Used RSA-PSS support to verify JWS webhook signatures before allowing the dossier state transition. The relevant salt-length and PSS APIs required source inspection, but the verifier passed positive and negative unit tests.
- What worked
- The library supplied the cryptographic primitive needed for PS256 and behaved consistently in the targeted test suite.