validate_crit.js 1.5 KB

12345678910111213141516171819202122232425262728293031323334
  1. import { JOSENotSupported } from '../util/errors.js';
  2. function validateCrit(Err, recognizedDefault, recognizedOption, protectedHeader, joseHeader) {
  3. if (joseHeader.crit !== undefined && protectedHeader.crit === undefined) {
  4. throw new Err('"crit" (Critical) Header Parameter MUST be integrity protected');
  5. }
  6. if (!protectedHeader || protectedHeader.crit === undefined) {
  7. return new Set();
  8. }
  9. if (!Array.isArray(protectedHeader.crit) ||
  10. protectedHeader.crit.length === 0 ||
  11. protectedHeader.crit.some((input) => typeof input !== 'string' || input.length === 0)) {
  12. throw new Err('"crit" (Critical) Header Parameter MUST be an array of non-empty strings when present');
  13. }
  14. let recognized;
  15. if (recognizedOption !== undefined) {
  16. recognized = new Map([...Object.entries(recognizedOption), ...recognizedDefault.entries()]);
  17. }
  18. else {
  19. recognized = recognizedDefault;
  20. }
  21. for (const parameter of protectedHeader.crit) {
  22. if (!recognized.has(parameter)) {
  23. throw new JOSENotSupported(`Extension Header Parameter "${parameter}" is not recognized`);
  24. }
  25. if (joseHeader[parameter] === undefined) {
  26. throw new Err(`Extension Header Parameter "${parameter}" is missing`);
  27. }
  28. else if (recognized.get(parameter) && protectedHeader[parameter] === undefined) {
  29. throw new Err(`Extension Header Parameter "${parameter}" MUST be integrity protected`);
  30. }
  31. }
  32. return new Set(protectedHeader.crit);
  33. }
  34. export default validateCrit;