Phase 3 + 4: XML signature (re-landed) + database integration - #4
Merged
Merged
Conversation
XML_Signature/: enveloped XML-DSig, RSA-SHA256 / exclusive-C14N, ds:Signature appended as last child of <FundsXML4> (schema-allowed). Java/Apache Santuario (xmlsec 4.0.4) sign + verify verified locally incl. tamper detection and that the signed file stays XSD-valid; secure validation enabled on verify. generate-test-key.sh makes a throwaway RSA keypair (keys/ gitignored). xmlsec1 CLI, Python signxml and .NET SignedXml provided as references with the same profile so files cross-verify. tools/fetch-tools.sh also fetches Santuario (xmlsec + commons-codec + slf4j). CI gains a sign->verify->tamper roundtrip step (verified locally). Top-level index row -> done. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…tgres code) Database_Integration/: shared relational model (ddl/schema.sql). Per scope no DB is provisioned — Oracle/SQL Server/Postgres load (XMLTABLE / XMLType / .nodes()) and generate (SQL/XML publishing) are code references. python/fundsxml_db.py is the runnable, verified SQLite reference: init/load/ generate/roundtrip using only stdlib + lxml. Verified: 4.2.9 positions, 4.1.0 & 4.0.0 positions, 4.2.9 transactions each load to SQLite and regenerate XSD-valid FundsXML with NAV / position count / percentage-sum preserved. Model is intentionally lossy outside the positions core (documented). CI gains a FundsXML -> SQLite -> FundsXML round-trip step with XSD validation and figure-preservation assertions (verified locally). Top-level index updated. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Builds on Phases 1–2 (PRs #1, #2 — merged to main). Contains TWO phases.
Phase 3 —
XML_Signature/(re-landed)Enveloped XML-DSig, RSA-SHA256 / exclusive C14N,
ds:Signatureas last child of<FundsXML4>. Java/Apache Santuario (xmlsec 4.0.4) sign+verify verified incl. tamper detection and signed file staying XSD-valid; secure validation on.generate-test-key.sh(keys gitignored). xmlsec1 / signxml / .NETSignedXmlreferences, same profile. CI sign→verify→tamper.Phase 4 —
Database_Integration/FundsXML ⇄ relational DB. No DB provisioned (per scope): Oracle/SQL Server/Postgres load (XMLTABLE/XMLType/
.nodes()) + generate (SQL/XML publishing) are code references.python/fundsxml_db.pyis the runnable, verified SQLite reference (init/load/generate/roundtrip). Round-trip → XSD-valid FundsXML, NAV/position-count/percentage-sum preserved (4.2.9 positions, 4.1.0 & 4.0.0 positions, 4.2.9 transactions). Lossy outside positions core (documented). CI round-trip + assertions.Roadmap remaining: Phase 5 large-file/stream · 6 data binding/JSON.
🤖 Generated with Claude Code