HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulejose-jwt-0.10.0Haskell2010

Jose.Internal.Crypto

Internal functions for encrypting and signing / decrypting and verifying JWT content.

  • 16 values
  • Packagejose-jwt-0.10.0
  • Exports16
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceCrypto.hs
valuehmacVerify
  1. :: JwsAlg

    HMAC Algorithm to use

  2. -> ByteString

    Key

  3. -> ByteString

    The message/content

  4. -> ByteString

    The signature to check

  5. -> Bool

    Whether the signature is correct

#

Verify the HMAC for a given message. Returns false if the MAC is incorrect or the Alg is not an HMAC.

valuersaSign
  1. :: Maybe Blinder

    RSA blinder

  2. -> JwsAlg

    Algorithm to use. Must be one of RSA256, RSA384 or RSA512

  3. -> PrivateKey

    Private key to sign with

  4. -> ByteString

    Message to sign

  5. -> Either JwtError ByteString

    The signature

#

Sign a message using an RSA private key.

The failure condition should only occur if the algorithm is not an RSA algorithm, or the RSA key is too small, causing the padding of the signature to fail. With real-world RSA keys this shouldn't happen in practice.

valuersaVerify
  1. :: JwsAlg

    The signature algorithm. Used to obtain the hash function.

  2. -> PublicKey

    The key to check the signature with

  3. -> ByteString

    The message/content

  4. -> ByteString

    The signature to check

  5. -> Bool

    Whether the signature is correct

#

Verify the signature for a message using an RSA public key.

Returns false if the check fails or if the Alg value is not an RSA signature algorithm.

valueecVerify
  1. :: JwsAlg

    The signature algorithm. Used to obtain the hash function.

  2. -> PublicKey

    The key to check the signature with

  3. -> ByteString

    The message/content

  4. -> ByteString

    The signature to check

  5. -> Bool

    Whether the signature is correct

#

Verify the signature for a message using an EC public key.

Returns false if the check fails or if the Alg value is not an EC signature algorithm.

valuedecryptPayload
  1. :: ByteArray ba
  2. => Enc

    Encryption algorithm

  3. -> ScrubbedBytes

    Content encryption key

  4. -> IV

    IV

  5. -> ba

    Additional authentication data

  6. -> Tag

    The integrity protection value to be checked

  7. -> ba

    The encrypted JWT payload

  8. -> Maybe ba
#

Decrypt an AES encrypted message.