如何用Python实现Acuity Webhook签名验证?现有代码验证失败
Acuity Webhook签名验证问题
Acuity Webhook文档中说明了验证Webhook来源是否为Acuity的步骤:
首先以请求正文为消息、API密钥为共享密钥,计算通知的base64
HMAC-SHA256签名,再将其与请求头X-Acuity-Signature对比,匹配则通知可信。
文档提供了PHP、JavaScript和Ruby的代码示例,但未说明变量来源,导致我无法完成消息验证。以下是我使用的Python代码:
acuity_api_key = 'redacted' key_bytes = acuity_api_key.encode('utf-8') signature = request.headers['x-acuity-signature'] message = request.body message_bytes = message.encode('utf-8') signed_body = base64.b64encode( hmac.new(key_bytes, message_bytes, hashlib.sha256).digest() ).decode('utf-8') if signature != signed_body: raise RuntimeError('Failed to validate message signature')
内容的提问来源于stack exchange,提问作者CoatedMoose
相关产品推荐
相关产品推荐

