asystec/firmador
Composer 安装命令:
composer require asystec/firmador
包简介
A PHP library for XML Security Hacienda
README 文档
README
#xmlseclibs
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures.
The author of xmlseclibs is Rob Richards.
Requirements
xmlseclibs requires PHP version 5.4 or greater. 5.6.24+ recommended for security reasons
How to Install
composer require "asystec/firmador"
Use cases
xmlseclibs is being used in many different software.
Basic usage
The example below shows basic usage of xmlseclibs, with a SHA-256 signature.
use JRTEC\XMLSecLibs_Hacienda\XMLSecurityDSig; use JRTEC\XMLSecLibs_Hacienda\XMLSecurityKey; class Firmador { const FROM_XML_STRING = 1; const FROM_XML_FILE = 2; const TO_BASE64_STRING = 3; const TO_XML_STRING = 4; const TO_XML_FILE = 5; public function firmarXml($pfx,$pin,$input,$output,$path=null){ // Cargar un nuevo XML para ser firmado $xml = new \DOMDocument(); // Detectar si es un archivo (ruta en disco) o bien un string xml if (file_exists($input)){ $input = file_get_contents($input); } // Intentar parsear el input como archivo xml. Caso contrario se detiene el script try { $xml->loadXML($input); } catch (\Exception $ex){ die($ex->getMessage()); } // Crear un nuevo objeto de seguridad $objSec = new XMLSecurityDSig(); // Mantener el primer nodo secundario original XML en memoria $objSec->xmlFirstChild = $xml->firstChild; // Establecer política de firma $objSec->setSignPolicy(); // Cargar la información del certificado desde el archivo *.p12 $certInfo = $objSec->loadCertInfo($pfx,$pin); // Usar la canonicalización exclusiva de c14n. $objSec->setCanonicalMethod($objSec::C14N); // Cargar la clave privada del certificado $objKey = new XMLSecurityKey(XMLSecurityKey::RSA_SHA256, array('type' => 'private')); $objKey->loadKey($certInfo["privateKey"]); // Agregar la clave pública asociada a la firma. $objSec->add509Cert($certInfo["publicKey"], true); $objSec->appendKeyValue($certInfo); // Insertar objeto Xades en la firma. $objSec->appendXades($certInfo); // Firmar utilizando SHA-256 // Referencia del documento $objSec->addReference($xml,$objSec::SHA256, [ 'http://www.w3.org/2000/09/xmldsig#enveloped-signature' ], [ 'id_ref' => $objSec->reference0Id, 'force_uri' => true ]); // Referencia de nodo de información clave $objSec->addReference($objSec->getKeyInfoNode(),$objSec::SHA256,null, [ 'id_ref' => $objSec->reference1Id, 'force_uri' => false, 'overwrite' => false ]); // Referencia del nodo Xades $objSec->addReference($objSec->getXadesNode(),$objSec::SHA256,null, [ 'force_uri' => false, 'overwrite' => false, "type" => "http://uri.etsi.org/01903#SignedProperties" ], [ [ 'qualifiedName' => 'xmlns:xades', 'value' => $objSec::XADES ] ]); // Firma el archivo xml $objSec->sign($objKey); // Adjuntar la firma al xml $objSec->appendSignature($xml->documentElement); if ($output == self::TO_BASE64_STRING){ // Devuelve el string del archivo xml firmado en formato Base64 return base64_encode($xml->saveXML()); } else if ($output == self::TO_XML_STRING){ // Devuelve el archivo xml firmado en formato string Xml return $xml->saveXML(); } else if ($output == self::TO_XML_FILE){ // Guarda el xml firmado en la ruta especificada y devuelve el resultado if (!is_null($path)) { return $xml->save($path); } else { return false; } } } }
asystec/firmador 适用场景与选型建议
asystec/firmador 是一款 基于 PHP 开发的 Composer 扩展包,目前已累计 489 次下载、GitHub Stars 达 0, 最近一次更新时间为 2022 年 01 月 28 日, 在 PHP 生态内属于活跃度较高的组件。
它主要适用于以下技术方向: 「xml」 「security」 「signature」 「xmldsig」 「hacienda CR」 等业务场景。在实际项目中,围绕这些方向常见需要落地的问题包括:接口对接、性能调优、并发安全、与既有框架(Laravel / ThinkPHP / Yii / Webman 等)的兼容适配,以及生产环境的日志埋点与稳定性保障。
我们在过去多个企业项目中使用过 asystec/firmador 或与其功能相近的方案,如果你在选型或落地过程中遇到问题,例如 版本兼容、二次改造、私有化封装、与内部系统对接、生产 BUG 排查,欢迎联系我们协助评估。
基于 asystec/firmador 在你已有业务上做功能扩展、字段裁剪、UI 适配、与内部账号 / 权限 / 日志系统的深度对接。
线上偶发问题、内存泄漏、慢查询、并发异常等排查修复;针对高流量场景做缓存、队列、索引层面的调优。
承接完整的项目从需求 → 设计 → 开发 → 上线 → 长期运维;也可按月提供技术保姆服务。
与 asystec/firmador 相关的其它包
同方向 / 同关键字的高下载量 PHP Composer 包推荐,方便对比选型:
Provide a way to secure accesses to all routes of an symfony application.
Load DOM document safety
接口签名验证
It's a barebone security class written on PHP
Digital signature Nova field.
Zoho Sign v1 API PHP Wrapper - PHP 7.4 Ready
统计信息
- 总下载量: 489
- 月度下载量: 0
- 日度下载量: 0
- 收藏数: 0
- 点击次数: 23
- 依赖项目数: 0
- 推荐数: 0
其他信息
- 授权协议: BSD-3-Clause
- 更新时间: 2022-01-28