-
Notifications
You must be signed in to change notification settings - Fork 11
Expand file tree
/
Copy pathAuthTokenSignatureValidator.php
More file actions
102 lines (83 loc) · 4.06 KB
/
AuthTokenSignatureValidator.php
File metadata and controls
102 lines (83 loc) · 4.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
<?php
/*
* Copyright (c) 2022-2024 Estonian Information System Authority
*
* Permission is hereby granted, free of charge, to any person obtaining a copy
* of this software and associated documentation files (the "Software"), to deal
* in the Software without restriction, including without limitation the rights
* to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
* copies of the Software, and to permit persons to whom the Software is
* furnished to do so, subject to the following conditions:
*
* The above copyright notice and this permission notice shall be included in all
* copies or substantial portions of the Software.
*
* THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
* IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
* FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
* AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
* LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
* OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
* SOFTWARE.
*/
declare(strict_types=1);
namespace web_eid\web_eid_authtoken_validation_php\validator;
use GuzzleHttp\Psr7\Uri;
use web_eid\web_eid_authtoken_validation_php\exceptions\AuthTokenParseException;
use web_eid\web_eid_authtoken_validation_php\exceptions\ChallengeNullOrEmptyException;
use InvalidArgumentException;
use web_eid\web_eid_authtoken_validation_php\util\AsnUtil;
use web_eid\web_eid_authtoken_validation_php\exceptions\AuthTokenSignatureValidationException;
class AuthTokenSignatureValidator
{
/** Supported subset of JSON Web Signature algorithms as defined in RFC 7518, sections 3.3, 3.4, 3.5.
* See https://github.com/web-eid/libelectronic-id/blob/main/include/electronic-id/enums.hpp#L176.
*/
private const ALLOWED_SIGNATURE_ALGORITHMS = [
'ES256', 'ES384', 'ES512', // ECDSA
'PS256', 'PS384', 'PS512', // RSASSA-PSS
'RS256', 'RS384', 'RS512', // RSASSA-PKCS1-v1_5
];
private Uri $siteOrigin;
public function __construct(Uri $siteOrigin)
{
$this->siteOrigin = $siteOrigin;
}
public function validate(string $algorithm, string $signature, $publicKey, string $currentChallengeNonce): void
{
if (empty($currentChallengeNonce)) {
throw new ChallengeNullOrEmptyException();
}
if (is_null($publicKey)) {
throw new InvalidArgumentException("Public key is null");
}
$this->requireNotEmpty($algorithm, "algorithm");
$this->requireNotEmpty($signature, "signature");
if (!in_array($algorithm, self::ALLOWED_SIGNATURE_ALGORITHMS)) {
throw new AuthTokenParseException("Unsupported signature algorithm");
}
$decodedSignature = base64_decode($signature);
// Note that in case of ECDSA, some eID cards output raw R||S, so we need to trascode it to DER
if (in_array($algorithm, ["ES256", "ES384", "ES512"]) && !AsnUtil::isSignatureInAsn1Format($decodedSignature)) {
$decodedSignature = AsnUtil::transcodeSignatureToDER($decodedSignature);
}
$hashAlgorithm = $this->hashAlgorithmForName($algorithm);
$originHash = openssl_digest($this->siteOrigin->jsonSerialize(), $hashAlgorithm, true);
$nonceHash = openssl_digest($currentChallengeNonce, $hashAlgorithm, true);
$concatSignedFields = $originHash . $nonceHash;
$result = openssl_verify($concatSignedFields, $decodedSignature, $publicKey, $hashAlgorithm);
if ($result !== 1) {
throw new AuthTokenSignatureValidationException($result === -1 ? openssl_error_string() : "Signature is invalid");
}
}
private function hashAlgorithmForName(string $algorithm): string
{
return "sha" . substr($algorithm, -3);
}
private function requireNotEmpty(string $argument, string $fieldName): void
{
if (empty($argument)) {
throw new AuthTokenParseException("'" . $fieldName . "' is null or empty");
}
}
}