sha256withrsa_combined_verifier.go 1.3 KB

12345678910111213141516171819202122232425262728293031323334353637
  1. package verifiers
  2. import (
  3. "context"
  4. "crypto/rsa"
  5. "git.nanodreamtech.com/sg/wechatpay-go/core"
  6. )
  7. // SHA256WithRSACombinedVerifier 数字签名验证器,组合了公钥和平台证书
  8. type SHA256WithRSACombinedVerifier struct {
  9. publicKeyVerifier SHA256WithRSAPubkeyVerifier
  10. certVerifier SHA256WithRSAVerifier
  11. }
  12. // Verify 验证签名,如果序列号和公钥一致则使用公钥验签,否则使用平台证书验签
  13. func (v *SHA256WithRSACombinedVerifier) Verify(ctx context.Context, serialNumber, message, signature string) error {
  14. if serialNumber == v.publicKeyVerifier.keyID {
  15. return v.publicKeyVerifier.Verify(ctx, serialNumber, message, signature)
  16. }
  17. return v.certVerifier.Verify(ctx, serialNumber, message, signature)
  18. }
  19. // GetSerial 获取可验签的公钥序列号。该验签器只用在回调,所以获取序列号时返回错误
  20. func (v *SHA256WithRSACombinedVerifier) GetSerial(ctx context.Context) (string, error) {
  21. return v.publicKeyVerifier.keyID, nil
  22. }
  23. // NewSHA256WithRSACombinedVerifier 用公钥和平台证书初始化验证器
  24. func NewSHA256WithRSACombinedVerifier(
  25. getter core.CertificateGetter,
  26. keyID string,
  27. publicKey rsa.PublicKey) *SHA256WithRSACombinedVerifier {
  28. return &SHA256WithRSACombinedVerifier{
  29. *NewSHA256WithRSAPubkeyVerifier(keyID, publicKey),
  30. *NewSHA256WithRSAVerifier(getter),
  31. }
  32. }