Repository navigation
feat(preuve): attestation PDF horodatée (PAdES) et jeton dans l'export - #26
Merged
Merged
Conversation
- src/pdf.php : attestation PDF sans dépendance, une page A4 (données de la signature et de l'horodatage), attestation JSON et jeton RFC 3161 en pièces jointes, horodatage PAdES du document (DocTimeStamp, ETSI.RFC3161) par l'autorité de staging. Téléchargeable depuis la page de preuve, conservé une fois horodaté. - Export JSON des données personnelles : texte exact de l'attestation et jeton d'horodatage en base64. Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Attestation PDF, comme sur la démonstration, téléchargeable depuis la page de preuve :
.jsonet son jeton.tsr;/DocTimeStamp,/SubFilter /ETSI.RFC3161) demandé au staging ;src/pdf.php) ; construit au premier téléchargement, conservé en base une fois horodaté ; si le staging ne répond pas, PDF servi sans champ de signature puis reconstruit.Export JSON (page de retrait) : ajoute le texte exact de l'attestation et le jeton d'horodatage RFC 3161 en base64.
Vérifié avec un PDF réellement horodaté par le staging :
qpdf --check: aucune erreur de structure ;pdfdetach: 2 pièces jointes ;pdftotext: accents corrects ;bash tests/flow.sh: PDF (en-tête, sous-filtre, pièces jointes), horodatage du document vérifié paropenssl ts -verifysur les plages ByteRange, cache, jeton dans l'export.Note :
pdfsig(poppler) ne sait pas valider les horodatages de document ETSI.RFC3161 (type « unknown ») — limite de l'outil.