KeyPackage class
The KEM recipient key(s) one APKAM keypair advertises so that other clients of the same atSign can seal secrets to it.
The recipient unit is the APKAM keypair, not a client process. Enrollment cardinality is 1:1:1 — one enrollment has exactly one APKAM keypair and therefore exactly one key package — so a key package is identified by its enrollmentId (with apkamId carried alongside for reference).
Key packages are enrollment-internal — they live in the enrollment
record, conveyed there by riding enroll:request as opaque
EnrollParams.metadata at enrollment time, and are discovered only via the
gated enroll:listns verb (see EnrollmentDirectory). They are not
published as ordinary at-keys. Per the ratified design the advertised key
package is wrapped in an APKAM-signed envelope by its generating enrollment
and verified against that enrollment's _apsk, so the encapsulation target
is authenticated rather than merely server-vouched. A package that does not
verify, or that is signed by an enrollment other than the one advertising
it, is not sealed to.
toJson / fromPayload are the inner payload — the value stored at
metadata.keyPackage is that payload wrapped in the signed envelope.
enrollmentId and apkamId are carried by the enclosing verb structure,
not duplicated in the payload.
- Annotations
-
- @experimental
Constructors
-
KeyPackage({required String enrollmentId, String? apkamId, required DateTime createdAt, required List<
PackageKey> keys, List<String> ? suites, int v = currentVersion}) -
suitesdefaults to whatkeyscan open — see the field's own doc for why that is not the same as what this build supports.factory
Properties
- apkamId → String?
-
The APKAM keypair this key package belongs to, as reported by the verb
(the enrollment's
apkamPubKey). Null on a key package this client builds for its own enrollment — identity is carried by the enclosing enrollment.final - createdAt → DateTime
-
final
- enrollmentId → String
-
The enrollment this key package belongs to.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
-
keys
→ List<
PackageKey> -
final
- kpid → String?
-
The addressing token for this key package: the
kidof its active enc-use key (the KEM public key a sender seals to). Null if the package advertises no active key for SecretSharingAlgos.keyAlgos.no setter - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
suites
→ List<
String> -
The sealing suites this package's holder can open, strongest first.
final
- v → int
-
final
Methods
-
bestKeyFor(
List< String> supportedAlgos, {String use = SecretSharingAlgos.useEnc}) → PackageKey? -
The first active key in
supportedAlgosorder (strongest first) that this key package advertises foruse. Returns null if the package andsupportedAlgoshave no algorithm in common, or if every key they do have in common is retired. -
bestSuiteFor(
List< String> senderSuites) → String? -
The first suite in
senderSuitesorder (strongest first) that this package's holder can also open, or null if there is no overlap. -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toJson(
) → Map< String, Object?> -
The value stored at
metadata.keyPackage— the payload only. enrollmentId / apkamId are carried by the enclosing verb structure (the enrollment and its APKAM-keypair entry), not repeated here. -
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Static Methods
-
fromPayload(
Object? payload, {required String enrollmentId, String? apkamId}) → KeyPackage -
Parses a stored key-package
payload(frommetadata.keyPackage), injecting theenrollmentId/apkamIdthe enclosing verb structure carried. Skips malformed entries inkeysrather than throwing — a payload written by a newer client may carry key entries (or extra fields) this version does not understand. -
payloadFor(
{required DateTime createdAt, required List< PackageKey> keys, List<String> ? suites, int v = currentVersion}) → Map<String, Object?> - The same payload as toJson, for a package whose enrollment does not exist yet.
Constants
- currentVersion → const int