pub fn verify(secret: &[u8], message: &[u8], signature: &str) -> Result<()>Expand description
Checks that signature is the HMAC-SHA256 of message with secret,
in constant time. The signature may be hex (any case, optionally
prefixed sha256= as GitHub sends it) or base64 (standard or URL-safe,
padded or not), the common encodings of webhook providers. Sign the raw
request body: parsed and re-serialized JSON may differ by a space.
§Errors
Error::Unauthorized when the signature is missing, malformed or
does not match.
§Examples
use base64::Engine as _;
use ocre::webhooks::{sign, verify};
let hex = sign(b"secret", b"body");
assert!(verify(b"secret", b"body", &format!("sha256={hex}")).is_ok());
assert!(verify(b"other", b"body", &hex).is_err());