Class: Ksef::Crypto::Certificate

Inherits:
Data
  • Object
show all
Defined in:
lib/ksef/crypto/certificate.rb,
lib/ksef/crypto/certificate.rb

Overview

Reopened rather than using a Data.define block so the usage constants land on the class rather than on Object.

Constant Summary collapse

KSEF_TOKEN_ENCRYPTION =

The two members of the contract's PublicKeyCertificateUsage enum. Keeping them here rather than as bare strings at call sites means a typo is a NameError at load time instead of an empty selection at runtime.

"KsefTokenEncryption"
SYMMETRIC_KEY_ENCRYPTION =
"SymmetricKeyEncryption"
USAGES =
[KSEF_TOKEN_ENCRYPTION, SYMMETRIC_KEY_ENCRYPTION].freeze

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Instance Attribute Details

#certificate ⇒ Object (readonly)

Returns the value of attribute certificate

Returns:

  • (Object) —

    the current value of certificate



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def certificate
  @certificate
end

#certificate_id ⇒ Object (readonly)

Returns the value of attribute certificate_id

Returns:

  • (Object) —

    the current value of certificate_id



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def certificate_id
  @certificate_id
end

#public_key_id ⇒ Object (readonly)

Returns the value of attribute public_key_id

Returns:

  • (Object) —

    the current value of public_key_id



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def public_key_id
  @public_key_id
end

#usage ⇒ Object (readonly)

Returns the value of attribute usage

Returns:

  • (Object) —

    the current value of usage



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def usage
  @usage
end

#valid_from ⇒ Object (readonly)

Returns the value of attribute valid_from

Returns:

  • (Object) —

    the current value of valid_from



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def valid_from
  @valid_from
end

#valid_to ⇒ Object (readonly)

Returns the value of attribute valid_to

Returns:

  • (Object) —

    the current value of valid_to



12
13
14
# File 'lib/ksef/crypto/certificate.rb', line 12

def valid_to
  @valid_to
end

Class Method Details

.from(payload) ⇒ Object



24
25
26
27
28
29
30
31
32
33
# File 'lib/ksef/crypto/certificate.rb', line 24

def self.from(payload)
  new(
    certificate: payload["certificate"],
    certificate_id: payload["certificateId"],
    public_key_id: payload["publicKeyId"],
    valid_from: time(payload["validFrom"]),
    valid_to: time(payload["validTo"]),
    usage: Array(payload["usage"]).freeze
  )
end

Instance Method Details

#encrypt(plaintext) ⇒ String

RSA-OAEP under this certificate's key. The plaintexts KSeF asks for are a 32-byte symmetric key (§10.1) and a short token|timestamp string (§4.5), both far inside MAX_OAEP_PLAINTEXT_BYTES.

Returns:



75
# File 'lib/ksef/crypto/certificate.rb', line 75

def encrypt(plaintext) = Crypto.rsa_encrypt(plaintext, public_key)

#public_key ⇒ OpenSSL::PKey::RSA

Returns:

  • (OpenSSL::PKey::RSA)


68
# File 'lib/ksef/crypto/certificate.rb', line 68

def public_key = x509.public_key

#usable_for?(kind) ⇒ Boolean

Parameters:

  • kind (String) —

    one of USAGES

Returns:

  • (Boolean)


50
# File 'lib/ksef/crypto/certificate.rb', line 50

def usable_for?(kind) = usage.include?(kind)

#valid_at?(now = Time.now) ⇒ Boolean

Returns:

  • (Boolean)


52
53
54
55
56
# File 'lib/ksef/crypto/certificate.rb', line 52

def valid_at?(now = Time.now)
  return false if valid_from.nil? || valid_to.nil?

  now.between?(valid_from, valid_to)
end

#x509 ⇒ OpenSSL::X509::Certificate

The contract ships the certificate as DER, base64-encoded, without PEM armour, so it cannot be handed to OpenSSL as text.

Not memoised: Data instances are frozen, and this is called once per session open or authentication, where a DER parse is not worth caching around.

Returns:

  • (OpenSSL::X509::Certificate)


65
# File 'lib/ksef/crypto/certificate.rb', line 65

def x509 = OpenSSL::X509::Certificate.new(Crypto.decode(certificate))