pub struct VerifyContext<'a> { /* private fields */ }Expand description
Verification builder/configuration.
Implementations§
Source§impl<'a> VerifyContext<'a>
impl<'a> VerifyContext<'a>
Sourcepub fn new() -> Self
pub fn new() -> Self
Create a context with conservative defaults.
Defaults:
- no pre-set key, no key resolver
- manifests disabled
- same-document URIs only
- all transforms allowed
- pre-digest buffers not stored
Sourcepub fn key(self, key: &'a dyn VerifyingKey) -> Self
pub fn key(self, key: &'a dyn VerifyingKey) -> Self
Set a pre-resolved verification key.
Built-in super::VerificationKey values are validated against the
same operation key-strength policy as resolver-produced keys. Custom
opaque VerifyingKey implementations retain responsibility for any
key metadata that the core cannot inspect.
Sourcepub fn key_resolver(self, resolver: &'a dyn KeyResolver) -> Self
pub fn key_resolver(self, resolver: &'a dyn KeyResolver) -> Self
Set a key resolver fallback used when key() is not provided.
Sourcepub fn policy(self, policy: VerificationPolicy) -> Self
pub fn policy(self, policy: VerificationPolicy) -> Self
Replace the complete immutable verification policy snapshot.
Sourcepub fn provider(self, provider: &'a dyn CryptoProvider) -> Self
pub fn provider(self, provider: &'a dyn CryptoProvider) -> Self
Select the cryptographic provider for this verification operation.
Sourcepub fn process_manifests(self, enabled: bool) -> Self
pub fn process_manifests(self, enabled: bool) -> Self
Enable or disable <Manifest> processing.
When enabled, references in <ds:Manifest> elements that are direct
element children of <ds:Object> are processed only when the direct-child
<ds:Object> or <ds:Manifest> itself is referenced from <SignedInfo>
by an ID-based same-document fragment URI such as #id or
#xpointer(id('id')), and that reference uses only canonicalization
transforms (or implicit canonicalization). Filtering or binary transforms
do not prove that the complete Manifest structure was authenticated.
Only those signed Manifest references are returned in
VerifyResult::manifest_references.
Manifest parsing begins only after every <SignedInfo> reference digest
validates; a failure returns immediately with no Manifest results.
Nested <ds:Manifest> descendants under <ds:Object> are not
processed.
Direct-child unsigned/unreferenced Manifests are skipped and do not
appear in VerifyResult::manifest_references.
Whole-document same-document references such as URI="" or
URI="#xpointer(/)" do not mark a specific direct-child
<ds:Object>/<ds:Manifest> as signed for this option.
Manifests are parsed and processed only after the SignedInfo references
and SignatureValue both validate. Their digest mismatches, policy
violations, and processing failures are then reported independently in
VerifyResult::manifest_references and do not alter VerifyResult::status.
Callers that enable process_manifests(true) must inspect
VerifyResult::manifest_references in addition to VerifyResult::status
when interpreting verify() results.
Structural/parse errors in Manifest content abort verify() and are
returned as Err(...).
Sourcepub fn allowed_uri_types(self, types: UriTypeSet) -> Self
pub fn allowed_uri_types(self, types: UriTypeSet) -> Self
Restrict allowed reference URI classes.
Sourcepub fn allowed_retrieval_method_uri_types(self, types: UriTypeSet) -> Self
pub fn allowed_retrieval_method_uri_types(self, types: UriTypeSet) -> Self
Restrict URI classes used to retrieve key material from <KeyInfo>.
This policy is independent from Self::allowed_uri_types: allowing an
external signed payload does not implicitly allow external key retrieval.
Same-document retrieval is enabled by default; external retrieval requires
an explicit opt-in and still uses only caller-supplied resources.
Sourcepub fn external_resources(self, resources: &'a HashMap<String, Vec<u8>>) -> Self
pub fn external_resources(self, resources: &'a HashMap<String, Vec<u8>>) -> Self
Provide external URI payloads explicitly.
