1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75
|
// Copyright 2024 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.
#include "components/web_package/signed_web_bundles/identity_validator.h"
#include <algorithm>
#include <variant>
#include "base/no_destructor.h"
#include "base/strings/stringprintf.h"
#include "components/web_package/signed_web_bundles/ecdsa_p256_public_key.h"
#include "components/web_package/signed_web_bundles/ed25519_public_key.h"
#include "components/web_package/signed_web_bundles/signed_web_bundle_id.h"
namespace web_package {
namespace {
IdentityValidator* g_instance = nullptr;
} // namespace
IdentityValidator::IdentityValidator() {
CHECK(!g_instance);
g_instance = this;
}
IdentityValidator::~IdentityValidator() {
CHECK(g_instance);
g_instance = nullptr;
}
void IdentityValidator::CreateInstanceForTesting() {
static base::NoDestructor<IdentityValidator> instance;
instance.get();
}
// static
IdentityValidator* IdentityValidator::GetInstance() {
CHECK(g_instance)
<< "IdentityValidator must be initialized by the time of "
"the call to GetInstance(). Normally this happens in the //chrome "
"layer via IwaIdentityValidator, although not in the case of unit "
"tests -- there you need to explicitly call "
"IwaIdentityValidator::CreateSingleton() in the setup phase.";
return g_instance;
}
base::expected<void, std::string> IdentityValidator::ValidateWebBundleIdentity(
const std::string& web_bundle_id,
const std::vector<PublicKey>& public_keys) const {
if (!std::ranges::any_of(public_keys, [&](const auto& public_key) {
return std::visit(
[&](const auto& public_key) {
return SignedWebBundleId::CreateForPublicKey(public_key).id() ==
web_bundle_id;
},
public_key);
})) {
return base::unexpected(base::StringPrintf(
"Web Bundle ID <%s> doesn't match any public key in the signature "
"list.",
web_bundle_id.c_str()));
}
return base::ok();
}
base::expected<void, std::string> IdentityValidator::ValidateWebBundleIdentity(
const SignedWebBundleIntegrityBlock& integrity_block) const {
return ValidateWebBundleIdentity(
integrity_block.web_bundle_id().id(),
integrity_block.signature_stack().public_keys());
}
} // namespace web_package
|