HTTP message signatures (RFC 9421) the way UCP uses them.
sign/3 adds Content-Digest, Signature-Input and Signature headers to
a request. The signature base covers @method, @authority, @path,
@query when present, content-digest, content-type and any extra
headers named in :components, in that order, followed by the
@signature-params line with created and keyid. No alg parameter: the
algorithm follows from the key's type, as the spec requires.
A request is %{method: "POST", url: "https://...", headers: [{name, value}], body: binary}
with lowercase header names.
Summary
Functions
The Content-Digest value for a body.
Signs a request. Returns the request's headers plus content-digest,
signature-input and signature.
The signature base for a request, one covered component per line.
Verifies a signed request against a public key. Checks the digest against the body and the signature against the reconstructed base.
Functions
The Content-Digest value for a body.
Signs a request. Returns the request's headers plus content-digest,
signature-input and signature.
Options
:components- extra header names to cover aftercontent-type:created- unix seconds for thecreatedparameter, defaults to now
The signature base for a request, one covered component per line.
Verifies a signed request against a public key. Checks the digest against the body and the signature against the reconstructed base.