{"_id":"@amsemnat/verifier-node","_rev":"3-281d5236cb783f468429c6355a3250d6","name":"@amsemnat/verifier-node","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@amsemnat/verifier-node","version":"0.1.0","keywords":["eid","romania","emrtd","passive-authentication","pades","signature","verifier","amsemnat"],"author":{"name":"am-semnat contributors"},"license":"Apache-2.0","_id":"@amsemnat/verifier-node@0.1.0","maintainers":[{"name":"andithemudkip","email":"andithemudkip@gmail.com"}],"homepage":"https://github.com/am-semnat/am-semnat-verifier-node","bugs":{"url":"https://github.com/am-semnat/am-semnat-verifier-node/issues"},"dist":{"shasum":"de1a89ab6a795f49986fb98eaaf5d8e0c0f2738c","tarball":"https://registry.npmjs.org/@amsemnat/verifier-node/-/verifier-node-0.1.0.tgz","fileCount":53,"integrity":"sha512-xTSUokZsyox72PQ7WulJJci4Rdhynr3fwfGgA0zD1IoGgkd43beEyJBIYOgIILkIxc6UxfjO8JHnp5QNrJu+Jg==","signatures":[{"sig":"MEYCIQCGbWQMDXnSYS0wo2uL1bMkS6lRSOs7l+4fMsG7EsIw9QIhAPanfaTFDsrtzjhISEZYxy76gMhdIrjv7uFiq8NuiO4D","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86767},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"2852317da535e7e8ee1a48dd000502ff61185ae4","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc --build","clean":"rm -rf dist","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build"},"_npmUser":{"name":"andithemudkip","email":"andithemudkip@gmail.com"},"repository":{"url":"git+https://github.com/am-semnat/am-semnat-verifier-node.git","type":"git"},"_npmVersion":"11.4.2","description":"Pure-Node verifier for Romanian eID artifacts produced by the am-semnat SDKs — eMRTD passive auth and PAdES B-B signer verification.","directories":{},"sideEffects":false,"_nodeVersion":"24.4.1","dependencies":{"pkijs":"^3.2.4","asn1js":"^3.0.5","pvtsutils":"^1.3.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.9","typescript":"^5.7.3","@types/node":"^22.12.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier-node_0.1.0_1777295337593_0.6363082202841932","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @amsemnat/verifier (same code, identical API). npm uninstall @amsemnat/verifier-node && npm install @amsemnat/verifier"},"0.1.1":{"name":"@amsemnat/verifier-node","version":"0.1.1","keywords":["eid","romania","emrtd","passive-authentication","pades","signature","verifier","amsemnat"],"author":{"name":"am-semnat contributors"},"license":"Apache-2.0","_id":"@amsemnat/verifier-node@0.1.1","maintainers":[{"name":"andithemudkip","email":"andithemudkip@gmail.com"}],"homepage":"https://github.com/am-semnat/am-semnat-verifier-node","bugs":{"url":"https://github.com/am-semnat/am-semnat-verifier-node/issues"},"dist":{"shasum":"f9f160ab3077c4ba54df11bf1bef25a0eeef146f","tarball":"https://registry.npmjs.org/@amsemnat/verifier-node/-/verifier-node-0.1.1.tgz","fileCount":53,"integrity":"sha512-E/Q4tOJ83yowcdW8t9PbtFD9T9lwhB0BTBldQP3J0dP6Bb1YwKS28ZDiJhSelqfg6WMRCF0BUj7enlJb8aZLVA==","signatures":[{"sig":"MEUCIH4VVUqp1zx7TrC2X65CNpizb/1dniLqIVWiryTYQG9UAiEAxrIKG/bbJUNVcFwz1mpH8azSjAOQOcTf71QNUSCKUBw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89481},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"b3971e313ff73ea363ab10b464d06d4f9ce1911b","scripts":{"lint":"tsc --noEmit","test":"vitest run","build":"tsc --build","clean":"rm -rf dist","test:watch":"vitest","prepublishOnly":"npm run clean && npm run build"},"_npmUser":{"name":"andithemudkip","email":"andithemudkip@gmail.com"},"repository":{"url":"git+https://github.com/am-semnat/am-semnat-verifier-node.git","type":"git"},"_npmVersion":"11.4.2","description":"Verifier for Romanian eID artifacts