Takes delivery of a pushed SET at a surface's receive endpoint: checks the
stream's authorization header, then records the SET in the inbox and checks
that it reads as a SET, its typ, issuer and audience, and its signature
(required in product mode or with ssf.receiveRequireSignature). Only a
SET that passed every check is acted on, and only as policy allows.
It sends nothing. A refusal carries RFC 8935 section 2.4's { err, description }, with 400 for a bad SET.
Parameters
OptionalsurfaceId: any
the surface's id
Optionalreq: any
the incoming request
Returns Loose
{ status, body, entry }: 202 with the entry on success
Takes delivery of a pushed SET at a surface's receive endpoint: checks the stream's authorization header, then records the SET in the inbox and checks that it reads as a SET, its
typ, issuer and audience, and its signature (required in product mode or withssf.receiveRequireSignature). Only a SET that passed every check is acted on, and only as policy allows.It sends nothing. A refusal carries RFC 8935 section 2.4's
{ err, description }, with 400 for a bad SET.