verifySignedFixture function
SdkResult<Map<String, Object?> >
verifySignedFixture(
- RemoteSchemaDef schema,
- Map<
String, Object?> signedEnvelope, - String secret
Verifies a fetched/authored signedEnvelope the same way
RemoteContentPack does at runtime: HMAC signature via
save_integrity.dart's verifyAndStrip, then rejects a schemaVersion
newer than schema's RemoteSchemaDef.current — a downgraded compiler
run must never bake content shaped for a future schema into generated
fixtures. Returns SdkFailure (never throws) on any problem so a CLI
caller can report it and refuse to generate anything from it.
Implementation
SdkResult<Map<String, Object?>> verifySignedFixture(
RemoteSchemaDef schema,
Map<String, Object?> signedEnvelope,
String secret,
) {
final Map<String, Object?> verified;
try {
verified = verifyAndStrip(signedEnvelope, secret);
} on FormatException catch (e) {
return SdkFailure(
kind: SdkErrorKind.validation,
message: 'signature invalid: ${e.message}',
);
}
final storedVersion = asIntOr(verified['schemaVersion'], 0);
if (storedVersion > schema.current.version) {
return SdkFailure(
kind: SdkErrorKind.validation,
message:
'fixture schemaVersion $storedVersion is newer than compiled '
'schema ${schema.current.version}',
);
}
return SdkSuccess(verified);
}