| | | 1 | | using System.Collections.ObjectModel; |
| | | 2 | | |
| | | 3 | | namespace AsiBackbone.Core.Signing; |
| | | 4 | | |
| | | 5 | | /// <summary> |
| | | 6 | | /// Represents a provider-neutral request to verify signing metadata against a precomputed artifact hash. |
| | | 7 | | /// </summary> |
| | | 8 | | public sealed class SignatureVerificationRequest |
| | | 9 | | { |
| | | 10 | | private readonly byte[]? signatureInput; |
| | | 11 | | |
| | 2 | 12 | | private static readonly IReadOnlyDictionary<string, string> EmptyMetadata = |
| | 2 | 13 | | new ReadOnlyDictionary<string, string>( |
| | 2 | 14 | | new Dictionary<string, string>(StringComparer.Ordinal)); |
| | | 15 | | |
| | | 16 | | /// <summary> |
| | | 17 | | /// Initializes a new instance of the <see cref="SignatureVerificationRequest" /> class. |
| | | 18 | | /// </summary> |
| | 51 | 19 | | public SignatureVerificationRequest( |
| | 51 | 20 | | string signingHash, |
| | 51 | 21 | | SigningMetadata signingMetadata, |
| | 51 | 22 | | string? purpose = null, |
| | 51 | 23 | | IReadOnlyDictionary<string, string>? metadata = null) |
| | | 24 | | { |
| | 51 | 25 | | ArgumentException.ThrowIfNullOrWhiteSpace(signingHash); |
| | 51 | 26 | | ArgumentNullException.ThrowIfNull(signingMetadata); |
| | | 27 | | |
| | 51 | 28 | | SigningHash = signingHash.Trim(); |
| | 51 | 29 | | SigningMetadata = signingMetadata; |
| | 51 | 30 | | Purpose = NormalizeOptional(purpose); |
| | 51 | 31 | | Metadata = NormalizeMetadata(metadata); |
| | 51 | 32 | | } |
| | | 33 | | |
| | | 34 | | /// <summary> |
| | | 35 | | /// Gets the precomputed artifact hash expected to have been signed. |
| | | 36 | | /// </summary> |
| | | 37 | | public string SigningHash { get; } |
| | | 38 | | |
| | | 39 | | /// <summary> |
| | | 40 | | /// Gets the provider-neutral signing metadata to verify. |
| | | 41 | | /// </summary> |
| | | 42 | | public SigningMetadata SigningMetadata { get; } |
| | | 43 | | |
| | | 44 | | /// <summary> |
| | | 45 | | /// Gets the host-defined verification purpose, when supplied. |
| | | 46 | | /// </summary> |
| | | 47 | | public string? Purpose { get; } |
| | | 48 | | |
| | | 49 | | /// <summary> |
| | | 50 | | /// Gets additional provider-neutral request metadata. |
| | | 51 | | /// </summary> |
| | | 52 | | public IReadOnlyDictionary<string, string> Metadata { get; } |
| | | 53 | | |
| | | 54 | | /// <summary> |
| | | 55 | | /// Gets a value indicating whether metadata is present. |
| | | 56 | | /// </summary> |
| | 3 | 57 | | public bool HasMetadata => Metadata.Count > 0; |
| | | 58 | | |
| | | 59 | | /// <summary> |
| | | 60 | | /// Gets the exact bytes the verification provider must verify the signature against. |
| | | 61 | | /// </summary> |
| | | 62 | | /// <remarks> |
| | | 63 | | /// <see cref="GovernanceArtifactVerifier" /> sets this to the version 1 input rebuilt from the artifact and its sig |
| | | 64 | | /// metadata, or to the pre-6.0 input when the verification context explicitly allows it. Verification providers mus |
| | | 65 | | /// verify these bytes rather than <see cref="SigningHash" />; verifying the hash text instead leaves the signing po |
| | | 66 | | /// context unauthenticated. When no input was supplied, this returns the pre-6.0 input from |
| | | 67 | | /// <see cref="GovernanceSignatureInput.CreateLegacy" />. The supplied value is copied. |
| | | 68 | | /// </remarks> |
| | | 69 | | public ReadOnlyMemory<byte> SignatureInput |
| | | 70 | | { |
| | | 71 | | #pragma warning disable ASIB902 // Retained internal fallback for pre-6.0 provider-request compatibility. |
| | 15 | 72 | | get => signatureInput ?? GovernanceSignatureInput.CreateLegacy(SigningHash); |
| | | 73 | | #pragma warning restore ASIB902 |
| | 43 | 74 | | init => signatureInput = value.IsEmpty ? null : [.. value.Span]; |
| | | 75 | | } |
| | | 76 | | |
| | | 77 | | /// <summary> |
| | | 78 | | /// Gets a value indicating whether no explicit signature input was supplied, so <see cref="SignatureInput" /> is th |
| | | 79 | | /// pre-6.0 hash-only input. |
| | | 80 | | /// </summary> |
| | 0 | 81 | | public bool UsesLegacySignatureInput => signatureInput is null; |
| | | 82 | | |
| | | 83 | | private static string? NormalizeOptional(string? value) |
| | | 84 | | { |
| | 51 | 85 | | return string.IsNullOrWhiteSpace(value) |
| | 51 | 86 | | ? null |
| | 51 | 87 | | : value.Trim(); |
| | | 88 | | } |
| | | 89 | | |
| | | 90 | | private static IReadOnlyDictionary<string, string> NormalizeMetadata( |
| | | 91 | | IReadOnlyDictionary<string, string>? metadata) |
| | | 92 | | { |
| | 51 | 93 | | if (metadata is null || metadata.Count == 0) |
| | | 94 | | { |
| | 49 | 95 | | return EmptyMetadata; |
| | | 96 | | } |
| | | 97 | | |
| | 2 | 98 | | Dictionary<string, string> normalizedMetadata = new(StringComparer.Ordinal); |
| | | 99 | | |
| | 12 | 100 | | foreach (KeyValuePair<string, string> item in metadata) |
| | | 101 | | { |
| | 4 | 102 | | if (string.IsNullOrWhiteSpace(item.Key)) |
| | | 103 | | { |
| | | 104 | | continue; |
| | | 105 | | } |
| | | 106 | | |
| | 2 | 107 | | normalizedMetadata[item.Key.Trim()] = item.Value?.Trim() ?? string.Empty; |
| | | 108 | | } |
| | | 109 | | |
| | 2 | 110 | | return normalizedMetadata.Count == 0 |
| | 2 | 111 | | ? EmptyMetadata |
| | 2 | 112 | | : new ReadOnlyDictionary<string, string>(normalizedMetadata); |
| | | 113 | | } |
| | | 114 | | } |