[FIX] l10n_es_edi_facturae: change signature template

This commit fixes the signature in the export by:
- Changing the signature template to remove unnecessary transforms.
- Replacing SigningCertificateV2 with the correct tag. According to https://www.facturae.gob.es/formato/Paginas/politicas-firma-electronica.aspx the signature follows the XAdES ETSI TS 101 903 format which contains the tag SigningCertificate instead.
- Correcting the way the signature node was removed in the _get_uri_function.

closes odoo/odoo#137321

X-original-commit: e4d92f37da41e7e5efaeb82b4adfff669083fb23
Signed-off-by: William André (wan) <wan@odoo.com>
This commit is contained in:
Ali Alfie (alal)
2023-10-03 07:19:01 +00:00
parent ca797bb960
commit d58e0c43c7
6 changed files with 22 additions and 37 deletions
@@ -7,11 +7,7 @@
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference t-att-Id="reference_uri" Type="http://www.w3.org/2000/09/xmldsig#Object" URI="">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
<ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue></ds:DigestValue>
@@ -42,7 +38,7 @@
<xades:SignedProperties t-att-Id="sigproperties_id">
<xades:SignedSignatureProperties>
<xades:SigningTime t-out="iso_now"/>
<xades:SigningCertificateV2>
<xades:SigningCertificate>
<xades:Cert>
<xades:CertDigest>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -53,7 +49,7 @@
<ds:X509SerialNumber t-out="x509_serial_number"/>
</xades:IssuerSerial>
</xades:Cert>
</xades:SigningCertificateV2>
</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>
<xades:SignaturePolicyId>
<xades:SigPolicyId>
@@ -254,18 +254,14 @@
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference Type="http://www.w3.org/2000/09/xmldsig#Object" URI="" Id="Reference-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
<ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>___ignore___</ds:DigestValue>
</ds:Reference>
<ds:Reference Type="http://uri.etsi.org/01903#SignedProperties" URI="#SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>UQH7ea0mtLoqLN/aM5mWssQ38fOK1bxnWT4fKQBYiSI=</ds:DigestValue>
<ds:DigestValue>SpcFoWamxWQCsYjqZ/lsru5Ia4MaKBVgXiUWgKKBh2s=</ds:DigestValue>
</ds:Reference>
<ds:Reference URI="#KeyInfo-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -310,7 +306,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<xades:SignedProperties Id="SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<xades:SignedSignatureProperties>
<xades:SigningTime>2023-01-01T00:00:00</xades:SigningTime>
<xades:SigningCertificateV2>
<xades:SigningCertificate>
<xades:Cert>
<xades:CertDigest>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -321,7 +317,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<ds:X509SerialNumber>548631688851000697209704649636588277530075594025</ds:X509SerialNumber>
</xades:IssuerSerial>
</xades:Cert>
</xades:SigningCertificateV2>
</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>
<xades:SignaturePolicyId>
<xades:SigPolicyId>
@@ -161,18 +161,14 @@
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference Type="http://www.w3.org/2000/09/xmldsig#Object" URI="" Id="Reference-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
<ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>___ignore___</ds:DigestValue>
</ds:Reference>
<ds:Reference Type="http://uri.etsi.org/01903#SignedProperties" URI="#SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>UQH7ea0mtLoqLN/aM5mWssQ38fOK1bxnWT4fKQBYiSI=</ds:DigestValue>
<ds:DigestValue>SpcFoWamxWQCsYjqZ/lsru5Ia4MaKBVgXiUWgKKBh2s=</ds:DigestValue>
</ds:Reference>
<ds:Reference URI="#KeyInfo-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -217,7 +213,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<xades:SignedProperties Id="SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<xades:SignedSignatureProperties>
<xades:SigningTime>2023-01-01T00:00:00</xades:SigningTime>
<xades:SigningCertificateV2>
