| Methods |
public
|
__construct(
string $clientPrivateKeySetLocation,
string $hyperwalletKeySetLocation,
string $encryptionAlgorithm = 'RSA-OAEP-256',
string $signAlgorithm = 'RS256',
string $encryptionMethod = 'A256CBC-HS512',
integer $jwsExpirationMinutes = 5,
)
Creates a instance of the HyperwalletEncryption
Creates a instance of the HyperwalletEncryption
Parameters
| $clientPrivateKeySetLocation |
String that can be a URL or path to file with client JWK set
|
| $hyperwalletKeySetLocation |
String that can be a URL or path to file with hyperwallet JWK set
|
| $encryptionAlgorithm |
JWE encryption algorithm, by default value = RSA-OAEP-256
|
| $signAlgorithm |
JWS signature algorithm, by default value = RS256
|
| $encryptionMethod |
JWE encryption method, by default value = A256CBC-HS512
|
| $jwsExpirationMinutes |
Minutes when JWS signature is valid, by default value = 5
|
|
#
|
public
|
encrypt(string $body): string
Makes an encrypted request : 1) signs the request body; 2) encrypts payload after signature
Makes an encrypted request : 1) signs the request body; 2) encrypts payload after signature
Parameters
| $body |
The request body to be encrypted
|
Throws
|
#
|
public
|
decrypt(string $body): string
Decrypts encrypted response : 1) decrypts the request body; 2) verifies the payload signature
Decrypts encrypted response : 1) decrypts the request body; 2) verifies the payload signature
Parameters
| $body |
The response body to be decrypted
|
Throws
|
#
|
public
|
checkJwsExpiration(array $header)
Checks if header 'exp' param has not expired value
Checks if header 'exp' param has not expired value
Parameters
Throws
|
#
|
public
|
checkJweHeaderAlgorithm(array $header)
Checks that the JWE header advertises the key-management algorithm and content-encryption method
this client expects,…
Checks that the JWE header advertises the key-management algorithm and content-encryption method
this client expects, before the header-controlled algorithm is ever used to decrypt with the
private key. Prevents an attacker from forcing algorithm downgrade (e.g. to legacy RSA1_5) by
tampering with the untrusted alg/enc header fields of an intercepted response.
Parameters
Throws
|
#
|
public
|
getVendorPath(): string
Finds the path of composer vendor directory
Finds the path of composer vendor directory
Throws
|
#
|