seal function
Signs a message then encrypts it to a recipient.
Uses the current system time as the signature timestamp, and sealAt takes it from the caller instead.
msgToSeal: The message to sign and encryptmsgToAuth: Additional authenticated data (signed and bound to encryption, but not embedded)signer: The xDSA secret key to sign withrecipient: The xHPKE public key to encrypt todomain: Application domain for HPKE key derivationpadding: Sender's policy for zeros after the signed envelope
Returns the serialized COSE_Encrypt0 structure containing the encrypted
COSE_Sign1. Throws if msgToSeal or msgToAuth does not encode into the
supported CBOR subset. A padded size beyond what the platform can address
surfaces as the bridge's panic exception.
Implementation
Uint8List seal({
required Object? msgToSeal,
required Object? msgToAuth,
required xdsa.SecretKey signer,
required xhpke.PublicKey recipient,
required Uint8List domain,
required Padding padding,
}) {
final nativePadding = padding._native;
try {
return ffi.coseSeal(
msgToSeal: _encode(msgToSeal),
msgToAuth: _encode(msgToAuth),
signer: signer.inner,
recipient: recipient.inner,
domain: domain,
padding: nativePadding,
);
} finally {
nativePadding.dispose();
}
}