Support for HTTP Signatures
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 6
- Forks
- 3
- Avg merge
- 1h 54m
- Merged PRs (30d)
- 1
Description
Support for the HTTP Message Signatures draft specification would require the specification of the algorithms, key types, and required covered content for a signature. The following examples show what a possible syntax could look like for the new OAS security model proposed in OAI/OpenAPI-Specification#2582.
This example shows how it could be defined for an example API requiring signed requests with an RSA PSS signature and the caller's key identifier and a set of required components on the request including the method, url, and several headers.
components:
securitySchemes:
photoApi:
type: httpsig
credentials:
- in: header
name: signature-input
- in: header
name: signature
config:
- alg: rsa-pss-sha512
keyid: <your key id here>
coveredComponents:
- @method
- content-digest
- content-type
- target-uri
requiredParameters:
- nonce
- created
As I'm not sure how to show placeholder values, I'm using things like <your key id> here.
As a corrollary, it would be useful to specify the algorithm and use of digest headers like Content-Digest, which protects the body, and Client-Cert, which contains the TLS client certificate.
This proposed syntax is just one possible idea, and I'm looking for feedback on how this could be made to fit the OAS model better.
Addresses #6
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the linked HTTP Message Signatures draft and OAI/OpenAPI-Specification#2582, then compare the proposed security-scheme syntax with the OAS model. No files or tests are named; done would require an agreed approach for algorithms, key types, covered content, digest headers, and placeholder values.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100