Skip to content

feat(ext/node): implement X509Certificate methods for Apple verifier - #752

Open
fffzlfk wants to merge 1 commit into
supabase:mainfrom
fffzlfk:fix/x509-certificate-methods
Open

fffzlfk wants to merge 1 commit into
supabase:mainfrom
fffzlfk:fix/x509-certificate-methods

Conversation

@fffzlfk

@fffzlfk fffzlfk commented Oct 8, 2026

Copy link
Copy Markdown

Summary

Implement X509Certificate.raw, toString(), infoAccess, and verify() in the Node crypto polyfill. These methods are used by @apple/app-store-server-library@3.1.0 when initializing its signed data verifier; the current stubs raise ERR_NOT_IMPLEMENTED.

The Rust ops expose the certificate DER and PEM encodings, format Authority Information Access entries, and verify the certificate signature against a supplied KeyObject. Signature verification covers RSA PKCS#1 v1.5 with SHA-1/256/384/512 and ECDSA with SHA-256/384/512. A certificate fixture checks the encodings, OCSP URI, successful verification, and a tampered signature.

Related upstream Deno work: denoland/deno#32270

Validation

  • cargo check -p ext_node and the targeted Rust unit test passed with this patch on the local Edge Runtime branch.
  • RUSTUP_TOOLCHAIN=stable cargo fmt --all --check and git diff --check passed on this branch.
  • Node.js confirmed the fixture's infoAccess, raw, toString(), and verify() output.
  • The targeted Rust test could not be rerun against upstream main locally: its pinned Rust 1.98 toolchain is not installed, and the offline dependency cache lacks async-scoped.

Expose DER and PEM encodings, authority information access, and certificate signature verification through the Node crypto polyfill.

Co-Authored-By: Codex <codex@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant