Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 0 additions & 71 deletions .github/scripts/check-support-crate-versions.sh

This file was deleted.

48 changes: 0 additions & 48 deletions .github/scripts/test-check-support-crate-versions.sh

This file was deleted.

14 changes: 0 additions & 14 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,20 +16,6 @@ env:
LD_LIBRARY_PATH: ${{ github.workspace }}/.tools/xmlsec1-1.3.13/lib

jobs:
support-crate-versions:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
persist-credentials: false
- name: Verify support-crate version gate
run: bash .github/scripts/test-check-support-crate-versions.sh
- name: Require version bumps for changed support crates
env:
BASE_SHA: ${{ github.event.pull_request.base.sha || github.event.before }}
run: bash .github/scripts/check-support-crate-versions.sh "$BASE_SHA"

capability-ledger:
runs-on: ubuntu-latest
steps:
Expand Down
21 changes: 0 additions & 21 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,29 +17,8 @@ jobs:
with:
fetch-depth: 0
- uses: dtolnay/rust-toolchain@stable
- name: Check support-crate versions against the prior release
run: |
previous="$(git describe --tags --match 'v*' --abbrev=0 HEAD^)"
bash .github/scripts/check-support-crate-versions.sh "$previous"
- uses: rust-lang/crates-io-auth-action@v1
id: auth
# Workspace path dependencies must exist in the registry before their consumers.
- name: Publish document support crate to crates.io
run: bash .github/scripts/publish-crate.sh xml-sec-sxd-document
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- name: Publish XPath support crate to crates.io
run: bash .github/scripts/publish-crate.sh xml-sec-sxd-xpath
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- name: Publish XML input crate to crates.io
run: bash .github/scripts/publish-crate.sh xml-sec-xml-input
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- name: Publish XSLT crate to crates.io
run: bash .github/scripts/publish-crate.sh xml-sec-xslt
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- name: Publish xml-sec to crates.io
run: bash .github/scripts/publish-crate.sh xml-sec
env:
Expand Down
4 changes: 4 additions & 0 deletions .release-plz.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
[workspace]
release = false
semver_check = false
# Unlike the single-crate coordinode workspace, older tags lack current internal members.
# git_only reconstructs those tags and fails before it can select the release package.
git_release_enable = false
git_tag_enable = false
changelog_update = true
Expand All @@ -10,6 +13,7 @@ release_commits = "^(feat|fix|perf|refactor|docs)(\\([^)]+\\))?!?:"

[[package]]
name = "xml-sec"
release = true
git_release_enable = true
git_tag_enable = true
git_tag_name = "v{{ version }}"
Expand Down
40 changes: 33 additions & 7 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -3,14 +3,29 @@ name = "xml-sec"
version = "0.1.16"
edition = "2024"
rust-version = "1.92"
license = "Apache-2.0"
license = "Apache-2.0 AND MIT"
description = "Pure Rust XML Security: XMLDSig, XMLEnc, C14N. Drop-in replacement for libxmlsec1."
repository = "https://github.com/structured-world/xml-sec"
homepage = "https://github.com/structured-world/xml-sec"
documentation = "https://docs.rs/xml-sec"
keywords = ["xml", "xmldsig", "xmlenc", "c14n", "saml"]
categories = ["cryptography", "web-programming", "authentication"]
readme = "README.md"
include = [
"/Cargo.toml",
"/Cargo.lock",
"/LICENSE",
"/LICENSE-THIRD-PARTY",
"/README.md",
Comment thread
polaz marked this conversation as resolved.
"/assets/usdt-qr.svg",
"/docs/**",
"/src/**",
Comment thread
polaz marked this conversation as resolved.
"/examples/**",
"/tests/**",
"/tools/xmlsec1/**",
"/compatibility/**",
"/scripts/**",
]

[workspace]
members = [
Expand Down Expand Up @@ -64,7 +79,10 @@ required-features = ["xmlenc"]
roxmltree = { version = "0.21", features = ["positions"], optional = true }
xmloxide = { version = "0.5", default-features = false, optional = true }
self_cell = "1.3"
xml-sec-xml-input = { version = "0.1.0", path = "crates/xml-sec-xml-input" }
encoding_rs = { version = "0.8", default-features = false, features = ["alloc"] }
xmlparser = { version = "0.13.6", default-features = false }
peresil = { version = "0.3", optional = true }
snafu = { version = "0.9", optional = true }

# Crypto
rsa = { package = "sad-rsa", version = "0.10.2", features = ["sha1", "sha2"], optional = true }
Expand All @@ -81,8 +99,6 @@ signature = { version = "3", optional = true }
subtle = { version = "2", optional = true }
getrandom = { version = "0.4", features = ["sys_rng"], optional = true }
zeroize = { version = "1", optional = true }
sxd-document-no-unsafe = { package = "xml-sec-sxd-document", version = "0.1.0", path = "vendor/sxd-document-no-unsafe", default-features = false, features = ["no-unsafe"], optional = true }
sxd-xpath-no-unsafe = { package = "xml-sec-sxd-xpath", version = "0.1.1", path = "vendor/sxd-xpath-no-unsafe", default-features = false, features = ["no-unsafe"], optional = true }
aes = { version = "0.9.2", optional = true }
aes-gcm = { version = "0.11.1", optional = true }
aes-kw = { version = "0.3.1", optional = true }
Expand Down Expand Up @@ -115,14 +131,18 @@ time = "0.3.55"
tempfile = "3"

