//#region src/internal/asn1/der.d.ts /** * Low-level DER encoding and reading helpers shared across the library. * * These utilities build and traverse ASN.1 TLV (tag-length-value) structures. * * @module */ /** * Maximum nesting depth allowed when recursively walking a DER structure. * * Guards against stack exhaustion from pathologically nested input. */ declare const DEFAULT_MAX_DER_DEPTH = 64; /** Concatenates multiple byte arrays into a single {@linkcode Uint8Array}. */ declare function concatBytes(parts: readonly Uint8Array[]): Uint8Array; /** * Builds a complete DER TLV (tag-length-value) element: * * - one tag octet, * - the DER-encoded length, then * - the raw value bytes. */ declare function tlv(tag: number, value: Uint8Array): Uint8Array; /** Wraps concatenated children in a SEQUENCE (tag `0x30`). */ declare function sequence(parts: readonly Uint8Array[]): Uint8Array; /** * Wraps children in a SET (tag `0x31`) after DER-sorting them lexicographically by encoded bytes, * as required by {@linkcode https://www.itu.int/rec/T-REC-X.690-202102-I/en | X.690} DER. */ declare function setOf(parts: readonly Uint8Array[]): Uint8Array; /** * Wraps a value in an explicit context-specific constructed tag (`0xa0 + tag`). * * Used for optional SEQUENCE fields tagged with `[tag] EXPLICIT`. */ declare function explicitContext(tag: number, value: Uint8Array): Uint8Array; /** * Wraps a value in an implicit context-specific constructed tag (`0xa0 + tag`). * * Used for `[tag] IMPLICIT` fields whose underlying type is constructed (e.g. SEQUENCE). */ declare function implicitConstructedContext(tag: number, value: Uint8Array): Uint8Array; /** * Wraps a value in an implicit context-specific primitive tag (`0x80 + tag`). * * Used for `[tag] IMPLICIT` fields whose underlying type is primitive (e.g. OCTET STRING). */ declare function implicitPrimitiveContext(tag: number, value: Uint8Array): Uint8Array; /** * Encodes raw big-endian bytes as a DER INTEGER (tag `0x02`). * * Strips leading zero bytes for minimal encoding and prepends a zero byte when the high bit is set * to keep the value non-negative. */ declare function integer(bytes: Uint8Array): Uint8Array; /** * Encodes a non-negative JavaScript `number` as a DER INTEGER. * * @throws if the value is not a non-negative safe integer. */ declare function integerFromNumber(value: number): Uint8Array; /** Encodes a DER BOOLEAN (tag `0x01`): `true` → `0xff`, `false` → `0x00`. */ declare function bool(value: boolean): Uint8Array; /** Produces a DER NULL element (tag `0x05`, zero-length value). */ declare function nullValue(): Uint8Array; /** Wraps raw bytes in an OCTET STRING element (tag `0x04`). */ declare function octetString(value: Uint8Array): Uint8Array; /** * Encodes a DER BIT STRING (tag `0x03`). * * The value is prefixed with a single octet indicating how many trailing bits in the last byte are unused. * * @param unusedBits Number of unused trailing bits (0–7). Defaults to 0. */ declare function bitString(value: Uint8Array, unusedBits?: number): Uint8Array; /** Encodes a DER UTF8String (tag `0x0c`). */ declare function utf8String(value: string): Uint8Array; /** * Encodes a DER PrintableString (tag `0x13`). * * @throws if the input contains characters outside the ITU-T X.680 §41.4 Table 10 PrintableString set. */ declare function printableString(value: string): Uint8Array; /** * Encodes a DER IA5String (tag `0x16`). * * @throws if the input contains any non-ASCII character (code point > 0x7f). */ declare function ia5String(value: string): Uint8Array; /** * Encodes a DER BMPString (tag `0x1e`) as big-endian UTF-16. * * @throws on lone surrogates and on code points above the Basic Multilingual Plane. */ declare function bmpString(value: string): Uint8Array; /** * Encodes a DER UniversalString (tag `0x1c`) as big-endian UTF-32. * * @throws on lone surrogates. */ declare function universalString(value: string): Uint8Array; /** * Encodes a dotted-decimal OID string as a DER OBJECT IDENTIFIER (tag `0x06`). * * Validates arc constraints per X.660 §7.6: the root arc must be 0–2, and under * roots 0 and 1 the second arc must be 0–39. X.690 §8.19.4 defines the `(X*40)+Y` * packing of the first two arcs into one subidentifier.