Allow customization of algorithms and elements to sign#1
Open
martingalloar wants to merge 3 commits intoerny:masterfrom
Open
Allow customization of algorithms and elements to sign#1martingalloar wants to merge 3 commits intoerny:masterfrom
martingalloar wants to merge 3 commits intoerny:masterfrom
Conversation
Allow setting DigestMethod/Canonicalization Algorithms. Allow defining list of nodes to sign (XPath elements) and IDs to use on each one. Defaults to sign Body and Timestamp with autogenerated IDs. Changed all hard-coded strings to xmlsec.string constants.
The official PyXMLSec version 0.3.1 now contains the required patch for this to work, so now moved to that version on PyPi. Also using suds-jurko version.
Pass a number of transforms we want to add to the signedinfo element. Allows performing some basic DoS vulns checks.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Allow setting different algorithms for DigestMethod and Canonicalization, as well as defining a list of elements to sign. Defaults to only sign Body and Timestamp.