Class: Ksef::Auth::SignatureTemplate

Inherits:
Object
  • Object
show all
Includes:
Xades
Defined in:
lib/ksef/auth/signature_template.rb

Overview

Renders the ds:Signature element, with the SignedProperties digest and the SignatureValue left empty for Signer to fill in once they can be computed.

Separated from Signer because the two jobs are genuinely different: this one is string templating with fiddly namespace placement, the other is canonicalising, digesting and signing. Rendering from a template rather than assembling nodes is deliberate — the prefixed and default-namespaced elements interleave, and the equivalent Nokogiri namespace calls are markedly harder to read and to get right.

Constant Summary

Constants included from Xades

Xades::C14N_MODE, Xades::CANONICALIZATION, Xades::DIGEST_METHOD, Xades::DS, Xades::ENVELOPED_SIGNATURE, Xades::SIGNATURE_ID, Xades::SIGNATURE_METHOD, Xades::SIGNED_PROPERTIES_ID, Xades::SIGNED_PROPERTIES_TYPE, Xades::XADES, Xades::XPATH_NAMESPACES

Instance Method Summary collapse

Constructor Details

#initialize(certificate:, signing_time:) ⇒ SignatureTemplate

Returns a new instance of SignatureTemplate.



18
19
20
21
# File 'lib/ksef/auth/signature_template.rb', line 18

def initialize(certificate:, signing_time:)
  @certificate = certificate
  @signing_time = signing_time
end

Instance Method Details

#render(document_digest) ⇒ String

Returns the signature element, ready to be parsed and adopted.

Parameters:

  • document_digest (String) —

    Base64 SHA-256 over the canonicalised document

Returns:

  • (String) —

    the signature element, ready to be parsed and adopted



25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
# File 'lib/ksef/auth/signature_template.rb', line 25

def render(document_digest)
  <<~XML
    <ds:Signature xmlns:ds="#{DS}" Id="#{SIGNATURE_ID}">
      <ds:SignedInfo>
        <ds:CanonicalizationMethod Algorithm="#{CANONICALIZATION}"/>
        <ds:SignatureMethod Algorithm="#{SIGNATURE_METHOD}"/>
    #{document_reference(document_digest)}
    #{signed_properties_reference}
      </ds:SignedInfo>
      <ds:SignatureValue/>
      <ds:KeyInfo>
        <ds:X509Data>
          <ds:X509Certificate>#{encode(certificate.to_der)}</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
      <ds:Object>#{qualifying_properties}</ds:Object>
    </ds:Signature>
  XML
end