-
Notifications
You must be signed in to change notification settings - Fork 9.4k
/
Copy pathJweEncryptionJwks.php
91 lines (81 loc) · 1.92 KB
/
JweEncryptionJwks.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
<?php
/**
* Copyright © Magento, Inc. All rights reserved.
* See COPYING.txt for license details.
*/
declare(strict_types=1);
namespace Magento\Framework\Jwt\Jwe;
use Magento\Framework\Jwt\Exception\EncryptionException;
use Magento\Framework\Jwt\Jwk;
use Magento\Framework\Jwt\JwkSet;
/**
* JWK encryption settings.
*/
class JweEncryptionJwks implements JweEncryptionSettingsInterface
{
/**
* @var JwkSet
*/
private $jwkSet;
/**
* @var string
*/
private $contentAlgo;
/**
* @param JwkSet|Jwk $jwk
* @param string $contentEncryptionAlgo
*/
public function __construct($jwk, string $contentEncryptionAlgo)
{
if ($jwk instanceof Jwk) {
$jwk = new JwkSet([$jwk]);
}
if (!$jwk instanceof JwkSet) {
throw new \InvalidArgumentException('JWK has to be provided');
}
$this->jwkSet = $jwk;
foreach ($this->jwkSet->getKeys() as $jwk) {
$this->validateJwk($jwk);
}
$this->contentAlgo = $contentEncryptionAlgo;
}
/**
* @inheritDoc
*/
public function getAlgorithmName(): string
{
if (count($this->jwkSet->getKeys()) > 1) {
return 'jwe-json-serialization';
} else {
return $this->jwkSet->getKeys()[0]->getAlgorithm();
}
}
/**
* @inheritDoc
*/
public function getContentEncryptionAlgorithm(): string
{
return $this->contentAlgo;
}
/**
* JWK Set.
*
* @return JwkSet
*/
public function getJwkSet(): JwkSet
{
return $this->jwkSet;
}
/**
* Validate JWK values.
*
* @param Jwk $jwk
* @return void
*/
private function validateJwk(Jwk $jwk): void
{
if ($jwk->getPublicKeyUse() === Jwk::PUBLIC_KEY_USE_SIGNATURE) {
throw new EncryptionException('JWK is not meant for JWEs');
}
}
}