Content assembly (BuildContent) is separate from PDF drawing (Render), so the actual business logic — what goes into the evidence dossier, in what form, with which mandatory fields — is unit-testable without parsing PDF bytes. BuildContent refuses to produce a dossier missing its evidentiary fields (timestamp token, asset/metadata hash, platform) rather than emitting one with silently empty proof sections. Every dossier carries the "this is not legal advice" disclaimer required by CLAUDE.md's guardrails. Uses github.com/go-pdf/fpdf (actively maintained fork of jung-kurt/ gofpdf, no dependencies beyond the Go stdlib) for rendering. Its core fonts use cp1252 internally, so a small cp1252.map (copied from the fpdf module, embedded via go:embed) drives UnicodeTranslator — German umlauts render correctly without needing an external font file at runtime, keeping Deklarix a single binary. Verified visually with pdftotext/pdfinfo against a generated sample. Tests build a real, structurally valid RFC-3161 token offline (a throwaway self-signed cert + timestamp.Timestamp.CreateResponse), so BuildContent/Render/Generate are fully tested without hitting a real TSA — unlike the network-gated integration test in internal/evidence. Also adds evidence.TimestampTime(), extracted from the parsing logic already used by the TSA client, since the dossier needs to show the timestamped time to a human reader. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
19 lines
408 B
Go
19 lines
408 B
Go
package evidence
|
|
|
|
import (
|
|
"fmt"
|
|
"time"
|
|
|
|
"github.com/digitorus/timestamp"
|
|
)
|
|
|
|
// TimestampTime liefert den im RFC-3161-Token bescheinigten Zeitpunkt,
|
|
// z. B. für die Anzeige im Nachweis-Dossier.
|
|
func TimestampTime(token []byte) (time.Time, error) {
|
|
ts, err := timestamp.Parse(token)
|
|
if err != nil {
|
|
return time.Time{}, fmt.Errorf("evidence: timestamp token parse: %w", err)
|
|
}
|
|
return ts.Time, nil
|
|
}
|