Bazaar.Signing.HttpSignature (Bazaar v0.3.0)

Copy Markdown View Source

HTTP message signatures (RFC 9421) the way UCP uses them.

sign/3 adds Content-Digest, Signature-Input and Signature headers to a request. The signature base covers @method, @authority, @path, @query when present, content-digest, content-type and any extra headers named in :components, in that order, followed by the @signature-params line with created and keyid. No alg parameter: the algorithm follows from the key's type, as the spec requires.

A request is %{method: "POST", url: "https://...", headers: [{name, value}], body: binary} with lowercase header names.

Summary

Functions

The Content-Digest value for a body.

Signs a request. Returns the request's headers plus content-digest, signature-input and signature.

The signature base for a request, one covered component per line.

Verifies a signed request against a public key. Checks the digest against the body and the signature against the reconstructed base.

Functions

content_digest(body)

The Content-Digest value for a body.

sign(request, key, opts \\ [])

Signs a request. Returns the request's headers plus content-digest, signature-input and signature.

Options

  • :components - extra header names to cover after content-type
  • :created - unix seconds for the created parameter, defaults to now

signature_base(request, components, params)

The signature base for a request, one covered component per line.

verify(request, key)

Verifies a signed request against a public key. Checks the digest against the body and the signature against the reconstructed base.