The map is the complete external I/O boundary: verification never
performs network or filesystem access. External URIs must also be
enabled through UriTypeSet. Map keys are RFC 3986 resolved URI
identities: use normalized paths with dot segments removed and retain
query or fragment suffixes.
Sourcepub fn start_node_id(self, id: &'a str) -> Self
pub fn start_node_id(self, id: &'a str) -> Self
Select the operation start node by its XML ID value.
Verification selects the first descendant <Signature> in document
order. This is request context, not a policy decision, and mirrors
libxmlsec1’s depth-first xmlSecFindNode start-node contract.
Sourcepub fn first_document_signature(self) -> Self
pub fn first_document_signature(self) -> Self
Select the first descendant <Signature> from the document root.
This is the libxmlsec1 command-line operation-root contract. The library default remains fail-closed and requires a unique document signature.
Sourcepub fn id_attributes(self, registrations: &'a [IdAttributeRegistration]) -> Self
pub fn id_attributes(self, registrations: &'a [IdAttributeRegistration]) -> Self
Add caller-declared ID attributes for start-node and Reference lookup.
Sourcepub fn allow_internal_dtd(self, enabled: bool) -> Self
pub fn allow_internal_dtd(self, enabled: bool) -> Self
Allow bounded internal DTD declarations while keeping external entity resolution disabled. This is off by default.
Sourcepub fn allowed_transforms<I, S>(self, transforms: I) -> Self
pub fn allowed_transforms<I, S>(self, transforms: I) -> Self
Restrict allowed transform and canonicalization algorithms by URI.
Example values:
http://www.w3.org/2000/09/xmldsig#enveloped-signaturehttp://www.w3.org/2001/10/xml-exc-c14n#
The allowlist covers explicit Reference and RetrievalMethod transforms,
the declared SignedInfo canonicalization method, and implicit default
C14N (http://www.w3.org/TR/2001/REC-xml-c14n-20010315) when a Reference
transform chain ends as a node set.
Sourcepub fn store_pre_digest(self, enabled: bool) -> Self
pub fn store_pre_digest(self, enabled: bool) -> Self
Store pre-digest buffers for diagnostics.
Retained reference buffers and canonicalized <SignedInfo> share a
non-configurable 32 MiB safety ceiling. Canonicalized <SignedInfo> is
charged even when diagnostic retention is disabled because signature
verification always materializes it. Overflow remains a typed policy
violation at both low-level and end-to-end entry points.
Sourcepub fn xpath_here_semantics(self, semantics: XPathHereSemantics) -> Self
pub fn xpath_here_semantics(self, semantics: XPathHereSemantics) -> Self
Select the node returned by XPath’s here() extension function.
The default follows XMLDSig and returns the <XPath> parameter.
Use XPathHereSemantics::XmlSecLegacy only for documents known to
have been generated with libxmlsec1’s <Transform> interpretation.
Sourcepub fn verify(&self, xml: &str) -> Result<VerifyResult, DsigError>
pub fn verify(&self, xml: &str) -> Result<VerifyResult, DsigError>
Verify one XMLDSig signature using this context.
Returns Ok(VerifyResult) for both valid and invalid signatures; inspect
VerifyResult::status for the core <SignedInfo> and signature-value
outcome. When Manifest processing is enabled, inspect every
VerifyResult::manifest_references entry separately. Err(...) is
reserved for pipeline failures.
Sourcepub fn verify_document(
&self,
document: &XmlDocument,
) -> Result<VerifyResult, DsigError>
pub fn verify_document( &self, document: &XmlDocument, ) -> Result<VerifyResult, DsigError>
Verify a signature against a retained owned document generation.
The active XML input policy is revalidated against the document’s parse provenance as well as its current byte and node counts. In particular, a strict context rejects a document that required internal DTD support.