pub fn verify_envelope(
ring: &KeyRing,
body: &[u8],
headers: &SigHeaders,
my_pc_id: &str,
now: DateTime<Utc>,
) -> Result<VerifiedEnvelope, EnvelopeError>Expand description
Verify a received envelope. Pure: the clock is passed in, so the admission step and the tests can call it without a broker or a real clock.
Order matters. The signature is checked over the received bytes first, and only then is the body parsed strictly, so forged bytes cannot provoke a clock or recipient report. After that: kind, recipient, expiry presence, then the time checks (future skew, reversed, ceiling, expiry, key age).