<xades:SigningCertificate>
<xades:Cert>
<xades:CertDigest>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -228,7 +224,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<ds:X509SerialNumber>548631688851000697209704649636588277530075594025</ds:X509SerialNumber>
</xades:IssuerSerial>
</xades:Cert>
</xades:SigningCertificateV2>
</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>
<xades:SignaturePolicyId>
<xades:SigPolicyId>
@@ -254,18 +254,14 @@
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<ds:Reference Type="http://www.w3.org/2000/09/xmldsig#Object" URI="" Id="Reference-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/TR/2001/REC-xml-c14n-20010315"/>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
<ds:Transform Algorithm="http://www.w3.org/TR/1999/REC-xpath-19991116">
<ds:XPath>not(ancestor-or-self::ds:Signature)</ds:XPath>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>___ignore___</ds:DigestValue>
<ds:DigestValue>ZLrDCYSAq93Xpv9PLeS4CSBh4htTOx5j4f7zH0K8ddI=</ds:DigestValue>
</ds:Reference>
<ds:Reference Type="http://uri.etsi.org/01903#SignedProperties" URI="#SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<ds:DigestValue>UQH7ea0mtLoqLN/aM5mWssQ38fOK1bxnWT4fKQBYiSI=</ds:DigestValue>
<ds:DigestValue>SpcFoWamxWQCsYjqZ/lsru5Ia4MaKBVgXiUWgKKBh2s=</ds:DigestValue>
</ds:Reference>
<ds:Reference URI="#KeyInfo-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -310,7 +306,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<xades:SignedProperties Id="SignatureProperties-Document-da39a3ee5e6b4b0d3255bfef95601890afd80709">
<xades:SignedSignatureProperties>
<xades:SigningTime>2023-01-01T00:00:00</xades:SigningTime>
<xades:SigningCertificateV2>
<xades:SigningCertificate>
<xades:Cert>
<xades:CertDigest>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -321,7 +317,7 @@ aWAYAMCL4KhvISclysD+5juDLpGCLHPtKxBXTQ==</ds:Modulus>
<ds:X509SerialNumber>548631688851000697209704649636588277530075594025</ds:X509SerialNumber>
</xades:IssuerSerial>
</xades:Cert>
</xades:SigningCertificateV2>
</xades:SigningCertificate>
<xades:SignaturePolicyIdentifier>
<xades:SignaturePolicyId>
<xades:SigPolicyId>
@@ -249,10 +249,6 @@
<ds:Reference Id="___ignore___" Type="___ignore___" URI="___ignore___">
<ds:Transforms>
<ds:Transform Algorithm="___ignore___"/>
<ds:Transform Algorithm="___ignore___"/>
<ds:Transform Algorithm="___ignore___">
<ds:XPath>___ignore___</ds:XPath>
</ds:Transform>
</ds:Transforms>
<ds:DigestMethod Algorithm="___ignore___"/>
<ds:DigestValue>___ignore___</ds:DigestValue>
@@ -283,7 +279,7 @@
<xd:SignedProperties Id="___ignore___">
<xd:SignedSignatureProperties>
<xd:SigningTime>___ignore___</xd:SigningTime>
<xd:SigningCertificateV2>
<xd:SigningCertificate>
<xd:Cert>
<xd:CertDigest>
<ds:DigestMethod Algorithm="___ignore___"/>
@@ -294,7 +290,7 @@
<ds:X509SerialNumber>___ignore___</ds:X509SerialNumber>
</xd:IssuerSerial>
</xd:Cert>
</xd:SigningCertificateV2>
</xd:SigningCertificate>
<xd:SignaturePolicyIdentifier>
<xd:SignaturePolicyId>
<xd:SigPolicyId>
+8 -3
View File
@@ -33,11 +33,16 @@ def _get_uri(uri, reference, base_uri=""):
https://www.w3.org/TR/xmldsig-core/#sec-EnvelopedSignature
Returns an UTF-8 encoded bytes string.
"""
node = deepcopy(reference.getroottree())
node = deepcopy(reference.getroottree().getroot())
if uri == base_uri:
# Base URI: whole document, without signature (default is empty URI)
for signature in node.xpath('/ds:Signature', namespaces=NS_MAP):
node = signature.getparent()
for signature in node.xpath('ds:Signature', namespaces=NS_MAP):
if signature.tail:
# move the tail to the previous node or to the parent
if (previous := signature.getprevious()) is not None:
previous.tail = "".join([previous.tail or "", signature.tail or ""])
else:
signature.getparent().text = "".join([signature.getparent().text or "", signature.tail or ""])
node.remove(signature)
return _canonicalize_node(node)