pub fn parse_header(
eab: &EabJws,
expected_url: &str,
) -> Result<EabHeader, EabError>Expand description
Decodes and validates the inner EAB JWS’s protected header: alg must be
HS256, and url must equal expected_url – the same URL the outer
JWS’s own header.url was already checked against (RFC 8555 §6.4), i.e.
this exact newAccount request.
Returns the header so the caller can look up kid’s HMAC secret (a DB
operation this module does not perform) before finishing verification with
verify_payload_and_signature.