hash($key, $input), $signature); } public function hash(JWK $key, string $input): string { $k = $this->getKey($key); return sodium_crypto_generichash($input, $k); } private function getKey(JWK $key): string { if (! in_array($key->get('kty'), $this->allowedKeyTypes(), true)) { throw new InvalidArgumentException('Wrong key type.'); } if (! $key->has('k')) { throw new InvalidArgumentException('The key parameter "k" is missing.'); } $k = $key->get('k'); if (! is_string($k)) { throw new InvalidArgumentException('The key parameter "k" is invalid.'); } $key = Base64UrlSafe::decode($k); if (mb_strlen($key, '8bit') < self::MINIMUM_KEY_LENGTH) { throw new InvalidArgumentException('Key provided is shorter than 256 bits.'); } return $key; } }