Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -388,6 +388,13 @@ To verify xml documents:
- `getSignedReferences()` - returns the canonical XML of each reference, only after `checkSignature` succeeds
- `validateElementAgainstReferences(elemOrXpath, doc)` - **[deprecated]** after `checkSignature` succeeds, use the XML that `getSignedReferences()` returns instead of nodes from the original document

#### One instance per signature

Create a new `SignedXml` for each signature you create or verify, including each signature in a document that has more than one. An instance keeps state between calls:

- `computeSignature()` signs every reference the instance holds. `addReference()` adds one, so calling it for each signature on a reused instance adds one more `Reference` to every new signature. `checkSignature()` replaces them with the references of the signature it checks.
- `getSignedReferences()` returns the references of each successful `checkSignature()` call since the last failed one, which empties it. On a reused instance, that can include content that earlier signatures cover.

Comment thread
coderabbitai[bot] marked this conversation as resolved.
## Customizing Algorithms

The following sample shows how to sign a message using custom algorithms.
Expand Down
Loading