PluginProbe
Gianism / 1.1
Gianism v1.1
4.3.0 4.3.1 4.3.2 4.3.3 4.3.4 4.4.0 5.0.0 5.0.1 5.0.2 5.1.0 5.2.1 5.2.2 5.3.0 6.0.0 6.0.1 trunk 1.0 1.1 1.1.1 1.1.2 1.1.3 1.1.4 1.1.5 1.1.6 1.1.7 All 65 releases
gianism / sdks / google / auth / apiPemVerifier.php

apiPemVerifier.php in Gianism 1.1, at sdks/google/auth/apiPemVerifier.php

62 lines 1.7 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2 /*
3 * Copyright 2011 Google Inc.
4 *
5 * Licensed under the Apache License, Version 2.0 (the "License");
6 * you may not use this file except in compliance with the License.
7 * You may obtain a copy of the License at
8 *
9 * http://www.apache.org/licenses/LICENSE-2.0
10 *
11 * Unless required by applicable law or agreed to in writing, software
12 * distributed under the License is distributed on an "AS IS" BASIS,
13 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14 * See the License for the specific language governing permissions and
15 * limitations under the License.
16 */
17
18 /**
19 * Verifies signatures using PEM encoded certificates.
20 *
21 * @author Brian Eaton <beaton@google.com>
22 */
23 class apiPemVerifier extends apiVerifier {
24 private $publicKey;
25
26 /**
27 * Constructs a verifier from the supplied PEM-encoded certificate.
28 *
29 * $pem: a PEM encoded certificate (not a file).
30 */
31 function __construct($pem) {
32 if (!function_exists('openssl_x509_read')) {
33 throw new Exception(
34 'The Google PHP API library needs the openssl PHP extension');
35 }
36 $this->publicKey = openssl_x509_read($pem);
37 if (!$this->publicKey) {
38 throw new apiAuthException("Unable to parse PEM: $pem");
39 }
40 }
41
42 function __destruct() {
43 if ($this->publicKey) {
44 openssl_x509_free($this->publicKey);
45 }
46 }
47
48 /**
49 * Verifies the signature on data.
50 *
51 * Returns true if the signature is valid, false otherwise.
52 */
53 function verify($data, $signature) {
54 $status = openssl_verify($data, $signature, $this->publicKey, "sha256");
55 if ($status === -1) {
56 throw new apiAuthException("Signature verification error: " .
57 openssl_error_string());
58 }
59 return $status === 1;
60 }
61 }
62