MCPcopy Create free account
hub / github.com/atomicdotdev/atomic / verify_revocation

Function verify_revocation

atomic-canonical/src/delegation.rs:484–510  ·  view source on GitHub ↗

Verify a revocation against the delegator's public key. Only the delegator may revoke, so the signature must be theirs and the `delegator` field must name that same key.

(
    document: &Value,
    delegator_public_key: &PublicKey,
)

Source from the content-addressed store, hash-verified

482/// Only the delegator may revoke, so the signature must be theirs and the
483/// `delegator` field must name that same key.
484pub fn verify_revocation(
485 document: &Value,
486 delegator_public_key: &PublicKey,
487) -> Result<DelegationRevocation> {
488 expect_type(document, TYPE_REVOCATION)?;
489 proof::verify_value(document, delegator_public_key)?;
490
491 let obj = as_object(document)?;
492 let delegator = string_field(obj, "delegator")?;
493 let delegator_id = IdentityId::from_did(&delegator)
494 .map_err(|e| CanonicalError::Verification(format!("delegator DID is malformed: {e}")))?;
495 if !delegator_id.matches_public_key(delegator_public_key) {
496 return Err(CanonicalError::Verification(
497 "revocation delegator DID does not match the verifying key".into(),
498 ));
499 }
500
501 Ok(DelegationRevocation {
502 delegation: string_field(obj, "delegation")?,
503 delegator,
504 revoked_at: timestamp_field(obj, "revokedAt")?,
505 reason: obj
506 .get("reason")
507 .and_then(Value::as_str)
508 .map(str::to_string),
509 })
510}
511
512// ---------------------------------------------------------------------------
513// Store-backed lookup

Callers 1

revocation_round_tripsFunction · 0.85

Calls 7

expect_typeFunction · 0.85
verify_valueFunction · 0.85
as_objectFunction · 0.85
string_fieldFunction · 0.85
timestamp_fieldFunction · 0.85
matches_public_keyMethod · 0.80
getMethod · 0.65

Tested by 1

revocation_round_tripsFunction · 0.68