Skip to content

DocFence 0.57.0

Choose a tag to compare

@SybilGambleyyu SybilGambleyyu released this 06 Aug 10:43

DocFence 0.57.0 enforces OPC Relationship Transform context across every recognized XML signature.

A Relationship Transform must be a direct Transform in a direct Manifest/Reference/Transforms chain whose URI declares a .rels part with OPCs exact relationships content type. It must have at least one direct OPC relationship selector, be immediately followed by XML Canonicalization, and occur only once for that declared relationships part in the signature.

This is a stored-syntax boundary applied before the bounded declaration-coverage audit, including unrelated SignedInfo references. DocFence does not resolve a manifest target, interpret selectors, execute transforms, recompute a digest, verify XMLDSIG, or make a trust decision.

Validation:

  • 69 tests passed locally and in tagged CI on Python 3.11 and 3.13.
  • A 0.56-versus-0.57 comparison shows 0.56 accepted malformed extra SignedInfo, selectorless, missing/misordered canonicalization, duplicate, and ordinary-Word-part Relationship Transform variants; 0.57 rejects each, while the standard declared-coverage fixture remains accepted.
  • The public OOXML Signature Security corpus has 29 DOCX files, 22 XML signature parts, and 21 parseable signature parts. Its 38 Relationship Transforms all satisfy this boundary; public profiles are byte-identical to 0.56.
  • Two independent tagged builds were byte-identical.

SHA-256:

  • docfence-0.57.0-py3-none-any.whl: 82833ab11f84aa432bac1bac601d89d23e24910b35a59f8306fad3e6c42f99a4
  • docfence-0.57.0.tar.gz: 642abd6d696b19ba08389eadeacf98506d66012558747f1dd500aea64e426336