Skip to content

feat(webhooks): export verifyWebhookSignature as standalone with error class (#617) - #812

Open
ZacLou wants to merge 4 commits into
Stellar-split:mainfrom
ZacLou:feat/verify-webhook-signature-617
Open

feat(webhooks): export verifyWebhookSignature as standalone with error class (#617)#812
ZacLou wants to merge 4 commits into
Stellar-split:mainfrom
ZacLou:feat/verify-webhook-signature-617

Conversation

@ZacLou

@ZacLou ZacLou commented Sep 5, 2026

Copy link
Copy Markdown

Closes #617

What

Exposes webhook signature verification as a first-class, standalone SDK export with a dedicated error type.

Changes

  • verifyWebhookSignature(payload, signature, secret): boolean — HMAC-SHA256 with crypto.timingSafeEqual
  • verifyWebhookSignatureOrThrow — wrapper that throws WebhookVerificationError on mismatch
  • WebhookVerificationError — typed error for consumers who prefer throwing over boolean returns
  • All exported from src/index.ts alongside existing webhook middleware
  • 7 unit tests: valid signature, wrong secret, tampered payload, malformed hex, length mismatch, never-throws, error class behavior

Verification

  • Unit tests in test/webhookVerify.test.ts

ZacLou added 4 commits September 6, 2026 02:08
…it#612)

- generateIdempotencyKey: deterministic SHA-256 hex key from invoiceId, payer, amount
- isKnownKey / registerKey / clearKeys: in-memory Set-backed registry
- Exported from index.ts alongside existing Deduplicator
- Unit tests: determinism, input sensitivity, nonce variation, registry lifecycle

Closes Stellar-split#612
…#614)

- searchByMemo(invoices, query, opts?) filters invoices by memo substring
- case-insensitive by default; opts.caseSensitive=true for exact case
- empty query returns all invoices unchanged
- invoices with undefined/null memo are skipped without error
- 6 unit tests covering all acceptance criteria

Closes Stellar-split#614
…r class (Stellar-split#617)

- verifyWebhookSignature(payload, signature, secret): boolean — HMAC-SHA256 with timing-safe comparison
- verifyWebhookSignatureOrThrow: wrapper that throws WebhookVerificationError
- WebhookVerificationError: typed error for consumers who prefer throwing
- Exported from src/index.ts alongside existing webhookMiddleware exports
- 7 unit tests covering valid/invalid signatures, tampered payloads, malformed input, and error class

Closes Stellar-split#617
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Export verifyWebhookSignature as standalone function from webhooks/verify.ts

1 participant