verifyDetached function

void verifyDetached({
  1. required Uint8List msgToCheck,
  2. required Object? msgToAuth,
  3. required PublicKey verifier,
  4. required Uint8List domain,
  5. int? maxDriftSecs,
})

Validates a COSE_Sign1 digital signature with a detached payload.

Uses the current system time for drift checking, and verifyDetachedAt takes it from the caller instead.

  • msgToCheck: The serialized COSE_Sign1 structure (with null payload)
  • msgToAuth: The same message used during signing (verified but not embedded)
  • verifier: The xDSA public key to verify against
  • domain: Application domain for separating protocol purposes
  • maxDriftSecs: Maximum allowed timestamp difference in seconds, past or future. A value of n accepts differences up to and including n; null skips the check.

Throws if maxDriftSecs is negative, or if the envelope is malformed, embeds a payload, was signed by another key or does not verify. Also throws if its timestamp is further than maxDriftSecs from the current time.

Implementation

void verifyDetached({
  required Uint8List msgToCheck,
  required Object? msgToAuth,
  required xdsa.PublicKey verifier,
  required Uint8List domain,
  int? maxDriftSecs,
}) => ffi.coseVerifyDetached(
  msgToCheck: msgToCheck,
  msgToAuth: _encode(msgToAuth),
  verifier: verifier.inner,
  domain: domain,
  maxDriftSecs: _drift(maxDriftSecs),
);