codekingpro/portable-devtools
114k
1"use strict";
2var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
3 if (k2 === undefined) k2 = k;
4 var desc = Object.getOwnPropertyDescriptor(m, k);
5 if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
6 desc = { enumerable: true, get: function() { return m[k]; } };
7 }
8 Object.defineProperty(o, k2, desc);
9}) : (function(o, m, k, k2) {
10 if (k2 === undefined) k2 = k;
11 o[k2] = m[k];
12}));
13var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
14 Object.defineProperty(o, "default", { enumerable: true, value: v });
15}) : function(o, v) {
16 o["default"] = v;
17});
18var __importStar = (this && this.__importStar) || (function () {
19 var ownKeys = function(o) {
20 ownKeys = Object.getOwnPropertyNames || function (o) {
21 var ar = [];
22 for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
23 return ar;
24 };
25 return ownKeys(o);
26 };
27 return function (mod) {
28 if (mod && mod.__esModule) return mod;
29 var result = {};
30 if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
31 __setModuleDefault(result, mod);
32 return result;
33 };
34})();
35Object.defineProperty(exports, "__esModule", { value: true });
36exports.SignedCertificateTimestamp = void 0;
37/*
38Copyright 2023 The Sigstore Authors.
39
40Licensed under the Apache License, Version 2.0 (the "License");
41you may not use this file except in compliance with the License.
42You may obtain a copy of the License at
43
44 http://www.apache.org/licenses/LICENSE-2.0
45
46Unless required by applicable law or agreed to in writing, software
47distributed under the License is distributed on an "AS IS" BASIS,
48WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
49See the License for the specific language governing permissions and
50limitations under the License.
51*/
52const crypto = __importStar(require("../crypto"));
53const stream_1 = require("../stream");
54class SignedCertificateTimestamp {
55 version;
56 logID;
57 timestamp;
58 extensions;
59 hashAlgorithm;
60 signatureAlgorithm;
61 signature;
62 constructor(options) {
63 this.version = options.version;
64 this.logID = options.logID;
65 this.timestamp = options.timestamp;
66 this.extensions = options.extensions;
67 this.hashAlgorithm = options.hashAlgorithm;
68 this.signatureAlgorithm = options.signatureAlgorithm;
69 this.signature = options.signature;
70 }
71 get datetime() {
72 return new Date(Number(this.timestamp.readBigInt64BE()));
73 }
74 // Returns the hash algorithm used to generate the SCT's signature.
75 // https://www.rfc-editor.org/rfc/rfc5246#section-7.4.1.4.1
76 get algorithm() {
77 switch (this.hashAlgorithm) {
78 /* istanbul ignore next */
79 case 0:
80 return 'none';
81 /* istanbul ignore next */
82 case 1:
83 return 'md5';
84 /* istanbul ignore next */
85 case 2:
86 return 'sha1';
87 /* istanbul ignore next */
88 case 3:
89 return 'sha224';
90 case 4:
91 return 'sha256';
92 /* istanbul ignore next */
93 case 5:
94 return 'sha384';
95 /* istanbul ignore next */
96 case 6:
97 return 'sha512';
98 /* istanbul ignore next */
99 default:
100 return 'unknown';
101 }
102 }
103 verify(preCert, key) {
104 // Assemble the digitally-signed struct (the data over which the signature
105 // was generated).
106 // https://www.rfc-editor.org/rfc/rfc6962#section-3.2
107 const stream = new stream_1.ByteStream();
108 stream.appendChar(this.version);
109 stream.appendChar(0x00); // SignatureType = certificate_timestamp(0)
110 stream.appendView(this.timestamp);
111 stream.appendUint16(0x01); // LogEntryType = precert_entry(1)
112 stream.appendView(preCert);
113 stream.appendUint16(this.extensions.byteLength);
114 /* istanbul ignore next - extensions are very uncommon */
115 if (this.extensions.byteLength > 0) {
116 stream.appendView(this.extensions);
117 }
118 return crypto.verify(stream.buffer, key, this.signature, this.algorithm);
119 }
120 // Parses a SignedCertificateTimestamp from a buffer. SCTs are encoded using
121 // TLS encoding which means the fields and lengths of most fields are
122 // specified as part of the SCT and TLS specs.
123 // https://www.rfc-editor.org/rfc/rfc6962#section-3.2
124 // https://www.rfc-editor.org/rfc/rfc5246#section-7.4.1.4.1
125 static parse(buf) {
126 const stream = new stream_1.ByteStream(buf);
127 // Version - enum { v1(0), (255) }
128 const version = stream.getUint8();
129 // Log ID - struct { opaque key_id[32]; }
130 const logID = stream.getBlock(32);
131 // Timestamp - uint64
132 const timestamp = stream.getBlock(8);
133 // Extensions - opaque extensions<0..2^16-1>;
134 const extenstionLength = stream.getUint16();
135 const extensions = stream.getBlock(extenstionLength);
136 // Hash algo - enum { sha256(4), . . . (255) }
137 const hashAlgorithm = stream.getUint8();
138 // Signature algo - enum { anonymous(0), rsa(1), dsa(2), ecdsa(3), (255) }
139 const signatureAlgorithm = stream.getUint8();
140 // Signature - opaque signature<0..2^16-1>;
141 const sigLength = stream.getUint16();
142 const signature = stream.getBlock(sigLength);
143 // Check that we read the entire buffer
144 if (stream.position !== buf.length) {
145 throw new Error('SCT buffer length mismatch');
146 }
147 return new SignedCertificateTimestamp({
148 version,
149 logID,
150 timestamp,
151 extensions,
152 hashAlgorithm,
153 signatureAlgorithm,
154 signature,
155 });
156 }
157}
158exports.SignedCertificateTimestamp = SignedCertificateTimestamp;
159 