MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / verify_request

Function verify_request

atomic-canonical/src/delegation.rs:408–437  ·  view source on GitHub ↗

Verify a delegation request's self-signature. The verifying key comes out of the document itself (`delegateKey`), which is exactly what makes this proof of *possession* and nothing more: it shows whoever produced the document holds the private half of the key it names. It carries no authority on its own — the human's countersignature does.

(document: &Value)

Source from the content-addressed store, hash-verified

406/// whoever produced the document holds the private half of the key it names. It
407/// carries no authority on its own — the human's countersignature does.
408pub fn verify_request(document: &Value) -> Result<DelegationRequest> {
409 expect_type(document, TYPE_REQUEST)?;
410 let obj = as_object(document)?;
411
412 let delegate_key_did = string_field(obj, "delegateKey")?;
413 let public_key = PublicKey::from_did_key(&delegate_key_did)
414 .map_err(|e| CanonicalError::Proof(format!("malformed delegateKey: {e}")))?;
415
416 proof::verify_value(document, &public_key)?;
417
418 let delegate = string_field(obj, "delegate")?;
419 let delegate_id = IdentityId::from_did(&delegate)
420 .map_err(|e| CanonicalError::Verification(format!("delegate DID is malformed: {e}")))?;
421 if !delegate_id.matches_public_key(&public_key) {
422 return Err(CanonicalError::Verification(
423 "delegateKey does not match the delegate DID".into(),
424 ));
425 }
426
427 Ok(DelegationRequest {
428 delegate,
429 delegate_key: delegate_key_did,
430 delegate_name: string_field(obj, "delegateName")?,
431 software_agent: obj
432 .get("softwareAgent")
433 .and_then(Value::as_str)
434 .map(str::to_string),
435 requested: timestamp_field(obj, "requested")?,
436 })
437}
438
439// ---------------------------------------------------------------------------
440// Revocation

Calls 8

expect_typeFunction · 0.85
as_objectFunction · 0.85
string_fieldFunction · 0.85
ProofClass · 0.85
verify_valueFunction · 0.85
timestamp_fieldFunction · 0.85
matches_public_keyMethod · 0.80
getMethod · 0.65

Tested by 1