Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
sct.js159 linesDownload Raw Back to x509
1"use strict";
2var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
3    if (k2 === undefined) k2 = k;
4    var desc = Object.getOwnPropertyDescriptor(m, k);
5    if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
6      desc = { enumerable: true, get: function() { return m[k]; } };
7    }
8    Object.defineProperty(o, k2, desc);
9}) : (function(o, m, k, k2) {
10    if (k2 === undefined) k2 = k;
11    o[k2] = m[k];
12}));
13var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
14    Object.defineProperty(o, "default", { enumerable: true, value: v });
15}) : function(o, v) {
16    o["default"] = v;
17});
18var __importStar = (this && this.__importStar) || (function () {
19    var ownKeys = function(o) {
20        ownKeys = Object.getOwnPropertyNames || function (o) {
21            var ar = [];
22            for (var k in o) if (Object.prototype.hasOwnProperty.call(o, k)) ar[ar.length] = k;
23            return ar;
24        };
25        return ownKeys(o);
26    };
27    return function (mod) {
28        if (mod && mod.__esModule) return mod;
29        var result = {};
30        if (mod != null) for (var k = ownKeys(mod), i = 0; i < k.length; i++) if (k[i] !== "default") __createBinding(result, mod, k[i]);
31        __setModuleDefault(result, mod);
32        return result;
33    };
34})();
35Object.defineProperty(exports, "__esModule", { value: true });
36exports.SignedCertificateTimestamp = void 0;
37/*
38Copyright 2023 The Sigstore Authors.
39
40Licensed under the Apache License, Version 2.0 (the "License");
41you may not use this file except in compliance with the License.
42You may obtain a copy of the License at
43
44    http://www.apache.org/licenses/LICENSE-2.0
45
46Unless required by applicable law or agreed to in writing, software
47distributed under the License is distributed on an "AS IS" BASIS,
48WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
49See the License for the specific language governing permissions and
50limitations under the License.
51*/
52const crypto = __importStar(require("../crypto"));
53const stream_1 = require("../stream");
54class SignedCertificateTimestamp {
55    version;
56    logID;
57    timestamp;
58    extensions;
59    hashAlgorithm;
60    signatureAlgorithm;
61    signature;
62    constructor(options) {
63        this.version = options.version;
64        this.logID = options.logID;
65        this.timestamp = options.timestamp;
66        this.extensions = options.extensions;
67        this.hashAlgorithm = options.hashAlgorithm;
68        this.signatureAlgorithm = options.signatureAlgorithm;
69        this.signature = options.signature;
70    }
71    get datetime() {
72        return new Date(Number(this.timestamp.readBigInt64BE()));
73    }
74    // Returns the hash algorithm used to generate the SCT's signature.
75    // https://www.rfc-editor.org/rfc/rfc5246#section-7.4.1.4.1
76    get algorithm() {
77        switch (this.hashAlgorithm) {
78            /* istanbul ignore next */
79            case 0:
80                return 'none';
81            /* istanbul ignore next */
82            case 1:
83                return 'md5';
84            /* istanbul ignore next */
85            case 2:
86                return 'sha1';
87            /* istanbul ignore next */
88            case 3:
89                return 'sha224';
90            case 4:
91                return 'sha256';
92            /* istanbul ignore next */
93            case 5:
94                return 'sha384';
95            /* istanbul ignore next */
96            case 6:
97                return 'sha512';
98            /* istanbul ignore next */
99            default:
100                return 'unknown';
101        }
102    }
103    verify(preCert, key) {
104        // Assemble the digitally-signed struct (the data over which the signature
105        // was generated).
106        // https://www.rfc-editor.org/rfc/rfc6962#section-3.2
107        const stream = new stream_1.ByteStream();
108        stream.appendChar(this.version);
109        stream.appendChar(0x00); // SignatureType = certificate_timestamp(0)
110        stream.appendView(this.timestamp);
111        stream.appendUint16(0x01); // LogEntryType = precert_entry(1)
112        stream.appendView(preCert);
113        stream.appendUint16(this.extensions.byteLength);
114        /* istanbul ignore next - extensions are very uncommon */
115        if (this.extensions.byteLength > 0) {
116            stream.appendView(this.extensions);
117        }
118        return crypto.verify(stream.buffer, key, this.signature, this.algorithm);
119    }
120    // Parses a SignedCertificateTimestamp from a buffer. SCTs are encoded using
121    // TLS encoding which means the fields and lengths of most fields are
122    // specified as part of the SCT and TLS specs.
123    // https://www.rfc-editor.org/rfc/rfc6962#section-3.2
124    // https://www.rfc-editor.org/rfc/rfc5246#section-7.4.1.4.1
125    static parse(buf) {
126        const stream = new stream_1.ByteStream(buf);
127        // Version - enum { v1(0), (255) }
128        const version = stream.getUint8();
129        // Log ID  - struct { opaque key_id[32]; }
130        const logID = stream.getBlock(32);
131        // Timestamp - uint64
132        const timestamp = stream.getBlock(8);
133        // Extensions - opaque extensions<0..2^16-1>;
134        const extenstionLength = stream.getUint16();
135        const extensions = stream.getBlock(extenstionLength);
136        // Hash algo - enum { sha256(4), . . . (255) }
137        const hashAlgorithm = stream.getUint8();
138        // Signature algo - enum { anonymous(0), rsa(1), dsa(2), ecdsa(3), (255) }
139        const signatureAlgorithm = stream.getUint8();
140        // Signature  - opaque signature<0..2^16-1>;
141        const sigLength = stream.getUint16();
142        const signature = stream.getBlock(sigLength);
143        // Check that we read the entire buffer
144        if (stream.position !== buf.length) {
145            throw new Error('SCT buffer length mismatch');
146        }
147        return new SignedCertificateTimestamp({
148            version,
149            logID,
150            timestamp,
151            extensions,
152            hashAlgorithm,
153            signatureAlgorithm,
154            signature,
155        });
156    }
157}
158exports.SignedCertificateTimestamp = SignedCertificateTimestamp;
159 
codekingpro/portable-devtools · Team Ai