sealAt function

Uint8List sealAt({
  1. required Object? msgToSeal,
  2. required Object? msgToAuth,
  3. required SecretKey signer,
  4. required PublicKey recipient,
  5. required Uint8List domain,
  6. required Padding padding,
  7. required int timestamp,
})

Signs a message with a timestamp from the caller, then encrypts it to a recipient.

  • msgToSeal: The message to sign and encrypt
  • msgToAuth: Additional authenticated data (signed and bound to encryption, but not embedded)
  • signer: The xDSA secret key to sign with
  • recipient: The xHPKE public key to encrypt to
  • domain: Application domain for HPKE key derivation
  • padding: Sender's policy for zeros after the signed envelope
  • timestamp: Unix timestamp in seconds to embed in the signature

Returns the serialized COSE_Encrypt0 structure containing the encrypted COSE_Sign1. Throws if msgToSeal or msgToAuth does not encode into the supported CBOR subset. A padded size beyond what the platform can address surfaces as the bridge's panic exception.

Implementation

Uint8List sealAt({
  required Object? msgToSeal,
  required Object? msgToAuth,
  required xdsa.SecretKey signer,
  required xhpke.PublicKey recipient,
  required Uint8List domain,
  required Padding padding,
  required int timestamp,
}) {
  final nativePadding = padding._native;
  try {
    return ffi.coseSealAt(
      msgToSeal: _encode(msgToSeal),
      msgToAuth: _encode(msgToAuth),
      signer: signer.inner,
      recipient: recipient.inner,
      domain: domain,
      padding: nativePadding,
      timestamp: timestamp,
    );
  } finally {
    nativePadding.dispose();
  }
}