Add support for DER-to-ECDSA signature formatting in AwsKmsSign#28
Merged
ievgeniiskliarenko merged 2 commits intomasterfrom Jan 30, 2026
Merged
Add support for DER-to-ECDSA signature formatting in AwsKmsSign#28ievgeniiskliarenko merged 2 commits intomasterfrom
AwsKmsSign#28ievgeniiskliarenko merged 2 commits intomasterfrom
Conversation
- Decode ASN.1 DER-encoded signatures into raw R and S components for ECDSA algorithms. - Implement padding logic for `ES256`, `ES384`, and `ES512` to ensure fixed-length signatures. - Add comprehensive unit tests to validate the changes, including edge cases for padding and negative integers.
There was a problem hiding this comment.
Pull request overview
This PR adds support for converting DER-encoded ECDSA signatures from AWS KMS to the raw R||S format required by JWT specifications. The implementation decodes ASN.1 DER signatures and applies algorithm-specific padding for ES256, ES384, and ES512.
Changes:
- Decode DER-encoded signatures into raw R and S components for ECDSA algorithms
- Implement fixed-length padding (32, 48, and 66 bytes) for ES256, ES384, and ES512 respectively
- Add comprehensive unit tests covering standard cases, padding scenarios, and edge cases with negative integers
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| vicephp/Virtue-JWT/src/JWT/Algorithms/AwsKmsSign.php | Implements DER-to-raw signature conversion with algorithm-specific padding for ECDSA signatures |
| vicephp/Virtue-JWT/tests/JWT/Algorithms/AwsKmsSignTest.php | Adds unit tests validating ES256/ES384/ES512 signature formatting, padding behavior, and negative integer handling |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
evmoroz
approved these changes
Jan 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ES256,ES384, andES512to ensure fixed-length signatures.