verify function
Verifies a CWT's COSE signature and temporal validity, then returns the decoded claims.
When now is provided, temporal claims are validated. The nbf claim (key
5, Claims.notBefore) must be present and nbf <= now, and if the exp
claim (key 4, Claims.expiration) is present then now < exp. When now
is null, temporal validation is skipped entirely.
The COSE signature timestamp is not checked; temporal validity comes from the CWT claims. Successful verification does not establish issuer trust, enforce an audience, evaluate attestation policy or EAT claim relationships, or prove possession of a Confirm key. The application must perform those checks.
token: The serialized CWTverifier: The xDSA public key to verify againstdomain: Application domain for separating protocol purposesnow: Unix timestamp in seconds for temporal validation (null to skip)
Throws if now is negative, if the token is malformed, was signed by
another key or does not verify, or if it fails the temporal checks. Also
throws if its claims fall outside the supported CBOR subset.
Implementation
Claims verify({
required Uint8List token,
required xdsa.PublicKey verifier,
required Uint8List domain,
int? now,
}) {
if (now != null && now < 0) {
throw ArgumentError.value(
now,
'now',
'must be a non-negative Unix timestamp',
);
}
return Claims._decode(
ffi.cwtVerify(
token: token,
verifier: verifier.inner,
domain: domain,
now: now != null ? BigInt.from(now) : null,
),
);
}