{"id":18485,"date":"2017-07-28T14:43:58","date_gmt":"2017-07-28T18:43:58","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=18485"},"modified":"2023-08-09T16:01:57","modified_gmt":"2023-08-09T20:01:57","slug":"receipt-validation-in-swift","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2017\/07\/28\/receipt-validation-in-swift\/","title":{"rendered":"Receipt Validation in Swift"},"content":{"rendered":"<p><a href=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/16\/receipt-validation-verifying-a-receipt-signature-in-swift\/\">Andrew Bancroft<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/16\/receipt-validation-verifying-a-receipt-signature-in-swift\/\">\n<p>The aim of this guide is to help you take a look <em>inside<\/em> the PKCS #7 container, and verify the presence and authenticity of the signature on the receipt.<\/p>\n<\/blockquote>\n<p><a href=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/27\/receipt-validation-parsing-a-receipt-with-swift\/\">Andrew Bancroft<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/27\/receipt-validation-parsing-a-receipt-with-swift\/\"><p>The aim of this guide is to help you parse a receipt and decode it so that you have readable pieces of metadata to inspect and finalize all of the receipt validation steps.<\/p>\n<p>[&#8230;]<\/p>\n<p>In-app purchase receipts are encoded as ASN.1 Sets (with ASN.1 Sequences within) <em>inside<\/em> the primary ASN.1 Set receipt payload.  In other words, they&rsquo;re <em>nested<\/em> ASN.1 Sets within the <em>overall<\/em> ASN.1 Set that encodes the whole receipt. The nested Set contains the <em>in-app purchase<\/em> receipt attributes.<\/p><\/blockquote>\n\n<p>Update (2017-07-31): <a href=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/31\/finalizing-receipt-validation-in-swift-computing-a-guid-hash\/\">Andrew Bancroft<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.andrewcbancroft.com\/2017\/07\/31\/finalizing-receipt-validation-in-swift-computing-a-guid-hash\/\"><p>The aim of this guide is to help you finalize the receipt validation process by computing the GUID hash for your app, and comparing it to the hash that&rsquo;s stored within your receipt itself.<\/p><\/blockquote>\n\n<p id=\"receipt-validation-in-swift-update-2023-08-09\">Update (2023-08-09): <a href=\"https:\/\/mastodon.social\/@felix_schwarz\/110832217816809929\">Felix Schwarz<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@felix_schwarz\/110832217816809929\"><p>Two days ago I finally got annoyed enough with the OpenSSL dependency for App Store receipt parsing and validation that I had another shot at an ASN.1 parser.<\/p><p>Today I have ObjC parsers for ASN.1 and PKCS#7, signature validation through Security.framework and can drop OpenSSL from my App Store project(s). &#x1F973;<\/p><p>In retrospect I wish I had found that courage earlier instead of spending a lot more time than this on getting OpenSSL to build for all the various Apple platforms and CPUs.<\/p><\/blockquote>\n\n<p>So much time and storage space have been collectively been wasted on this. Why couldn&rsquo;t Apple have just used a plist or JSON?<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/03\/08\/swift-certificates-and-asn-1-packages\/\">Swift &ldquo;Certificates&rdquo; and &ldquo;ASN.1&rdquo; Packages<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Andrew Bancroft: The aim of this guide is to help you take a look inside the PKCS #7 container, and verify the presence and authenticity of the signature on the receipt. Andrew Bancroft: The aim of this guide is to help you parse a receipt and decode it so that you have readable pieces of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2023-05-29T14:17:03Z","apple_news_api_id":"8c565dc9-ae3d-46f0-b0a1-9cbfe7a9089c","apple_news_api_modified_at":"2023-08-09T20:01:59Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AjFZdya49RvCwoZy_56kInA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[4],"tags":[91,2392,522,31,1380,30,39,1381,270,71,901],"class_list":["post-18485","post","type-post","status-publish","format-standard","hentry","category-programming-category","tag-appstore","tag-app-store-receipt-validation","tag-inapppurchase","tag-ios","tag-ios-10","tag-mac","tag-macappstore","tag-macos-10-12","tag-parser","tag-programming","tag-swift-programming-language"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/18485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=18485"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/18485\/revisions"}],"predecessor-version":[{"id":40299,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/18485\/revisions\/40299"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=18485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=18485"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=18485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}