Documentation
¶
Overview ¶
Package jws parses compact JWS strictly, for the JWTs clients sign with their own keys (DPoP proofs, jwt-bearer assertions, device-key capabilities): duplicate members, non-objects and trailing JSON are refused, and only the algorithm each caller names verifies.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrInvalid = errors.New("invalid JWS")
ErrInvalid is any malformed or unverified JWS.
Functions ¶
func Object ¶
func Object(raw []byte) (map[string]json.RawMessage, error)
Object decodes one JSON object, refusing duplicate members, any other value and trailing JSON.
func String ¶
func String(raw json.RawMessage) string
String is raw's string value; "" for anything else.
Types ¶
type Parsed ¶
type Parsed struct {
Header, Claims map[string]json.RawMessage
// contains filtered or unexported fields
}
Parsed is a compact JWS split and decoded, not yet verified.
func (Parsed) VerifyEdDSA ¶
VerifyEdDSA verifies an EdDSA (Ed25519) signature by key.
func (Parsed) VerifyEmbeddedES256 ¶
VerifyEmbeddedES256 verifies an ES256 signature by the public P-256 key the header carries (jwk: exactly kty, crv, x and y), and returns the key's RFC 7638 thumbprint (unpadded base64url). It proves possession of that key, nothing else.