\ * Sub-identifiers are encoded with base-128 continuation. */ declare function objectIdentifier(oid: string): Uint8Array; /** * Encodes a `Date` as a DER UTCTime (tag `0x17`), format `YYMMDDHHMMSSZ`. * * Only the two-digit year is stored; suitable for dates in 1950–2049. */ declare function utcTime(date: Date): Uint8Array; /** * Encodes a {@linkcode Date} as a DER GeneralizedTime (tag `0x18`), format `YYYYMMDDHHMMSSZ`. * * Uses a four-digit year; required for dates outside the 1950–2049 range. */ declare function generalizedTime(date: Date): Uint8Array; /** * Encodes a {@linkcode Date} as the appropriate DER time type per RFC 5280. * * - {@linkcode utcTime} for 1950–2049 * - {@linkcode generalizedTime} otherwise */ declare function time(date: Date): Uint8Array; /** A single parsed ASN.1 TLV element with byte-range metadata. */ interface DerElement { /** ASN.1 tag byte (e.g. `0x30` for SEQUENCE, `0x02` for INTEGER). */ readonly tag: number; /** Number of bytes occupied by the tag + length octets. */ readonly headerLength: number; /** Byte length of the value portion (excluding tag and length octets). */ readonly length: number; /** Byte offset where the value portion begins in the source buffer. */ readonly start: number; /** Byte offset one past the last value byte. Equals the next element's header offset. */ readonly end: number; /** The raw value bytes (slice of the source buffer). */ readonly value: Uint8Array; } /** Options for {@linkcode readSequenceChildren}. */ interface ReadSequenceChildrenOptions { /** Maximum nesting depth for the DER depth check. @default {@linkcode DEFAULT_MAX_DER_DEPTH}. */ readonly maxDepth?: number; /** Constructed tags whose inner bytes may not parse as valid TLV children (e.g. opaque extension values). */ readonly allowOpaqueConstructedTags?: readonly number[]; } /** Options for {@linkcode readRootElement}. */ interface ReadRootElementOptions { /** Maximum nesting depth for the DER depth check. @default {@linkcode DEFAULT_MAX_DER_DEPTH}. */ readonly maxDepth?: number; /** Constructed tags whose inner bytes may not parse as valid TLV children (e.g. opaque extension values). */ readonly allowOpaqueConstructedTags?: readonly number[]; } /** * Walks the full DER tree rooted in {@linkcode bytes}. * * Constructed tags with content that cannot be parsed as valid children are tolerated when listed in {@linkcode options | allowOpaqueConstructedTags}. * * @throws if nesting exceeds {@linkcode maxDepth}. */ declare function assertDerMaxDepth(bytes: Uint8Array, maxDepth?: number, options?: { /** Constructed tags whose inner bytes may not parse as valid TLV children. */ readonly allowOpaqueConstructedTags?: readonly number[]; }): void; //#endregion export { DEFAULT_MAX_DER_DEPTH, DerElement, ReadRootElementOptions, ReadSequenceChildrenOptions, assertDerMaxDepth, bitString, bmpString, bool, concatBytes, explicitContext, generalizedTime, ia5String, implicitConstructedContext, implicitPrimitiveContext, integer, integerFromNumber, nullValue, objectIdentifier, octetString, printableString, sequence, setOf, time, tlv, universalString, utcTime, utf8String }; //# sourceMappingURL=der.d.ts.map