Skip to content

basalt / audit/src / checkAuditHash

Function: checkAuditHash() ​

> checkAuditHash(entry, keys): "hash-mismatch" | "unknown-key" | "ok"

Defined in: audit/src/chain.ts:228

Checks an entry's stored hash against the keys a verifier holds, keyed by id (empty = an unkeyed chain):

  • v2 hmac-sha256 — recomputed under the key its id names; 'unknown-key' when the verifier does not hold that id.
  • v2 sha256 — accepted only by an unkeyed verifier. A keyed verifier refuses it as 'hash-mismatch': anyone can compute a plain SHA-256, so accepting one would let a writer without the key extend or rewrite the chain.
  • v1 — an unkeyed verifier recomputes the SHA-256; a keyed one accepts the HMAC under ANY key it holds (v1 never recorded which).

Parameters ​

entry ​

AuditEntry

keys ​

ReadonlyMap<string, AuditIntegrityKey>

Returns ​

"hash-mismatch" | "unknown-key" | "ok"

Released under the MIT License.