Skip to content

Phase 3 + 4: XML signature (re-landed) + database integration - #4

Merged
karlkauc merged 2 commits into
mainfrom
feature/enterprise-showcase-phase4
May 15, 2026
Merged

karlkauc merged 2 commits into
mainfrom
feature/enterprise-showcase-phase4

Conversation

@karlkauc

@karlkauc karlkauc commented May 15, 2026 •

Copy link
Copy Markdown
Contributor

Builds on Phases 1–2 (PRs #1, #2 — merged to main). Contains TWO phases.

⚠️ PR #3 ("MERGED") did not actually land on main. It was a stacked PR based on the Phase 2 branch, which GitHub auto-deleted when PR #2 merged — so Phase 3's XML_Signature/ never reached main. This PR re-lands Phase 3 together with Phase 4. Future phases branch off the latest main (no stacking).

Phase 3 — XML_Signature/ (re-landed)

Enveloped XML-DSig, RSA-SHA256 / exclusive C14N, ds:Signature as last child of <FundsXML4>. Java/Apache Santuario (xmlsec 4.0.4) sign+verify verified incl. tamper detection and signed file staying XSD-valid; secure validation on. generate-test-key.sh (keys gitignored). xmlsec1 / signxml / .NET SignedXml references, same profile. CI sign→verify→tamper.

Phase 4 — Database_Integration/

FundsXML ⇄ relational DB. No DB provisioned (per scope): Oracle/SQL Server/Postgres load (XMLTABLE/XMLType/.nodes()) + generate (SQL/XML publishing) are code references. python/fundsxml_db.py is the runnable, verified SQLite reference (init/load/generate/roundtrip). Round-trip → XSD-valid FundsXML, NAV/position-count/percentage-sum preserved (4.2.9 positions, 4.1.0 & 4.0.0 positions, 4.2.9 transactions). Lossy outside positions core (documented). CI round-trip + assertions.

Roadmap remaining: Phase 5 large-file/stream · 6 data binding/JSON.

🤖 Generated with Claude Code

karlkauc and others added 2 commits May 15, 2026 18:58
XML_Signature/: enveloped XML-DSig, RSA-SHA256 / exclusive-C14N, ds:Signature
appended as last child of <FundsXML4> (schema-allowed). Java/Apache Santuario
(xmlsec 4.0.4) sign + verify verified locally incl. tamper detection and that
the signed file stays XSD-valid; secure validation enabled on verify.
generate-test-key.sh makes a throwaway RSA keypair (keys/ gitignored).
xmlsec1 CLI, Python signxml and .NET SignedXml provided as references with the
same profile so files cross-verify.

tools/fetch-tools.sh also fetches Santuario (xmlsec + commons-codec + slf4j).
CI gains a sign->verify->tamper roundtrip step (verified locally). Top-level
index row -> done.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…tgres code)

Database_Integration/: shared relational model (ddl/schema.sql). Per scope no
DB is provisioned — Oracle/SQL Server/Postgres load (XMLTABLE / XMLType /
.nodes()) and generate (SQL/XML publishing) are code references.

python/fundsxml_db.py is the runnable, verified SQLite reference: init/load/
generate/roundtrip using only stdlib + lxml. Verified: 4.2.9 positions, 4.1.0
& 4.0.0 positions, 4.2.9 transactions each load to SQLite and regenerate
XSD-valid FundsXML with NAV / position count / percentage-sum preserved.
Model is intentionally lossy outside the positions core (documented).

CI gains a FundsXML -> SQLite -> FundsXML round-trip step with XSD validation
and figure-preservation assertions (verified locally). Top-level index updated.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@karlkauc karlkauc changed the title Phase 4: database integration (SQLite verified + Oracle/SQL Server/Postgres code) Phase 3 + 4: XML signature (re-landed) + database integration May 15, 2026
@karlkauc
karlkauc merged commit 1bb1ca1 into main May 15, 2026
2 checks passed
@karlkauc
karlkauc deleted the feature/enterprise-showcase-phase4 branch May 15, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant