|
StripeKit 0.1.1
Stripe integration toolkit for C++
|
The signature verifier StripeKit uses by default. More...
#include <WebhookVerifier.h>
Public Member Functions | |
| VerificationMetadata | verify (const WebhookVerificationInput &input) const override |
| Checks a signature and reports what it contained. | |
| Public Member Functions inherited from stripekit::WebhookSignatureVerifier | |
| virtual | ~WebhookSignatureVerifier ()=default |
| Destroys the verifier instance. | |
Static Public Member Functions | |
| static bool | is_available () |
| Reports whether this build can verify signatures. | |
The signature verifier StripeKit uses by default.
Implements Stripe's scheme: HMAC-SHA256 over the timestamp and payload, compared in constant time so the comparison itself leaks nothing.
Definition at line 94 of file WebhookVerifier.h.
|
overridevirtual |
Checks a signature and reports what it contained.
| input | The payload, signature header, secret, and timing rules. |
| SignatureVerificationException | The header is malformed, no signature matches, or the timestamp is outside the tolerance. |
| ConfigurationException | This build has no cryptography support. |
Implements stripekit::WebhookSignatureVerifier.
|
static |
Reports whether this build can verify signatures.
Verification needs libsodium, which is a build option. Without it, webhooks cannot be trusted and must not be accepted.