1 | <?php |
||
22 | final class JWSBuilder |
||
23 | { |
||
24 | /** |
||
25 | * @var JsonConverterInterface |
||
26 | */ |
||
27 | private $jsonConverter; |
||
28 | |||
29 | /** |
||
30 | * @var string |
||
31 | */ |
||
32 | private $payload; |
||
33 | |||
34 | /** |
||
35 | * @var bool |
||
36 | */ |
||
37 | private $isPayloadDetached; |
||
38 | |||
39 | /** |
||
40 | * @var array |
||
41 | */ |
||
42 | private $signatures = []; |
||
43 | |||
44 | /** |
||
45 | * @var JWAManager |
||
46 | */ |
||
47 | private $signatureAlgorithmManager; |
||
48 | |||
49 | /** |
||
50 | * JWSBuilder constructor. |
||
51 | * |
||
52 | * @param JsonConverterInterface $jsonConverter |
||
53 | * @param JWAManager $signatureAlgorithmManager |
||
54 | */ |
||
55 | public function __construct(JsonConverterInterface $jsonConverter, JWAManager $signatureAlgorithmManager) |
||
60 | |||
61 | /** |
||
62 | * @return string[] |
||
63 | */ |
||
64 | public function getSupportedSignatureAlgorithms(): array |
||
68 | |||
69 | /** |
||
70 | * @param mixed $payload |
||
71 | * @param bool $isPayloadDetached |
||
72 | * |
||
73 | * @return JWSBuilder |
||
74 | */ |
||
75 | public function withPayload($payload, bool $isPayloadDetached = false): JWSBuilder |
||
87 | |||
88 | /** |
||
89 | * @param JWK $signatureKey |
||
90 | * @param array $protectedHeaders |
||
91 | * @param array $headers |
||
92 | * |
||
93 | * @return JWSBuilder |
||
94 | */ |
||
95 | public function addSignature(JWK $signatureKey, array $protectedHeaders, array $headers = []): JWSBuilder |
||
111 | |||
112 | /** |
||
113 | * @return JWS |
||
114 | */ |
||
115 | public function build(): JWS |
||
142 | |||
143 | /** |
||
144 | * @param array $protectedHeaders |
||
145 | * @param string $encodedProtectedHeaders |
||
146 | * |
||
147 | * @return string |
||
148 | */ |
||
149 | private function getInputToSign(array $protectedHeaders, ?string $encodedProtectedHeaders): string |
||
150 | { |
||
151 | $this->checkB64AndCriticalHeader($protectedHeaders); |
||
152 | if (!array_key_exists('b64', $protectedHeaders) || (array_key_exists('b64', $protectedHeaders) && true === $protectedHeaders['b64'])) { |
||
153 | $encodedPayload = Base64Url::encode($this->payload); |
||
154 | |||
155 | return sprintf('%s.%s', $encodedProtectedHeaders, $encodedPayload); |
||
156 | } |
||
157 | |||
158 | return sprintf('%s.%s', $encodedProtectedHeaders, $this->payload); |
||
159 | } |
||
160 | |||
161 | /** |
||
162 | * @param array $protectedHeaders |
||
163 | */ |
||
164 | private function checkB64AndCriticalHeader(array $protectedHeaders) |
||
179 | |||
180 | /** |
||
181 | * @param array $protectedHeader |
||
182 | * @param array $headers |
||
183 | * @param JWK $key |
||
184 | * |
||
185 | * @return SignatureAlgorithmInterface |
||
186 | */ |
||
187 | private function findSignatureAlgorithm(JWK $key, array $protectedHeader, array $headers): SignatureAlgorithmInterface |
||
204 | |||
205 | /** |
||
206 | * @param array ...$headers |
||
207 | */ |
||
208 | private function checkDuplicatedHeaderParameters(...$headers) |
||
215 | } |
||
216 |