Split out of #573, which keeps the implicitTransforms and idAttribute tests for 6.3.3. #599 has already fixed the test that passed on the wrong error, and it covered signatureAlgorithm is required and digestAlgorithm is required.
On master at c13e30b, 53 of the 592 statements in src/signed-xml.ts are uncovered (9.0%). 22 of those are throw sites:
| Where |
Uncovered throws |
getCanonSignedInfoXml |
No signature found., Missing canonicalizationAlgorithm…, could not find SignedInfo…, the multiple-signatures guard, the non-exclusive whole-DOM guard |
checkSignature |
Canonical signed info cannot be empty, Could not parse unverifiedSignedInfoCanon…, could not find any Reference elements |
addReference |
transforms must contain at least one transform algorithm, and getValidatedNode() called before checkSignature() |
computeSignature |
the two location.reference root-node guards (#583) |
createSignedInfo |
Missing canonicalizationAlgorithm when trying to create signed info for XML |
calculateSignatureValue |
Private key is required to compute signature |
findCanonicalizationAlgorithm |
canonicalization algorithm … is not supported (#576 covers it) |
validateElementAgainstReferences |
No references passed validation |
loadReference |
could not find the value of DigestValue… |
namespaceResolver |
Not implemented |
| callback forms |
Last parameter must be a callback function, and three throw err rethrows in computeSignature() |
#571 replaces the callback forms, so measure again once it lands. Then, for each remaining site, follow AGENTS.md: add a test through the public API if a caller can reach the site, and remove the code if nothing can. This is best done a few sites at a time rather than in one sweep.
Split out of #573, which keeps the
implicitTransformsandidAttributetests for 6.3.3. #599 has already fixed the test that passed on the wrong error, and it coveredsignatureAlgorithm is requiredanddigestAlgorithm is required.On
masterat c13e30b, 53 of the 592 statements insrc/signed-xml.tsare uncovered (9.0%). 22 of those arethrowsites:getCanonSignedInfoXmlNo signature found.,Missing canonicalizationAlgorithm…,could not find SignedInfo…, the multiple-signatures guard, the non-exclusive whole-DOM guardcheckSignatureCanonical signed info cannot be empty,Could not parse unverifiedSignedInfoCanon…,could not find any Reference elementsaddReferencetransforms must contain at least one transform algorithm, andgetValidatedNode()called beforecheckSignature()computeSignaturelocation.referenceroot-node guards (#583)createSignedInfoMissing canonicalizationAlgorithm when trying to create signed info for XMLcalculateSignatureValuePrivate key is required to compute signaturefindCanonicalizationAlgorithmcanonicalization algorithm … is not supported(#576 covers it)validateElementAgainstReferencesNo references passed validationloadReferencecould not find the value of DigestValue…namespaceResolverNot implementedLast parameter must be a callback function, and threethrow errrethrows incomputeSignature()#571 replaces the callback forms, so measure again once it lands. Then, for each remaining site, follow AGENTS.md: add a test through the public API if a caller can reach the site, and remove the code if nothing can. This is best done a few sites at a time rather than in one sweep.