sealAt function
Signs a message with a timestamp from the caller, then encrypts it to a recipient.
msgToSeal: The message to sign and encryptmsgToAuth: Additional authenticated data (signed and bound to encryption, but not embedded)signer: The xDSA secret key to sign withrecipient: The xHPKE public key to encrypt todomain: Application domain for HPKE key derivationpadding: Sender's policy for zeros after the signed envelopetimestamp: Unix timestamp in seconds to embed in the signature
Returns the serialized COSE_Encrypt0 structure containing the encrypted
COSE_Sign1. Throws if msgToSeal or msgToAuth does not encode into the
supported CBOR subset. A padded size beyond what the platform can address
surfaces as the bridge's panic exception.
Implementation
Uint8List sealAt({
required Object? msgToSeal,
required Object? msgToAuth,
required xdsa.SecretKey signer,
required xhpke.PublicKey recipient,
required Uint8List domain,
required Padding padding,
required int timestamp,
}) {
final nativePadding = padding._native;
try {
return ffi.coseSealAt(
msgToSeal: _encode(msgToSeal),
msgToAuth: _encode(msgToAuth),
signer: signer.inner,
recipient: recipient.inner,
domain: domain,
padding: nativePadding,
timestamp: timestamp,
);
} finally {
nativePadding.dispose();
}
}