ServiceAccountSignerTrait.php 1.8 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556
  1. <?php
  2. /*
  3. * Copyright 2019 Google LLC
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. */
  17. namespace Google\Auth;
  18. use phpseclib3\Crypt\PublicKeyLoader;
  19. use phpseclib3\Crypt\RSA;
  20. /**
  21. * Sign a string using a Service Account private key.
  22. */
  23. trait ServiceAccountSignerTrait
  24. {
  25. /**
  26. * Sign a string using the service account private key.
  27. *
  28. * @param string $stringToSign
  29. * @param bool $forceOpenssl Whether to use OpenSSL regardless of
  30. * whether phpseclib is installed. **Defaults to** `false`.
  31. * @return string
  32. */
  33. public function signBlob($stringToSign, $forceOpenssl = false)
  34. {
  35. $privateKey = $this->auth->getSigningKey();
  36. $signedString = '';
  37. if (class_exists(phpseclib3\Crypt\RSA::class) && !$forceOpenssl) {
  38. $key = PublicKeyLoader::load($privateKey);
  39. $rsa = $key->withHash('sha256')->withPadding(RSA::SIGNATURE_PKCS1);
  40. $signedString = $rsa->sign($stringToSign);
  41. } elseif (extension_loaded('openssl')) {
  42. openssl_sign($stringToSign, $signedString, $privateKey, 'sha256WithRSAEncryption');
  43. } else {
  44. // @codeCoverageIgnoreStart
  45. throw new \RuntimeException('OpenSSL is not installed.');
  46. }
  47. // @codeCoverageIgnoreEnd
  48. return base64_encode($signedString);
  49. }
  50. }