produced by the am-semnat SDKs — eMRTD passive auth and PAdES B-B signer verification. Runs in Node 20+, modern browsers, and edge runtimes.","directories":{},"sideEffects":false,"_nodeVersion":"24.4.1","dependencies":{"pkijs":"^3.2.4","asn1js":"^3.0.5","pvtsutils":"^1.3.6"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.1.9","typescript":"^5.7.3","@types/node":"^22.12.0"},"_npmOperationalInternal":{"tmp":"tmp/verifier-node_0.1.1_1777297730893_0.9005210936927126","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed to @amsemnat/verifier (same code, identical API). npm uninstall @amsemnat/verifier-node && npm install @amsemnat/verifier"}},"time":{"created":"2026-04-27T13:08:57.488Z","modified":"2026-04-27T19:04:34.564Z","0.1.0":"2026-04-27T13:08:57.791Z","0.1.1":"2026-04-27T13:48:51.103Z"},"bugs":{"url":"https://github.com/am-semnat/am-semnat-verifier-node/issues"},"author":{"name":"am-semnat contributors"},"license":"Apache-2.0","homepage":"https://github.com/am-semnat/am-semnat-verifier-node","keywords":["eid","romania","emrtd","passive-authentication","pades","signature","verifier","amsemnat"],"repository":{"url":"git+https://github.com/am-semnat/am-semnat-verifier-node.git","type":"git"},"description":"Verifier for Romanian eID artifacts produced by the am-semnat SDKs — eMRTD passive auth and PAdES B-B signer verification. Runs in Node 20+, modern browsers, and edge runtimes.","maintainers":[{"name":"andithemudkip","email":"andithemudkip@gmail.com"}],"readme":"# `@amsemnat/verifier-node`\n\nVerifier for Romanian eID artifacts produced by the\n[am-semnat](https://amsemnat.ro) SDKs. Pure JavaScript, runs unchanged\nin Node 20+, modern browsers, Cloudflare Workers, Deno, and Bun.\n\nTwo operations:\n\n- **`verifyPassive`** — eMRTD passive authentication. Takes the raw\n  `EF.SOD` bytes plus the data groups read from the chip and verifies\n  the SOD CMS signature, the DSC chain to a caller-supplied\n  CSCA Romania anchor, and the per-DG hashes. Use this server-side when\n  you receive `RomanianIdentity.rawSod` / `RomanianIdentity.rawDg*` from\n  one of the mobile SDKs.\n\n- **`verifyPadesSignatures`** — verifies every PAdES B-B signature in\n  an assembled signed PDF. Returns one result per signature in document\n  order, with `coversWholeDocument` for incremental-update detection.\n\nThis package ships **zero MAI trust material**. Consumers fetch the\ncurrent CSCA Romania (DGP) and RO CEI MAI Root/Sub-CA (DGEP) certs\nthemselves from the official MAI publication points.\n\n- **DGP — `CSCA Romania`**, published at\n  <https://pasapoarte.mai.gov.ro/csca.html>. Self-signed ICAO CSCA that\n  issues the Document Signer embedded in the eMRTD SOD. This is the\n  trust anchor for `verifyPassive(...)`.\n- **DGEP — `RO CEI MAI Root-CA` / `Sub-CA`**, published at\n  <https://hub.mai.gov.ro/cei/info/descarca-cert>. Issues the\n  per-citizen signing certificates stored in the CEI applet and used by\n  `AmSemnat.sign(...)`; those are the anchors for verifying the PAdES\n  signatures the SDK produces.\n\nYour app owns freshness and revocation — re-fetch on a cadence\nappropriate for your trust window.\n\n## Install\n\n```bash\nnpm install @amsemnat/verifier-node\n```\n\nESM-only. Server-side: Node 20 LTS or newer (for native\n`globalThis.crypto.subtle`). Client-side: any evergreen browser.