codekingpro/portable-devtools
114k
1"use strict";
2var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
3 if (k2 === undefined) k2 = k;
4 var desc = Object.getOwnPropertyDescriptor(m, k);
5 if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
6 desc = { enumerable: true, get: function() { return m[k]; } };
7 }
8 Object.defineProperty(o, k2, desc);
9}) : (function(o, m, k, k2) {
10 if (k2 === undefined) k2 = k;
11 o[k2] = m[k];
12}));
13var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
14 Object.defineProperty(o, "default", { enumerable: true, value: v });
15}) : function(o, v) {
16 o["default"] = v;
17});
18var __importStar = (this && this.__importStar) || (function () {
19 var ownKeys = function(o) {
20 ownKeys = Object.getOwnPropertyNames || function (o) {
21 var ar = [];
22 for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
23 return ar;
24 };
25 return ownKeys(o);
26 };
27 return function (mod) {
28 if (mod && mod.__esModule) return mod;
29 var result = {};
30 if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
31 __setModuleDefault(result, mod);
32 return result;
33 };
34})();
35Object.defineProperty(exports, "__esModule", { value: true });
36exports.sign = sign;
37exports.attest = attest;
38exports.verify = verify;
39exports.createVerifier = createVerifier;
40/*
41Copyright 2023 The Sigstore Authors.
42
43Licensed under the Apache License, Version 2.0 (the "License");
44you may not use this file except in compliance with the License.
45You may obtain a copy of the License at
46
47 http://www.apache.org/licenses/LICENSE-2.0
48
49Unless required by applicable law or agreed to in writing, software
50distributed under the License is distributed on an "AS IS" BASIS,
51WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
52See the License for the specific language governing permissions and
53limitations under the License.
54*/
55const bundle_1 = require("@sigstore/bundle");
56const tuf = __importStar(require("@sigstore/tuf"));
57const verify_1 = require("@sigstore/verify");
58const config = __importStar(require("./config"));
59async function sign(payload,
60/* istanbul ignore next */
61options = {}) {
62 const bundler = config.createBundleBuilder('messageSignature', options);
63 const bundle = await bundler.create({ data: payload });
64 return (0, bundle_1.bundleToJSON)(bundle);
65}
66async function attest(payload, payloadType,
67/* istanbul ignore next */
68options = {}) {
69 const bundler = config.createBundleBuilder('dsseEnvelope', options);
70 const bundle = await bundler.create({ data: payload, type: payloadType });
71 return (0, bundle_1.bundleToJSON)(bundle);
72}
73async function verify(bundle, dataOrOptions, options) {
74 let data;
75 if (Buffer.isBuffer(dataOrOptions)) {
76 data = dataOrOptions;
77 }
78 else {
79 options = dataOrOptions;
80 }
81 const verifier = await createVerifier(options);
82 return verifier.verify(bundle, data);
83}
84async function createVerifier(
85/* istanbul ignore next */
86options = {}) {
87 const trustedRoot = await tuf.getTrustedRoot({
88 mirrorURL: options.tufMirrorURL,
89 rootPath: options.tufRootPath,
90 cachePath: options.tufCachePath,
91 forceCache: options.tufForceCache,
92 retry: options.retry ?? config.DEFAULT_RETRY,
93 timeout: options.timeout ?? config.DEFAULT_TIMEOUT,
94 });
95 const keyFinder = options.keySelector
96 ? config.createKeyFinder(options.keySelector)
97 : undefined;
98 const trustMaterial = (0, verify_1.toTrustMaterial)(trustedRoot, keyFinder);
99 const verifierOptions = {
100 ctlogThreshold: options.ctLogThreshold,
101 tlogThreshold: options.tlogThreshold,
102 };
103 const verifier = new verify_1.Verifier(trustMaterial, verifierOptions);
104 const policy = config.createVerificationPolicy(options);
105 return {
106 verify: (bundle, payload) => {
107 const deserializedBundle = (0, bundle_1.bundleFromJSON)(bundle);
108 const signedEntity = (0, verify_1.toSignedEntity)(deserializedBundle, payload);
109 return verifier.verify(signedEntity, policy);
110 },
111 };
112}
113 