Decode a certificate presented in a request header. Checks the size cap first, then base64, then JSON. Does **not** verify — [`verify`] against the delegator's registered key is a separate, mandatory step, and keeping them apart means no call site can accidentally treat a well-formed certificate as a trusted one.
(encoded: &str)
| 301 | /// step, and keeping them apart means no call site can accidentally treat a |
| 302 | /// well-formed certificate as a trusted one. |
| 303 | pub fn decode_from_transport(encoded: &str) -> Result<Value> { |
| 304 | if encoded.len() > MAX_ENCODED_DELEGATION { |
| 305 | return Err(CanonicalError::Proof(format!( |
| 306 | "delegation is {} bytes, over the {MAX_ENCODED_DELEGATION}-byte limit", |
| 307 | encoded.len() |
| 308 | ))); |
| 309 | } |
| 310 | |
| 311 | let bytes = data_encoding::BASE64URL_NOPAD |
| 312 | .decode(encoded.trim().as_bytes()) |
| 313 | .map_err(|e| CanonicalError::Proof(format!("delegation is not valid base64url: {e}")))?; |
| 314 | |
| 315 | serde_json::from_slice(&bytes) |
| 316 | .map_err(|e| CanonicalError::Proof(format!("delegation is not valid JSON: {e}"))) |
| 317 | } |
| 318 | |
| 319 | /// A stable fingerprint of an encoded certificate, for caching a verified |
| 320 | /// result without re-running the Ed25519 check on every request. |