AuthPortableSamlXmlDsigVerifier class final

Pure-Dart, application-selectable verifier for the bounded SAML XMLDSig profile documented by AuthSamlXmlDsigPolicy.

Trust comes only from the single certificate pinned on the selected AuthSamlConnection. An embedded KeyInfo/X509Certificate is optional, but when present it must byte-for-byte match that pin. Embedded keys never become trust roots.

Every signature must be an enveloped direct child of the exact Response or Assertion it references. References are local #ID values, use exactly the enveloped-signature and exclusive-C14N transforms, and cannot use XPath, XPointer, external resources, comments, implicit transforms, or an InclusiveNamespaces prefix list.

Implemented types

Constructors

AuthPortableSamlXmlDsigVerifier({AuthSamlXmlDsigPolicy? policy, AuthSamlLimits limits = const AuthSamlLimits()})
Creates a bounded pure-Dart XMLDSig verifier.

Properties

hashCode → int
The hash code for this object.
no setterinherited
limits → AuthSamlLimits
XML parsing limits used during verification.
final
policy → AuthSamlXmlDsigPolicy
XMLDSig algorithm policy used during verification.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited
verify(AuthSamlVerificationInput input) → AuthSamlSignatureProof
Verifies the signed response and returns its signature proof.
override

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

envelopedSignatureTransform → const String
Enveloped-signature transform supported by this verifier.
exclusiveCanonicalizationAlgorithm → const String
Exclusive XML canonicalization algorithm supported by this verifier.