Function verifyEncKeyBinding

  • Anti-MITM re-verification: before sealing to a public encryption key served by the directory, the sealer re-derives the binding from the args (never trusts a passed-in string) and checks the recipient's Ed25519 signature over it. If the directory swapped the lock, this fails. Mirrors verify_enc_key_binding in sealed_field.rs.

    Parameters

    • workspaceId: string
    • encKeyId: string
    • encPubkeyB64: string
    • ed25519SigB64: string
    • ed25519PubB64: string

    Returns boolean