verify function

Claims verify({
  1. required Uint8List token,
  2. required PublicKey verifier,
  3. required Uint8List domain,
  4. int? now,
})

Verifies a CWT's COSE signature and temporal validity, then returns the decoded claims.

When now is provided, temporal claims are validated. The nbf claim (key 5, Claims.notBefore) must be present and nbf <= now, and if the exp claim (key 4, Claims.expiration) is present then now < exp. When now is null, temporal validation is skipped entirely.

The COSE signature timestamp is not checked; temporal validity comes from the CWT claims. Successful verification does not establish issuer trust, enforce an audience, evaluate attestation policy or EAT claim relationships, or prove possession of a Confirm key. The application must perform those checks.

  • token: The serialized CWT
  • verifier: The xDSA public key to verify against
  • domain: Application domain for separating protocol purposes
  • now: Unix timestamp in seconds for temporal validation (null to skip)

Throws if now is negative, if the token is malformed, was signed by another key or does not verify, or if it fails the temporal checks. Also throws if its claims fall outside the supported CBOR subset.

Implementation

Claims verify({
  required Uint8List token,
  required xdsa.PublicKey verifier,
  required Uint8List domain,
  int? now,
}) {
  if (now != null && now < 0) {
    throw ArgumentError.value(
      now,
      'now',
      'must be a non-negative Unix timestamp',
    );
  }
  return Claims._decode(
    ffi.cwtVerify(
      token: token,
      verifier: verifier.inner,
      domain: domain,
      now: now != null ? BigInt.from(now) : null,
    ),
  );
}