| | | 1 | | namespace AsiBackbone.Core.Signing; |
| | | 2 | | |
| | | 3 | | /// <summary> |
| | | 4 | | /// Evaluates provider-neutral signature verification results against host verification policy. |
| | | 5 | | /// </summary> |
| | | 6 | | public static class VerificationPolicyEvaluator |
| | | 7 | | { |
| | 1 | 8 | | private static readonly CategoryRule[] FailureCodeCategoryRules = |
| | 1 | 9 | | [ |
| | 1 | 10 | | new(SignatureVerificationCategory.MissingSignature, ["missing"]), |
| | 1 | 11 | | new(SignatureVerificationCategory.HashMismatch, ["hash"]), |
| | 1 | 12 | | new(SignatureVerificationCategory.CanonicalizationMismatch, ["canonicalization", "payload-schema", "artifact"]), |
| | 1 | 13 | | new(SignatureVerificationCategory.UnsupportedAlgorithm, ["unsupported", "algorithm"]), |
| | 1 | 14 | | new(SignatureVerificationCategory.RevokedKey, ["revoked", "disabled"]), |
| | 1 | 15 | | new(SignatureVerificationCategory.UntrustedKey, ["key-not-trusted", "key.mismatch", "key-mismatch"]), |
| | 1 | 16 | | new(SignatureVerificationCategory.UntrustedSigningContext, ["provider-not-trusted", "policy-context-not-trusted" |
| | 1 | 17 | | new( |
| | 1 | 18 | | SignatureVerificationCategory.UnknownKeyVersion, |
| | 1 | 19 | | ["key-version"], |
| | 1 | 20 | | ["unknown", "key"]), |
| | 1 | 21 | | new(SignatureVerificationCategory.ProviderUnavailable, ["provider-unavailable", "unavailable", "timeout", "netwo |
| | 1 | 22 | | new(SignatureVerificationCategory.InvalidSignature, ["invalid", "malformed", "signature"]) |
| | 1 | 23 | | ]; |
| | | 24 | | |
| | | 25 | | /// <summary> |
| | | 26 | | /// Evaluates a signed governance artifact and verification result against verification policy. |
| | | 27 | | /// </summary> |
| | | 28 | | public static VerificationPolicyOutcome Evaluate<TArtifact>( |
| | | 29 | | SignedGovernanceArtifact<TArtifact> artifact, |
| | | 30 | | SignatureVerificationResult verificationResult, |
| | | 31 | | VerificationPolicyOptions? options = null) |
| | | 32 | | { |
| | 62 | 33 | | ArgumentNullException.ThrowIfNull(artifact); |
| | 62 | 34 | | ArgumentNullException.ThrowIfNull(verificationResult); |
| | | 35 | | |
| | 62 | 36 | | return VerificationPolicyOutcome.CreateCore( |
| | 62 | 37 | | artifact.ArtifactType, |
| | 62 | 38 | | artifact.ArtifactId, |
| | 62 | 39 | | artifact.SigningHash, |
| | 62 | 40 | | artifact.HashAlgorithm, |
| | 62 | 41 | | artifact.SigningMetadata, |
| | 62 | 42 | | verificationResult, |
| | 62 | 43 | | options); |
| | | 44 | | } |
| | | 45 | | |
| | | 46 | | /// <summary> |
| | | 47 | | /// Maps a provider-neutral verification result to a stable verification category. |
| | | 48 | | /// </summary> |
| | | 49 | | public static SignatureVerificationCategory Categorize(SignatureVerificationResult verificationResult) |
| | | 50 | | { |
| | 110 | 51 | | ArgumentNullException.ThrowIfNull(verificationResult); |
| | | 52 | | |
| | 109 | 53 | | if (verificationResult.IsValid) |
| | | 54 | | { |
| | 22 | 55 | | return SignatureVerificationCategory.Valid; |
| | | 56 | | } |
| | | 57 | | |
| | 87 | 58 | | if (Matches(verificationResult.Status, "MissingSignature")) |
| | | 59 | | { |
| | 6 | 60 | | return SignatureVerificationCategory.MissingSignature; |
| | | 61 | | } |
| | | 62 | | |
| | 81 | 63 | | if (verificationResult.Category is SignatureVerificationCategory explicitCategory) |
| | | 64 | | { |
| | 35 | 65 | | return explicitCategory; |
| | | 66 | | } |
| | | 67 | | |
| | 46 | 68 | | string failureCode = verificationResult.FailureCode ?? string.Empty; |
| | | 69 | | |
| | 659 | 70 | | foreach (CategoryRule rule in FailureCodeCategoryRules) |
| | | 71 | | { |
| | 305 | 72 | | if (rule.IsMatch(failureCode)) |
| | | 73 | | { |
| | 43 | 74 | | return rule.Category; |
| | | 75 | | } |
| | | 76 | | } |
| | | 77 | | |
| | 3 | 78 | | return SignatureVerificationCategory.Failed; |
| | | 79 | | } |
| | | 80 | | |
| | | 81 | | private static bool Matches(string value, string pattern) |
| | | 82 | | { |
| | 708 | 83 | | return value.Contains(pattern, StringComparison.OrdinalIgnoreCase); |
| | | 84 | | } |
| | | 85 | | |
| | | 86 | | private readonly record struct CategoryRule( |
| | | 87 | | SignatureVerificationCategory Category, |
| | | 88 | | string[] AnyPatterns, |
| | | 89 | | string[]? AllPatterns = null) |
| | | 90 | | { |
| | | 91 | | public bool IsMatch(string failureCode) |
| | | 92 | | { |
| | 1765 | 93 | | foreach (string pattern in AnyPatterns) |
| | | 94 | | { |
| | 598 | 95 | | if (Matches(failureCode, pattern)) |
| | | 96 | | { |
| | 41 | 97 | | return true; |
| | | 98 | | } |
| | | 99 | | } |
| | | 100 | | |
| | 264 | 101 | | if (AllPatterns is null) |
| | | 102 | | { |
| | 244 | 103 | | return false; |
| | | 104 | | } |
| | | 105 | | |
| | 68 | 106 | | foreach (string pattern in AllPatterns) |
| | | 107 | | { |
| | 23 | 108 | | if (!Matches(failureCode, pattern)) |
| | | 109 | | { |
| | 18 | 110 | | return false; |
| | | 111 | | } |
| | | 112 | | } |
| | | 113 | | |
| | 2 | 114 | | return AllPatterns.Length > 0; |
| | | 115 | | } |
| | | 116 | | } |
| | | 117 | | } |