open<T> function
T
open<T>({})
Decrypts and verifies a sealed message.
Uses the current system time for drift checking, and openAt takes it from the caller instead.
msgToOpen: The serialized COSE_Encrypt0 structuremsgToAuth: The same additional authenticated data used during sealingrecipient: The xHPKE secret key to decrypt withsender: The xDSA public key to verify the signature againstdomain: Application domain for HPKE key derivationmaxDriftSecs: Maximum allowed timestamp difference in seconds, past or future. A value of n accepts differences up to and including n;nullskips the check.
Returns the payload decoded by the cbor package, cast to T. Throws if
maxDriftSecs is negative, if decryption fails as in decrypt, or if
verification fails as in verify.
Implementation
T open<T>({
required Uint8List msgToOpen,
required Object? msgToAuth,
required xhpke.SecretKey recipient,
required xdsa.PublicKey sender,
required Uint8List domain,
int? maxDriftSecs,
}) =>
_decode(
ffi.coseOpen(
msgToOpen: msgToOpen,
msgToAuth: _encode(msgToAuth),
recipient: recipient.inner,
sender: sender.inner,
domain: domain,
maxDriftSecs: _drift(maxDriftSecs),
),
)
as T;