[features]
default = ["xmldsig", "xmlenc", "c14n", "xml-backend-xmloxide"]
default = ["std", "xmldsig", "xmlenc", "c14n", "xml-backend-xmloxide"]
std = ["thiserror/std", "xmlparser/std"]
xml-backend-xmloxide = ["dep:xmloxide"]
xml-backend-roxmltree = ["dep:roxmltree"]
xml-backends-all = ["xml-backend-xmloxide", "xml-backend-roxmltree"]
# Compatibility alias for existing CI/fuzz builds. Unlike `xml-backends-all`,
# this also selects differential parsing as the default runtime mode.
xml-backend-differential = ["xml-backends-all"]
xmldsig = [ # XML Digital Signatures (sign + verify)
"std",
"no-unsafe",
"embedded",
"dep:der",
"dep:crypto-bigint",
"dep:dsa",
Expand All @@ -132,6 +152,7 @@ xmldsig = [ # XML Digital Signatures (sign + verify)
"dep:hmac",
"dep:md-5",
"dep:pem",
"dep:peresil",
"dep:p256",
"dep:p384",
"dep:p521",
Expand All @@ -140,16 +161,16 @@ xmldsig = [ # XML Digital Signatures (sign + verify)
"dep:sha1",
"dep:sha2",
"dep:signature",
"dep:snafu",
"dep:subtle",
"dep:sxd-document-no-unsafe",
"dep:sxd-xpath-no-unsafe",
"dep:x509-parser",
"dep:x509-cert",
"dep:x520-stringprep",
"dep:tinyvec",
"dep:zeroize",
]
xmlenc = [ # XML Encryption (encrypt + decrypt)
"std",
"dep:aes",
"dep:aes-gcm",
"dep:aes-kw",
Expand All @@ -160,3 +181,8 @@ xmlenc = [ # XML Encryption (encrypt + decrypt)
"dep:sha2",
]
c14n = [] # XML Canonicalization (inclusive + exclusive)
no-unsafe = []
embedded = []

[lints.rust]
unexpected_cfgs = { level = "warn", check-cfg = ['cfg(feature, values("raw-pointer-backend", "__internal_expose_string_pool"))'] }
52 changes: 52 additions & 0 deletions LICENSE-THIRD-PARTY
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
The xml-sec crate includes code derived from the following projects. Their
copyright and permission notices are preserved below.

sxd-document (src/sxd_document/)
--------------------------------

The MIT License (MIT)

Copyright (c) 2014-2015 Jake Goulding

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

sxd-xpath (src/sxd_xpath/)
-------------------------

The MIT License (MIT)

Copyright (c) 2014-2017 Jake Goulding

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
17 changes: 8 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,11 +142,13 @@ ambiguous BOM-less UTF-16/UTF-32, and unsupported EBCDIC variants fail explicitl

**API migration for this pre-release change:** `encoding::decode_xml_octets` now requires a
maximum decoded-byte count as its second argument. `encoding::XmlEncodingError` is now the
shared, non-exhaustive `xml-sec-xml-input::Error`; update matches to handle the new error
shared, non-exhaustive `xml_sec::encoding::XmlEncodingError`; update matches to handle the new error
variants and include a fallback arm. Code constructing `ResourcePolicy` with every field must
also set `max_xml_namespace_bindings` (or start from `ResourcePolicy::default()` and override
selected fields). These changes keep decoding and namespace-scope allocation under explicit
resource limits.
resource limits. For trusted resolver-provided encoding metadata, use
`xml_input::decode_xml_bounded(bytes, Some(encoding), maximum_decoded_bytes)`; the unbounded
decoder remains internal.

## Native xmlsec1 CLI

Expand Down Expand Up @@ -184,14 +186,11 @@ access, XInclude processing, and operation time explicit. The default grants no
clock access; callers may supply a fixed clock for reproducible EXSLT date functions or explicitly
request host-clock compatibility.

```sh
cargo add xml-sec-xslt
```

The engine remains a separate architectural boundary. The main crate continues to reject XMLDSig
The engine currently remains an in-repository workspace crate rather than a separately published
package; `xml-sec` is the only crate published to crates.io. The main crate continues to reject XMLDSig
XSLT transforms until the policy, resource identity, and node-set adapter contracts are connected.
[`xml-sec-xml-input`](crates/xml-sec-xml-input) supplies the shared strict byte-decoding and lexical
boundary used by core and XSLT paths.
The shared strict byte-decoding and lexical source is compiled into `xml-sec` and reused by the
internal XSLT workspace crate.

## Specifications

Expand Down
1 change: 1 addition & 0 deletions crates/xml-sec-xml-input/Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
[package]
name = "xml-sec-xml-input"
version = "0.1.0"
publish = false
edition = "2024"
rust-version = "1.92"
license = "Apache-2.0"
Expand Down
Loading
Loading