summaryrefslogtreecommitdiff
path: root/verify.py
blob: 2ed7d244eb67ea757f1492d32cec6ed586c1e489 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
import base64
import click
import fitz
import json

from io import BytesIO
from pathlib import Path

from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import padding, ec
from cryptography.exceptions import InvalidSignature
from PIL import Image
from pyzbar import pyzbar


class GreenPassVerifier(object):
    def __init__(self, data_bytes):
        self.validate_bytes(data_bytes)

        sig, self.payload = data_bytes.split(b"#", maxsplit=1)
        self.signature = base64.decodebytes(sig)
        self.data = json.loads(self.payload)

        self.validate_data()
        self.details = self.get_details()
        self.digest = self.get_digest()

        self.ec_cert = self.get_cert_path("IL-NB-DSC-01.pem")
        self.rsa_cert = self.get_cert_path("RamzorQRPubKey.pem")

    @classmethod
    def from_payload(cls, path):
        with open(path, "rb") as f:
            return cls(f.read().strip())

    @classmethod
    def from_qr(cls, path):
        return cls(pyzbar.decode(Image.open(path))[0].data)

    @classmethod
    def from_pdf(cls, path):
        doc = fitz.open(path)
        for i in range(len(doc)):
            for img in doc.get_page_images(i):
                xref, width = img[0], img[2]
                if width in (
                    3080,  # in green pass v2
                    3720,  # in green pass
                    4200,  # in vaccination certificate
                ):
                    img = fitz.Pixmap(doc, xref)
                    data = img.getImageData(output="png")
                    return cls.from_qr(BytesIO(data))

    def validate_bytes(self, bs):
        if bs.decode().startswith("GreenPass"):
            click.secho(
                "⚠️  Green pass QR code contains no signature to verify",
                fg="yellow",
                bold=True,
            )
            click.get_current_context().exit()

    def validate_data(self):
        ct = self.data["ct"]
        if ct not in (1, 2):
            click.secho(f"Unknown certificate type ct={ct}", fg="red", bold=True)
            click.get_current_context().exit()

    def get_cert_path(self, name):
        return Path(__file__).absolute().parent / "certs" / name

    def get_details(self):
        details = []
        data = self.data
        if data["ct"] == 1:
            for i in range(len(data["p"])):
                details.append(
                    {
                        "id_num": data["p"][i]["idl"],
                        "valid_by": data["p"][i]["e"],
                        "cert_id": data["id"],
                    }
                )
        elif data["ct"] == 2:
            details.append(
                {
                    "id_num": data["idl"],
                    "valid_by": data["e"],
                    "cert_id": data["id"],
                }
            )
        return details

    def get_digest(self):
        ct = self.data["ct"]
        if ct == 1:
            digest = self.payload.decode().encode("utf8")
        elif ct == 2:
            h = hashes.Hash(hashes.SHA256())
            h.update(self.payload)
            digest = h.finalize()
        return digest

    def verify(self):
        for d in self.details:
            click.echo(f"\tIsraeli ID Number {d['id_num']}")
            click.echo(f"\tID valid by {d['valid_by']}")
            click.echo(f"\tCert Unique ID {d['cert_id']}")

        certs = [
            [
                self.rsa_cert,
                [
                    padding.PKCS1v15(),
                    hashes.SHA256(),
                ],
            ],
            [self.ec_cert, [ec.ECDSA(hashes.SHA256())]],
        ]
        for cert, method in certs:
            with open(cert, "rb") as f:
                k = serialization.load_pem_public_key(f.read())
                try:
                    k.verify(self.signature, self.digest, *method)
                    click.secho("✅ Valid signature!", fg="green", bold=True)
                    break
                except InvalidSignature:
                    pass
        else:
            click.secho("❌ Invalid signature!", fg="red", bold=True)


@click.command()
@click.option("-p", "--pdf-path", type=click.Path(exists=True), help="Path to PDF file")
@click.option(
    "-i",
    "--image-path",
    type=click.Path(exists=True),
    help="Path to an image with the QR code",
)
@click.option(
    "-t",
    "--txt-path",
    type=click.Path(exists=True),
    help="Path to decoded QR code textual content",
)
def verify(pdf_path="", image_path="", txt_path=""):
    if image_path:
        verifier = GreenPassVerifier.from_qr(image_path)
    elif pdf_path:
        verifier = GreenPassVerifier.from_pdf(pdf_path)
    elif txt_path:
        verifier = GreenPassVerifier.from_payload(txt_path)
    else:
        ctx = click.get_current_context()
        click.echo(ctx.get_help())
        ctx.exit()
    verifier.verify()


if __name__ == "__main__":
    verify()