Skip to main content

verify

Function verify 

Source
pub fn verify(secret: &[u8], message: &[u8], signature: &str) -> Result<()>
Expand description

Checks that signature is the HMAC-SHA256 of message with secret, in constant time. The signature may be hex (any case, optionally prefixed sha256= as GitHub sends it) or base64 (standard or URL-safe, padded or not), the common encodings of webhook providers. Sign the raw request body: parsed and re-serialized JSON may differ by a space.

§Errors

Error::Unauthorized when the signature is missing, malformed or does not match.

§Examples

use base64::Engine as _;
use ocre::webhooks::{sign, verify};

let hex = sign(b"secret", b"body");
assert!(verify(b"secret", b"body", &format!("sha256={hex}")).is_ok());
assert!(verify(b"other", b"body", &hex).is_err());