Split out of #409. In 6.3.3, #624 documents that each signature needs its own SignedXml. This issue is the change #409's reporter asked for: an error, instead of signatures that silently carry one more Reference each time. They only found out when responses grew large enough for their API gateway to reject them.
From #624's measurements on master:
| Usage |
Result |
one instance, addReference() before each of three documents |
1, 2 and 3 Reference elements |
| one verifier, three documents checked |
every check passes; getSignedReferences() returns 1, 2, then 3 entries, including the earlier documents' content |
To decide
- Throw from
addReference() when the instance already holds an equal reference, or
- make an instance single-use, and throw when
computeSignature() or checkSignature() is called a second time. That would also refuse signing several documents with the same references, which works correctly today.
The verifier row belongs in the same decision. getSignedReferences() is how the README tells callers to get the content a signature covers, and on a reused verifier it also returns content from documents checked earlier.
Why 7.0
Either option rejects calls that work today.
Split out of #409. In 6.3.3, #624 documents that each signature needs its own
SignedXml. This issue is the change #409's reporter asked for: an error, instead of signatures that silently carry one moreReferenceeach time. They only found out when responses grew large enough for their API gateway to reject them.From #624's measurements on
master:addReference()before each of three documentsReferenceelementsgetSignedReferences()returns 1, 2, then 3 entries, including the earlier documents' contentTo decide
addReference()when the instance already holds an equal reference, orcomputeSignature()orcheckSignature()is called a second time. That would also refuse signing several documents with the same references, which works correctly today.The verifier row belongs in the same decision.
getSignedReferences()is how the README tells callers to get the content a signature covers, and on a reused verifier it also returns content from documents checked earlier.Why 7.0
Either option rejects calls that work today.