CSC Remote Signature Provider
THPDFCSCSignatureProvider implements CSC API v2 credentials/info, credentials/authorize, credentials/authorizeCheck, signatures/signHash, signatures/signPolling, and signatures/timestamp on the existing THPDFSignatureProvider contract
Transport and authorization
The provider never selects an HTTP stack or stores a refresh token, client secret, PIN, or OTP
THPDFCSCTransport receives the exact method, URL, bearer authorization, JSON body, stable idempotency key, attempt number, operation identifier, and response budget, while THPDFCSCAccessTokenCallback supplies and refreshes short-lived OAuth access tokens
When SAD is required, the provider retrieves credential metadata and the complete bounded certificate chain, asks THPDFCSCAuthenticationCallback for reviewed authentication values, obtains a SAD, and polls an asynchronous authorization handle when necessary
Signing and replay safety
Sign accepts digest input from the CMS pipeline, carries the digest and signature OIDs into signatures/signHash, and emits DER-encoded RSA-PSS parameters when required
SignHashBatch sends an ordered same-algorithm digest batch under one authorization, pins the resulting SAD to the exact count, algorithms, parameters, and digest bytes, and preserves request order in synchronous and asynchronous results
A multi-digest call is accepted only when its count fits both MaxBatchSignatures and the credential multisign value, and the response must contain exactly one signature for every requested digest
Transient requests reuse a fixed-length SHA-256 content-addressed Idempotency-Key, while the bounded operation cache returns defensive copies of an already completed batch when the same operation, credential, parameters, and ordered digests are submitted again
A failed transport attempt retains an automatically authorized SAD for an exact retry, but a different batch cannot consume that SAD and must obtain a new authorization
Budgets and cancellation
THPDFCSCOptions.Default bounds batch signatures, response bytes, individual signatures, timestamps, certificate chain count and bytes, retry attempts, Retry-After delays, poll attempts, and cached operations
Cancel is observed before transport calls, between retries, and during short-sliced poll waits, and the operation identifier is also passed to the transport so an application can cancel its own in-flight HTTP request
Certificate chains and timestamps
RefreshCredentialInfo validates and caches key, algorithm, authorization, SCAL, multisignature, and certificate-chain metadata without signing
GetCertificateChain returns defensive byte copies suitable for the CMS certificate input, while TimestampDigest requests and decodes one RFC 3161 token with an optional nonce