Table of contents
Namespace: Com\Tecnick\Pdf\Sign\Cms
final class SigningRequest
Source: src/Cms/SigningRequest.php:47
Validated, immutable record of everything the CMS signed attributes are derived from. It is what crosses the boundary of a two-phase signature: Builder::signaturePayload() turns it into the bytes a signer has to sign, and Builder::buildFromSignature() rebuilds the same attributes from it once the signature comes back.
Every invariant is enforced by the constructor, and toArray()/fromArray() round-trip through it, so a request rehydrated from a session, a queue, or a second HTTP request is validated again. Validation is not authentication: pass a key to that pair, or protect the channel, to catch a request edited into a different valid one.
Constants
MAX_SIGNING_TIME
Latest signing time a DER Time value can carry: 9999-12-31T23:59:59Z.
public const MAX_SIGNING_TIME = 253402300799
Source: src/Cms/SigningRequest.php:52
Properties
$digestAlgorithm
Selected CMS digest algorithm (one of the DigestAlgorithm backing values).
public string $digestAlgorithm
Source: src/Cms/SigningRequest.php:57
$extraSignedAttributes
Additional signed attributes, keyed by attribute type OID.
public array<string,string> $extraSignedAttributes
Source: src/Cms/SigningRequest.php:64
$includeSigningTime
public $includeSigningTime = true
Source: src/Cms/SigningRequest.php:88
$messageDigest
public $messageDigest
Source: src/Cms/SigningRequest.php:84
$signerCertDer
public $signerCertDer
Source: src/Cms/SigningRequest.php:85
$signingTime
public $signingTime = 0
Source: src/Cms/SigningRequest.php:87
Methods
__construct()
public __construct(
string $messageDigest,
string $signerCertDer,
string|DigestAlgorithm $digestAlgorithm = 'sha256',
int $signingTime = 0,
bool $includeSigningTime = true,
array<array-key,string> $extraSignedAttributes = []
)
Parameters:
$messageDigest(string): Digest of the detached content, raw bytes, computed with $digestAlgorithm. A caller that cannot hold the content in memory computes it with hash_update_stream().$signerCertDer(string): DER of the signing certificate.$digestAlgorithm(string|DigestAlgorithm): Digest algorithm name or enum case.$signingTime(int): Unix timestamp for the signing-time attribute.$includeSigningTime(bool): Whether to add the CMS signing-time signed attribute. The legacy (ISO 32000-1) profile includes it; PAdES-BASELINE forbids it (ETSI EN 319 142-1).$extraSignedAttributes(array<array-key,string>): Additional signed attributes as OID => DER-encoded attribute value, for a profile that requires one such as the CAdES signature-policy-identifier.
Throws:
- Exception: If the digest, the certificate, the signing time, or an extra attribute is invalid.
Source: src/Cms/SigningRequest.php:83
fromArray()
Rebuild a request from the array produced by toArray().
The full constructor runs again, so a payload that is not a valid request is rejected. Pass the $key given to toArray() and the MAC is verified first, which rejects a payload edited into a different valid request.
public static fromArray(array<array-key,mixed> $state, string|null $key = null): self
Parameters:
$state(array<array-key,mixed>): Exported state.$key(string|null): The secret passed to toArray(), or null when the state was exported unprotected.
Returns: self
Throws:
- Exception: If the MAC is missing or wrong, or a field is missing, malformed, or fails validation.
Source: src/Cms/SigningRequest.php:200
signerCertPem()
The signing certificate wrapped as PEM, which is what the OpenSSL functions read.
public signerCertPem(): string
Returns: string
Source: src/Cms/SigningRequest.php:136
toArray()
Export the request as a JSON-safe array, with the binary fields base64-encoded.
Pass $key to add a keyed MAC over the exported fields. Without one the export carries no integrity protection: the constructor re-runs on the way back in, so a malformed payload is rejected, but a payload edited into another well-formed one is not.
public toArray(string|null $key = null): array{message_digest: string, signer_cert: string, digest_algorithm: string, signing_time: int, include_signing_time: bool, extra_signed_attributes: array<string,string>, mac?: string}
Parameters:
$key(string|null): Secret for the HMAC-SHA256, or null to export unprotected.
Returns: array{message_digest: string, signer_cert: string, digest_algorithm: string, signing_time: int, include_signing_time: bool, extra_signed_attributes: array<string,string>, mac?: string}
Throws:
- Exception: If the key is empty.
Source: src/Cms/SigningRequest.php:163