Constructor.
the auth token to use
Optionalurl: string
the request URL to use
The signed HTTP headers.
The SolarNet auth token value.
Get the covered components, in signing order.
Get the keyid signature parameter value.
Set the signature algorithm.
The alg signature parameter is optional in RFC 9421, and is omitted unless set
here.
Optionalval: HmacSha256
the algorithm, or undefined to omit the parameter
this object
Compute the signing key from a token secret.
When a derived signing key is configured this is
HMAC(HMAC("SNWS3"+secret, "YYYYMMDD"), "snws3_request"), which expires like an
SNWS2 signing key does. Otherwise it is the token secret itself.
the token secret
the signing key
Compute a Content-Digest HTTP header for the request content.
The computed header value is saved on Net.HttpMessageSignatureBuilder#httpHeaders, and must also be passed on the HTTP request for the signature to verify. The Net.HttpMessageSignatureBuilder#contentDigestHeaderValue method can be used to obtain the header value after calling this method.
the request body content to digest
this object
Get the Content-Digest HTTP header value.
The Net.HttpMessageSignatureBuilder#contentDigest method should be called to compute the header value before calling this method.
the header value, or undefined if none set
Set the HTTP Content-Type header.
the content type to use
this object
Add covered components, in signing order.
the components to cover, either names or component objects
this object
Cover the minimum set of components SolarNetwork requires.
That is the request method, authority, and path, along with the query when the
request has one, the content type and content digest when the request has content,
and every X-SN-* header configured on this builder.
this object
Get the request date.
the signature creation date
Set the request date.
the signature creation date to use
this object
Set whether to derive the signing key from the token secret and the signing date.
This is enabled by default, so that a token secret need not be handed to whatever signs the request.
true to derive a signing key, false to use the token secret itself
this object
Set the signature expiration date.
Optionalval: Date
the expiration date, or undefined for none
this object
Set an HTTP header value.
the header name
the header value
this object
Set the signature label.
the label to use
this object
Get the HTTP method (verb) to use.
the HTTP method to use
Set the HTTP method (verb) to use.
the method to use; see the Net.HttpMethod enum for possible values
this object
Set the signature nonce.
Optionalval: string
the nonce, or undefined for none
this object
Reset to default property values.
The token ID, label, tag, algorithm, and signing key mode are preserved.
this object
Compute the signature value, using a token secret.
the token secret
the Base64 encoded signature value
Get the Signature HTTP header value, using a token secret.
the token secret
the header value
Get the Signature HTTP header value, using a signing key.
the signing key
the header value
Get the Signature-Input HTTP header value.
the header value
Compute the serialized signature parameters.
This is the value of the @signature-params line of the signature base, and also
the Signature-Input member value.
the serialized signature parameters
Compute the signature value, using a signing key.
the signing key
the Base64 encoded signature value
Set the application tag.
SolarNetwork uses this to pick the signature meant for authentication when a
request carries more than one. It defaults to solarnetwork.
Optionalval: string
the tag, or undefined for none
this object
Get the request URL.
the request URL
Set the request URL.
the absolute request URL to use
this object
A builder for RFC 9421 HTTP message signatures on a SolarNetwork API request.
This is the RFC 9421 counterpart to Net.AuthorizationV2Builder, and uses the same security token credentials. A request is signed by covering a set of message components; SolarNetwork requires a minimum set of them, which coverRequiredComponents() configures:
By default the signing key is derived from the token secret and the signing date, which works like the SNWS2 signing key in that it expires, and so can be handed to a signer without disclosing the secret. To sign with the token secret itself instead, which is what any RFC 9421 implementation can do with only the token ID and secret:
Post requests
RFC 9421 has no notion of message content: a request body is covered by covering a
Content-Digestfield that digests it. Use contentDigest() to compute that field, and pass the same value on the request.