MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / verify_revocation

Function verify_revocation

atomic-canonical/src/delegation.rs:452–478  ·  view source on GitHub ↗

Verify a revocation against the delegator's public key. Only the delegator may revoke, so the signature must be theirs and the `delegator` field must name that same key.

(
    document: &Value,
    delegator_public_key: &PublicKey,
)

Source from the content-addressed store, hash-verified

450/// Only the delegator may revoke, so the signature must be theirs and the
451/// `delegator` field must name that same key.
452pub fn verify_revocation(
453 document: &Value,
454 delegator_public_key: &PublicKey,
455) -> Result<DelegationRevocation> {
456 expect_type(document, TYPE_REVOCATION)?;
457 proof::verify_value(document, delegator_public_key)?;
458
459 let obj = as_object(document)?;
460 let delegator = string_field(obj, "delegator")?;
461 let delegator_id = IdentityId::from_did(&delegator)
462 .map_err(|e| CanonicalError::Verification(format!("delegator DID is malformed: {e}")))?;
463 if !delegator_id.matches_public_key(delegator_public_key) {
464 return Err(CanonicalError::Verification(
465 "revocation delegator DID does not match the verifying key".into(),
466 ));
467 }
468
469 Ok(DelegationRevocation {
470 delegation: string_field(obj, "delegation")?,
471 delegator,
472 revoked_at: timestamp_field(obj, "revokedAt")?,
473 reason: obj
474 .get("reason")
475 .and_then(Value::as_str)
476 .map(str::to_string),
477 })
478}
479
480// ---------------------------------------------------------------------------
481// Store-backed lookup

Callers 1

revocation_round_tripsFunction · 0.85

Calls 7

expect_typeFunction · 0.85
verify_valueFunction · 0.85
as_objectFunction · 0.85
string_fieldFunction · 0.85
timestamp_fieldFunction · 0.85
matches_public_keyMethod · 0.80
getMethod · 0.65

Tested by 1

revocation_round_tripsFunction · 0.68