Node.js开发Coinegg客户端遭遇API签名问题求助
Let's break down what's going wrong with your Coinegg signature implementation and fix it step by step. First, let's clarify the official signature rules to eliminate ambiguity:
signature -- Parameters like "amount", "price", "type", "nonce", "key" will be combined by '&' to create a new string, encrypt the new string by Sha256 algorithm, key is md5(private key)
Key Misunderstandings in Your Current Code
Your implementation has two critical issues that are causing invalid signatures:
- Incorrect signature string format: You're using
qs.stringify(data)which produces akey=value&key=valuestring, but the API requires you to concatenate the values of the specified parameters with&(not the full key-value pairs). - Wrong encoding in hash updates: You're passing
'base64'as the encoding toupdate(), but both your private key and the signature string are plain UTF-8 text, not base64-encoded.
Correct Implementation with Node.js crypto
Here's the fixed code that aligns perfectly with Coinegg's rules:
const crypto = require('crypto'); const getMessageSignature = (params, privateKey) => { // Step 1: Generate MD5 hash of your private key (returned as hex string) const md5Secret = crypto.createHash('md5') .update(privateKey, 'utf8') .digest('hex'); // Step 2: Concatenate values of required parameters in the EXACT ORDER specified // Follow this sequence: amount, price, type, nonce, key const signatureString = [ params.amount, params.price, params.type, params.nonce, params.key ].join('&'); // Step 3: Create HMAC-SHA256 signature using the MD5 secret const hmac = crypto.createHmac('sha256', md5Secret) .update(signatureString, 'utf8') .digest('hex'); return hmac; };
Edge Case Notes
- If an API endpoint doesn't require one of the parameters (e.g., no
pricefor a market order), you still need to include an empty string in its position to maintain the required order. For example:[params.amount, '', params.type, params.nonce, params.key].join('&') - Ensure your
nonceis a unique, incrementing value for every request—this is a standard requirement for most crypto exchange APIs to prevent replay attacks.
Alternative Implementation with crypto-js
If you prefer using crypto-js instead of Node's built-in crypto, here's the equivalent working code:
const CryptoJS = require('crypto-js'); const getMessageSignature = (params, privateKey) => { // MD5 hash of private key const md5Secret = CryptoJS.MD5(privateKey).toString(); // Build signature string from parameter values const signatureString = [ params.amount, params.price, params.type, params.nonce, params.key ].join('&'); // Generate HMAC-SHA256 signature const hmac = CryptoJS.HmacSHA256(signatureString, md5Secret); return CryptoJS.enc.Hex.stringify(hmac); };
Quick Verification Test
To confirm your code works, use sample values to compute manually:
- Take test parameters:
amount=1,price=100,type=buy,nonce=12345,key=your_public_key,privateKey=your_private_key - Compute MD5 of your private key first, then HMAC-SHA256 the string
1&100&buy&12345&your_public_keywith that MD5 hash. - Compare the result with your code's output—they should match exactly.
内容的提问来源于stack exchange,提问作者Philip

