Class: Saml::Kit::Signature

Inherits:
Object
  • Object
show all
Includes:
ActiveModel::Validations, Translatable
Defined in:
lib/saml/kit/signature.rb

Overview

This class is responsible for validating an xml digital signature in an xml document.

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(node) ⇒ Signature

Returns a new instance of Signature.



17
18
19
20
# File 'lib/saml/kit/signature.rb', line 17

def initialize(node)
  @name = 'Signature'
  @node = node
end

Instance Attribute Details

#nameObject (readonly)

Returns the value of attribute name.



15
16
17
# File 'lib/saml/kit/signature.rb', line 15

def name
  @name
end

Instance Method Details

#canonicalization_methodObject



58
59
60
# File 'lib/saml/kit/signature.rb', line 58

def canonicalization_method
  at_xpath('./ds:SignedInfo/ds:CanonicalizationMethod/@Algorithm').try(:value)
end

#certificateObject

Returns the embedded X509 Certificate



23
24
25
26
27
# File 'lib/saml/kit/signature.rb', line 23

def certificate
  value = at_xpath('./ds:KeyInfo/ds:X509Data/ds:X509Certificate').try(:text)
  return if value.nil?
  ::Xml::Kit::Certificate.new(value, use: :signing)
end

#digest_methodObject



46
47
48
# File 'lib/saml/kit/signature.rb', line 46

def digest_method
  at_xpath('./ds:SignedInfo/ds:Reference/ds:DigestMethod/@Algorithm').try(:value)
end

#digest_valueObject



35
36
37
# File 'lib/saml/kit/signature.rb', line 35

def digest_value
  at_xpath('./ds:SignedInfo/ds:Reference/ds:DigestValue').try(:text)
end

#expected_digest_valueObject



39
40
41
42
43
44
# File 'lib/saml/kit/signature.rb', line 39

def expected_digest_value
  digests = dsignature.references.map do |xxx|
    Base64.encode64(xxx.calculate_digest_value).chomp
  end
  digests.count > 1 ? digests : digests[0]
end

#present?Boolean

Returns:

  • (Boolean)


71
72
73
# File 'lib/saml/kit/signature.rb', line 71

def present?
  node.present?
end

#signature_methodObject



54
55
56
# File 'lib/saml/kit/signature.rb', line 54

def signature_method
  at_xpath('./ds:SignedInfo/ds:SignatureMethod/@Algorithm').try(:value)
end

#signature_valueObject



50
51
52
# File 'lib/saml/kit/signature.rb', line 50

def signature_value
  at_xpath('./ds:SignatureValue').try(:text)
end

#to_hObject

Returns the XML Hash.



67
68
69
# File 'lib/saml/kit/signature.rb', line 67

def to_h
  @to_h ||= present? ? Hash.from_xml(to_xml)['Signature'] : {}
end

#to_sObject



79
80
81
# File 'lib/saml/kit/signature.rb', line 79

def to_s
  node.to_s
end

#to_xml(pretty: nil) ⇒ Object



75
76
77
# File 'lib/saml/kit/signature.rb', line 75

def to_xml(pretty: nil)
  pretty ? node.to_xml(indent: 2) : to_s
end

#transformsObject



62
63
64
# File 'lib/saml/kit/signature.rb', line 62

def transforms
  node.search('./ds:SignedInfo/ds:Reference/ds:Transforms/ds:Transform/@Algorithm', Saml::Kit::Document::NAMESPACES).try(:map, &:value)
end

#trusted?(metadata) ⇒ Boolean

Returns true when the fingerprint of the certificate matches one of the certificates registered in the metadata.

Returns:

  • (Boolean)


30
31
32
33
# File 'lib/saml/kit/signature.rb', line 30

def trusted?()
  return false if .nil?
  .matches?(certificate.fingerprint, use: :signing).present?
end