Verify a delegation request's self-signature. The verifying key comes out of the document itself (`delegateKey`), which is exactly what makes this proof of *possession* and nothing more: it shows whoever produced the document holds the private half of the key it names. It carries no authority on its own — the human's countersignature does.
(document: &Value)
| 406 | /// whoever produced the document holds the private half of the key it names. It |
| 407 | /// carries no authority on its own — the human's countersignature does. |
| 408 | pub fn verify_request(document: &Value) -> Result<DelegationRequest> { |
| 409 | expect_type(document, TYPE_REQUEST)?; |
| 410 | let obj = as_object(document)?; |
| 411 | |
| 412 | let delegate_key_did = string_field(obj, "delegateKey")?; |
| 413 | let public_key = PublicKey::from_did_key(&delegate_key_did) |
| 414 | .map_err(|e| CanonicalError::Proof(format!("malformed delegateKey: {e}")))?; |
| 415 | |
| 416 | proof::verify_value(document, &public_key)?; |
| 417 | |
| 418 | let delegate = string_field(obj, "delegate")?; |
| 419 | let delegate_id = IdentityId::from_did(&delegate) |
| 420 | .map_err(|e| CanonicalError::Verification(format!("delegate DID is malformed: {e}")))?; |
| 421 | if !delegate_id.matches_public_key(&public_key) { |
| 422 | return Err(CanonicalError::Verification( |
| 423 | "delegateKey does not match the delegate DID".into(), |
| 424 | )); |
| 425 | } |
| 426 | |
| 427 | Ok(DelegationRequest { |
| 428 | delegate, |
| 429 | delegate_key: delegate_key_did, |
| 430 | delegate_name: string_field(obj, "delegateName")?, |
| 431 | software_agent: obj |
| 432 | .get("softwareAgent") |
| 433 | .and_then(Value::as_str) |
| 434 | .map(str::to_string), |
| 435 | requested: timestamp_field(obj, "requested")?, |
| 436 | }) |
| 437 | } |
| 438 | |
| 439 | // --------------------------------------------------------------------------- |
| 440 | // Revocation |