verifyAndStrip function

Map<String, Object?> verifyAndStrip(
  1. Map<String, Object?> signed,
  2. String secret
)

Verifies a map produced by signExport and, if the checksum matches, returns the original data with checksumKey removed — ready to pass straight into StorageService.importAll().

Throws a FormatException if checksumKey is missing, or if the recomputed HMAC doesn't match (tampered/corrupted data). Callers should catch this and warn the player / refuse to import rather than silently importing unverified data.

Implementation

Map<String, Object?> verifyAndStrip(
  Map<String, Object?> signed,
  String secret,
) {
  if (!signed.containsKey(checksumKey)) {
    throw const FormatException(
      'Save file thiếu checksum — không thể xác minh tính toàn vẹn dữ liệu.',
    );
  }
  final storedChecksum = signed[checksumKey];
  final data = Map<String, Object?>.from(signed)..remove(checksumKey);
  if (_hmac(data, secret) != storedChecksum) {
    throw const FormatException(
      'Save file đã bị chỉnh sửa hoặc hỏng — checksum không khớp.',
    );
  }
  return data;
}