Verify a revocation against the delegator's public key. Only the delegator may revoke, so the signature must be theirs and the `delegator` field must name that same key.
(
document: &Value,
delegator_public_key: &PublicKey,
)
| 482 | /// Only the delegator may revoke, so the signature must be theirs and the |
| 483 | /// `delegator` field must name that same key. |
| 484 | pub fn verify_revocation( |
| 485 | document: &Value, |
| 486 | delegator_public_key: &PublicKey, |
| 487 | ) -> Result<DelegationRevocation> { |
| 488 | expect_type(document, TYPE_REVOCATION)?; |
| 489 | proof::verify_value(document, delegator_public_key)?; |
| 490 | |
| 491 | let obj = as_object(document)?; |
| 492 | let delegator = string_field(obj, "delegator")?; |
| 493 | let delegator_id = IdentityId::from_did(&delegator) |
| 494 | .map_err(|e| CanonicalError::Verification(format!("delegator DID is malformed: {e}")))?; |
| 495 | if !delegator_id.matches_public_key(delegator_public_key) { |
| 496 | return Err(CanonicalError::Verification( |
| 497 | "revocation delegator DID does not match the verifying key".into(), |
| 498 | )); |
| 499 | } |
| 500 | |
| 501 | Ok(DelegationRevocation { |
| 502 | delegation: string_field(obj, "delegation")?, |
| 503 | delegator, |
| 504 | revoked_at: timestamp_field(obj, "revokedAt")?, |
| 505 | reason: obj |
| 506 | .get("reason") |
| 507 | .and_then(Value::as_str) |
| 508 | .map(str::to_string), |
| 509 | }) |
| 510 | } |
| 511 | |
| 512 | // --------------------------------------------------------------------------- |
| 513 | // Store-backed lookup |