verify<T> function

T verify<T>({
  1. required Uint8List msgToCheck,
  2. required Object? msgToAuth,
  3. required PublicKey verifier,
  4. required Uint8List domain,
  5. int? maxDriftSecs,
})

Validates a COSE_Sign1 digital signature and returns the embedded payload.

Uses the current system time for drift checking, and verifyAt takes it from the caller instead.

  • msgToCheck: The serialized COSE_Sign1 structure
  • msgToAuth: The same additional authenticated data used during signing
  • verifier: The xDSA public key to verify against
  • domain: Application domain for separating protocol purposes
  • maxDriftSecs: Maximum allowed timestamp difference in seconds, past or future. A value of n accepts differences up to and including n; null skips the check.

Returns the embedded payload decoded by the cbor package, cast to T. Throws if maxDriftSecs is negative, or if the envelope is malformed, has no embedded payload, was signed by another key or does not verify. Also throws if its payload falls outside the supported CBOR subset, or if its timestamp is further than maxDriftSecs from the current time.

Implementation

T verify<T>({
  required Uint8List msgToCheck,
  required Object? msgToAuth,
  required xdsa.PublicKey verifier,
  required Uint8List domain,
  int? maxDriftSecs,
}) =>
    _decode(
          ffi.coseVerify(
            msgToCheck: msgToCheck,
            msgToAuth: _encode(msgToAuth),
            verifier: verifier.inner,
            domain: domain,
            maxDriftSecs: _drift(maxDriftSecs),
          ),
        )
        as T;