Verify a revocation against the delegator's public key. Only the delegator may revoke, so the signature must be theirs and the `delegator` field must name that same key.
(
document: &Value,
delegator_public_key: &PublicKey,
)
| 450 | /// Only the delegator may revoke, so the signature must be theirs and the |
| 451 | /// `delegator` field must name that same key. |
| 452 | pub fn verify_revocation( |
| 453 | document: &Value, |
| 454 | delegator_public_key: &PublicKey, |
| 455 | ) -> Result<DelegationRevocation> { |
| 456 | expect_type(document, TYPE_REVOCATION)?; |
| 457 | proof::verify_value(document, delegator_public_key)?; |
| 458 | |
| 459 | let obj = as_object(document)?; |
| 460 | let delegator = string_field(obj, "delegator")?; |
| 461 | let delegator_id = IdentityId::from_did(&delegator) |
| 462 | .map_err(|e| CanonicalError::Verification(format!("delegator DID is malformed: {e}")))?; |
| 463 | if !delegator_id.matches_public_key(delegator_public_key) { |
| 464 | return Err(CanonicalError::Verification( |
| 465 | "revocation delegator DID does not match the verifying key".into(), |
| 466 | )); |
| 467 | } |
| 468 | |
| 469 | Ok(DelegationRevocation { |
| 470 | delegation: string_field(obj, "delegation")?, |
| 471 | delegator, |
| 472 | revoked_at: timestamp_field(obj, "revokedAt")?, |
| 473 | reason: obj |
| 474 | .get("reason") |
| 475 | .and_then(Value::as_str) |
| 476 | .map(str::to_string), |
| 477 | }) |
| 478 | } |
| 479 | |
| 480 | // --------------------------------------------------------------------------- |
| 481 | // Store-backed lookup |