Crear cuenta

Verificar la firma

Comprueba que cada aviso viene de Closeford.

Calcula el HMAC-SHA256 del timestamp y el cuerpo sin procesar con tu secreto de firma, y compáralo con la cabecera X-Webhook-Signature antes de aceptar el aviso.

import crypto from "node:crypto";

// raw = the request body as received (string), before JSON.parse
export function verify(raw, headers, secret) {
  const ts = headers["x-webhook-timestamp"];
  const expected = "sha256=" + crypto
    .createHmac("sha256", secret)
    .update(`${ts}.${raw}`)
    .digest("hex");
  const got = headers["x-webhook-signature"] ?? "";
  return got.length === expected.length &&
    crypto.timingSafeEqual(Buffer.from(got), Buffer.from(expected));
}