\n\n## Quick start — passive auth\n\n```ts\nimport { readFileSync } from \"node:fs\";\nimport { verifyPassive } from \"@amsemnat/verifier-node\";\n\nconst csca = readFileSync(\"./csca-romania.cer\"); // DER, fetched from DGP\n\nconst result = await verifyPassive({\n  rawSod: req.body.rawSod,             // RomanianIdentity.rawSod from the mobile SDK\n  dataGroups: {\n    1: req.body.rawDg1,\n    2: req.body.rawDg2,\n    14: req.body.rawDg14,\n  },\n  trustAnchors: [csca],\n});\n\nif (!result.valid) {\n  console.error(\"Passive auth failed:\", result.errors);\n}\n```\n\n## Quick start — PAdES signature (Node)\n\n```ts\nimport { readFileSync } from \"node:fs\";\nimport { verifyPadesSignatures } from \"@amsemnat/verifier-node\";\n\nconst root = readFileSync(\"./ro-cei-mai-root-ca.cer\");\nconst sub = readFileSync(\"./ro-cei-mai-sub-ca.cer\");\n\nconst results = await verifyPadesSignatures({\n  pdf: readFileSync(\"./signed.pdf\"),\n  trustAnchors: [root, sub],\n});\n\nfor (const sig of results) {\n  console.log(\n    `#${sig.signatureIndex} [${sig.fieldName ?? \"?\"}] valid=${sig.valid} ` +\n      `signer=\"${sig.signerCommonName ?? \"?\"}\" ` +\n      `coversWholeDocument=${sig.coversWholeDocument}`,\n  );\n}\n```\n\n## Quick start — PAdES signature (browser)\n\n```ts\nimport { verifyPadesSignatures } from \"@amsemnat/verifier-node\";\n\n// Trust anchors fetched as static assets (DER), or bundled. Both work.\nconst [root, sub] = await Promise.all([\n  fetch(\"/anchors/ro-cei-mai-root-ca.cer\").then((r) => r.arrayBuffer()),\n  fetch(\"/anchors/ro-cei-mai-sub-ca.cer\").then((r) => r.arrayBuffer()),\n]);\n\nasync function onFile(file: File) {\n  const pdf = new Uint8Array(await file.arrayBuffer());\n  const results = await verifyPadesSignatures({\n    pdf,\n    trustAnchors: [new Uint8Array(root), new Uint8Array(sub)],\n  });\n  // render `results` in the UI\n}\n```\n\nThe verifier returns `[]` for unsigned PDFs. Each `PadesVerificationResult`\nincludes:\n\n- `valid` — overall outcome (CMS signature + chain + `signingCertificateV2` binding).\n- `errors` — human-readable failure strings; empty when `valid: true`.\n- `signerCommonName`, `signedAt` — best-effort metadata.\n- `signatureIndex`, `fieldName` — multi-sig disambiguation.\n- `byteRange`, `coversWholeDocument` — caller decides whether\n  `valid && coversWholeDocument` is the right policy for \"trust this PDF\n  end-to-end\". A `coversWholeDocument: false` on a non-final signature\n  is normal in incremental-update workflows.\n\n## Trust anchors\n\n`trustAnchors` is a flat list of DER-encoded X.509 certificates. The\nverifier auto-classifies self-signed entries as roots and the rest as\nintermediates — same convention as the mobile SDKs'\n`verifyPassiveOffline`. Pass everything in one array.\n\nPEM input is not accepted in 0.1.0. Decode to DER on the caller side\n(`pem.replace(/-----.*-----|\\s/g, '')` then base64-decode).\n\n## What we do *not* check yet\n\nDocumented out of scope for 0.1.0:\n\n- **Timestamp tokens (PAdES B-T).** `signedAt` comes from the\n  `signingTime` signed attribute only, not from a TST.\n- **CRL / OCSP / LTV.** Freshness and revocation are the consumer's\n  responsibility — fetch a current CSCA / DGEP masterlist on a\n  reasonable cadence yourself.\n- **MRZ / DG1 parsing.** This package verifies; it doesn't parse\n  identity. Use the mobile SDK's `RomanianIdentity` object for that.\n- **PEM trust anchors.** DER only.\n\n## Public API parity\n\nThe top-level result fields (`valid`, `errors`, `signerCommonName`,\n`signedAt`) match the mobile SDKs' `verifyPassiveOffline` shape. Cross-\nplatform code reading either offline or server-side results sees the\nsame surface for the load-bearing checks.\n\n## License\n\nApache-2.0. No vendored third-party source. Runtime deps (`pkijs`,\n`asn1js`, `pvtsutils`) are MIT-licensed.\n","readmeFilename":"README.md"}