Verificar la firma
Comprueba que cada aviso viene de Closeford.
Calcula el HMAC-SHA256 del timestamp y el cuerpo sin procesar con tu secreto de firma, y compáralo con la cabecera X-Webhook-Signature antes de aceptar el aviso.
import crypto from "node:crypto";
// raw = the request body as received (string), before JSON.parse
export function verify(raw, headers, secret) {
const ts = headers["x-webhook-timestamp"];
const expected = "sha256=" + crypto
.createHmac("sha256", secret)
.update(`${ts}.${raw}`)
.digest("hex");
const got = headers["x-webhook-signature"] ?? "";
return got.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(got), Buffer.from(expected));
}