Says whether a signature verifies under a COSE algorithm, synchronously; a key of the wrong kind is false, never a throw.
the COSE algorithm identifier
the public key, or for ML-DSA an AKP JWK or the raw bytes
the bytes signed
the signature
allowInsecure: accept an algorithm marked insecure (RS1); refused otherwise
allowInsecure
true when it verifies
Says whether a signature verifies under a COSE algorithm, synchronously; a key of the wrong kind is false, never a throw.