Verify a delegation request's self-signature. The verifying key comes out of the document itself (`delegateKey`), which is exactly what makes this proof of *possession* and nothing more: it shows whoever produced the document holds the private half of the key it names. It carries no authority on its own — the human's countersignature does.
(document: &Value)
| 374 | /// whoever produced the document holds the private half of the key it names. It |
| 375 | /// carries no authority on its own — the human's countersignature does. |
| 376 | pub fn verify_request(document: &Value) -> Result<DelegationRequest> { |
| 377 | expect_type(document, TYPE_REQUEST)?; |
| 378 | let obj = as_object(document)?; |
| 379 | |
| 380 | let delegate_key_did = string_field(obj, "delegateKey")?; |
| 381 | let public_key = PublicKey::from_did_key(&delegate_key_did) |
| 382 | .map_err(|e| CanonicalError::Proof(format!("malformed delegateKey: {e}")))?; |
| 383 | |
| 384 | proof::verify_value(document, &public_key)?; |
| 385 | |
| 386 | let delegate = string_field(obj, "delegate")?; |
| 387 | let delegate_id = IdentityId::from_did(&delegate) |
| 388 | .map_err(|e| CanonicalError::Verification(format!("delegate DID is malformed: {e}")))?; |
| 389 | if !delegate_id.matches_public_key(&public_key) { |
| 390 | return Err(CanonicalError::Verification( |
| 391 | "delegateKey does not match the delegate DID".into(), |
| 392 | )); |
| 393 | } |
| 394 | |
| 395 | Ok(DelegationRequest { |
| 396 | delegate, |
| 397 | delegate_key: delegate_key_did, |
| 398 | delegate_name: string_field(obj, "delegateName")?, |
| 399 | software_agent: obj |
| 400 | .get("softwareAgent") |
| 401 | .and_then(Value::as_str) |
| 402 | .map(str::to_string), |
| 403 | requested: timestamp_field(obj, "requested")?, |
| 404 | }) |
| 405 | } |
| 406 | |
| 407 | // --------------------------------------------------------------------------- |
| 408 | // Revocation |