From f509e3083dd7870cce5880c804b5122317287581 Mon Sep 17 00:00:00 2001 From: Tim van Dijen Date: Mon, 27 Nov 2023 19:17:51 +0100 Subject: [PATCH] Merge pull request from GHSA-ww7x-3gxh-qm6r --- src/XML/SignedElementTrait.php | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/src/XML/SignedElementTrait.php b/src/XML/SignedElementTrait.php index 59e7b92a..c595a1e7 100644 --- a/src/XML/SignedElementTrait.php +++ b/src/XML/SignedElementTrait.php @@ -24,6 +24,7 @@ use SimpleSAML\XMLSecurity\Utils\XPath; use SimpleSAML\XMLSecurity\XML\ds\Reference; use SimpleSAML\XMLSecurity\XML\ds\Signature; +use SimpleSAML\XMLSecurity\XML\ds\SignedInfo; use SimpleSAML\XMLSecurity\XML\ds\X509Certificate; use SimpleSAML\XMLSecurity\XML\ds\X509Data; @@ -124,12 +125,11 @@ private function validateReferenceUri(Reference $reference, DOMElement $xml): vo /** + * @param \SimpleSAML\XMLSecurity\XML\ds\SignedInfo $signedInfo * @return \SimpleSAML\XMLSecurity\XML\SignedElementInterface */ - private function validateReference(): SignedElementInterface + private function validateReference(SignedInfo $signedInfo): SignedElementInterface { - /** @var \SimpleSAML\XMLSecurity\XML\ds\Signature $this->signature */ - $signedInfo = $this->signature->getSignedInfo(); $references = $signedInfo->getReferences(); Assert::count( $references, @@ -177,8 +177,12 @@ private function verifyInternal(SignatureAlgorithmInterface $verifier): SignedEl /** @var \SimpleSAML\XMLSecurity\XML\ds\Signature $this->signature */ $signedInfo = $this->signature->getSignedInfo(); $c14nAlg = $signedInfo->getCanonicalizationMethod()->getAlgorithm(); + + // the canonicalized ds:SignedInfo element (plaintext) $c14nSignedInfo = $signedInfo->canonicalize($c14nAlg); - $ref = $this->validateReference(); + $ref = $this->validateReference( + SignedInfo::fromXML(DOMDocumentFactory::fromString($c14nSignedInfo)->documentElement), + ); if ( $verifier?->verify(