如何在C#中验证Tillo Webhook的PSS签名
Tillo Webhook签名验证C#实现始终失败,求排查
我正在集成Tillo的签名Webhook,官方仅提供Python和PHP的签名验证示例,但我需要用C#实现。目前基于BouncyCastle.Cryptography和Microsoft.Bcl.Cryptography库(.NET 9.0.1)编写了代码,但签名验证始终返回isValid=false,自己无法定位问题。
相关信息如下:
我的非工作代码
using System; using System.Text; using System.Security.Cryptography; using Org.BouncyCastle.Crypto; using Org.BouncyCastle.Crypto.Parameters; using Org.BouncyCastle.Security; public class TilloWebhookValidator { public bool ValidateSignature(string payload, string signature, string secretKey) { try { var secretBytes = Encoding.UTF8.GetBytes(secretKey); var payloadBytes = Encoding.UTF8.GetBytes(payload); var hmac = new HMACSHA256(secretBytes); var computedHash = hmac.ComputeHash(payloadBytes); var computedSignature = Convert.ToBase64String(computedHash); return computedSignature == signature; } catch (Exception ex) { Console.WriteLine(ex.Message); return false; } } }
测试Payload
{ "event_type": "transaction.succeeded", "transaction_id": "txn_123456789", "amount": 5000, "currency": "GBP" }
请求头中的签名字段
X-Tillo-Signature: v1=abcdef1234567890abcdef1234567890abcdef1234567890abcdef1234567890
麻烦帮忙排查签名验证失败的原因,或者提供一个可正常工作的C#实现方案。
内容的提问来源于stack exchange,提问作者Elliveny
相关产品推荐
相关产品推荐

