openAt<T> function

T openAt<T>({
  1. required Uint8List msgToOpen,
  2. required Object? msgToAuth,
  3. required SecretKey recipient,
  4. required PublicKey sender,
  5. required Uint8List domain,
  6. int? maxDriftSecs,
  7. required int now,
})

Decrypts and verifies a sealed message against a time from the caller.

  • msgToOpen: The serialized COSE_Encrypt0 structure
  • msgToAuth: The same additional authenticated data used during sealing
  • recipient: The xHPKE secret key to decrypt with
  • sender: The xDSA public key to verify the signature against
  • domain: Application domain for HPKE key derivation
  • maxDriftSecs: Maximum allowed timestamp difference in seconds, past or future. A value of n accepts differences up to and including n; null skips the check.
  • now: Unix timestamp in seconds to measure the drift against

Returns the payload decoded by the cbor package, cast to T. Throws as open does, with the drift measured against now.

Implementation

T openAt<T>({
  required Uint8List msgToOpen,
  required Object? msgToAuth,
  required xhpke.SecretKey recipient,
  required xdsa.PublicKey sender,
  required Uint8List domain,
  int? maxDriftSecs,
  required int now,
}) =>
    _decode(
          ffi.coseOpenAt(
            msgToOpen: msgToOpen,
            msgToAuth: _encode(msgToAuth),
            recipient: recipient.inner,
            sender: sender.inner,
            domain: domain,
            maxDriftSecs: _drift(maxDriftSecs),
            now: now,
          ),
        )
        as T;