddAsiBackboneManagedKeySigningForLocalValidation( |
| | | 89 | | this IServiceCollection services, |
| | | 90 | | Action<ManagedKeySigningOptions> configure) |
| | | 91 | | { |
| | 3 | 92 | | ArgumentNullException.ThrowIfNull(services); |
| | 2 | 93 | | ArgumentNullException.ThrowIfNull(configure); |
| | | 94 | | |
| | 1 | 95 | | ManagedKeySigningOptions options = new(); |
| | 1 | 96 | | configure(options); |
| | 1 | 97 | | options.ReturnUnsignedOnFailure = true; |
| | 1 | 98 | | options.Validate(); |
| | | 99 | | |
| | 1 | 100 | | return AddManagedKeySigningCore(services, options); |
| | | 101 | | } |
| | | 102 | | |
| | | 103 | | private static IServiceCollection AddManagedKeySigningCore( |
| | | 104 | | IServiceCollection services, |
| | | 105 | | ManagedKeySigningOptions options, |
| | | 106 | | Func<IServiceProvider, IManagedKeySigningClient> clientFactory) |
| | | 107 | | { |
| | 5 | 108 | | _ = services.AddSingleton(options); |
| | 5 | 109 | | _ = services.AddSingleton(clientFactory); |
| | 5 | 110 | | _ = services.AddSingleton(provider => |
| | 5 | 111 | | { |
| | 5 | 112 | | ThrowIfProductionWithoutVerification(provider); |
| | 5 | 113 | | return new ManagedKeySigningService( |
| | 5 | 114 | | provider.GetRequiredService<ManagedKeySigningOptions>(), |
| | 5 | 115 | | provider.GetRequiredService<IManagedKeySigningClient>()); |
| | 5 | 116 | | }); |
| | 5 | 117 | | _ = services.AddSingleton<IGovernanceSigningService>(provider => |
| | 5 | 118 | | provider.GetRequiredService<ManagedKeySigningService>()); |
| | | 119 | | |
| | 5 | 120 | | return services; |
| | | 121 | | } |
| | | 122 | | |
| | | 123 | | private static IServiceCollection AddManagedKeySigningCore( |
| | | 124 | | IServiceCollection services, |
| | | 125 | | ManagedKeySigningOptions options) |
| | | 126 | | { |
| | 7 | 127 | | _ = services.AddSingleton(options); |
| | 7 | 128 | | _ = services.AddSingleton(provider => |
| | 7 | 129 | | { |
| | 7 | 130 | | ThrowIfProductionWithoutVerification(provider); |
| | 7 | 131 | | return new ManagedKeySigningService( |
| | 7 | 132 | | provider.GetRequiredService<ManagedKeySigningOptions>(), |
| | 7 | 133 | | provider.GetRequiredService<IManagedKeySigningClient>()); |
| | 7 | 134 | | }); |
| | 7 | 135 | | _ = services.AddSingleton<IGovernanceSigningService>(provider => |
| | 7 | 136 | | provider.GetRequiredService<ManagedKeySigningService>()); |
| | | 137 | | |
| | 7 | 138 | | return services; |
| | | 139 | | } |
| | | 140 | | |
| | | 141 | | private static void ThrowIfProductionWithoutVerification(IServiceProvider serviceProvider) |
| | | 142 | | { |
| | 12 | 143 | | string? dotnetEnvironment = Environment.GetEnvironmentVariable("DOTNET_ENVIRONMENT"); |
| | 12 | 144 | | string? aspNetCoreEnvironment = Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT"); |
| | 12 | 145 | | bool hasExplicitEnvironment = !string.IsNullOrWhiteSpace(dotnetEnvironment) |
| | 12 | 146 | | || !string.IsNullOrWhiteSpace(aspNetCoreEnvironment); |
| | 12 | 147 | | bool isProduction = !hasExplicitEnvironment |
| | 12 | 148 | | || string.Equals(dotnetEnvironment, "Production", StringComparison.OrdinalIgnoreCase) |
| | 12 | 149 | | || string.Equals(aspNetCoreEnvironment, "Production", StringComparison.OrdinalIgnoreCase); |
| | | 150 | | |
| | 12 | 151 | | if (!isProduction) |
| | | 152 | | { |
| | 4 | 153 | | return; |
| | | 154 | | } |
| | | 155 | | |
| | 8 | 156 | | IServiceProviderIsService? isService = serviceProvider.GetService<IServiceProviderIsService>(); |
| | 8 | 157 | | bool hasVerificationRegistration = isService?.IsService(typeof(IGovernanceSignatureVerificationService)) |
| | 8 | 158 | | ?? (serviceProvider.GetService<IGovernanceSignatureVerificationService>() is not null); |
| | | 159 | | |
| | 8 | 160 | | if (!hasVerificationRegistration) |
| | | 161 | | { |
| | 3 | 162 | | throw new InvalidOperationException( |
| | 3 | 163 | | "Managed-key signing is being resolved in Production without an IGovernanceSignatureVerificationService. |
| | 3 | 164 | | "This host signs artifacts but never verifies them, which silently breaks trust validation. " + |
| | 3 | 165 | | "Register a verification implementation before resolving the signing service or move this registration b |
| | | 166 | | } |
| | 5 | 167 | | } |
| | | 168 | | } |