feat(webhooks): export verifyWebhookSignature as standalone with error class (#617) - #812
Open
ZacLou wants to merge 4 commits into
Open
feat(webhooks): export verifyWebhookSignature as standalone with error class (#617)#812ZacLou wants to merge 4 commits into
ZacLou wants to merge 4 commits into
Conversation
added 4 commits
September 6, 2026 02:08
…it#612) - generateIdempotencyKey: deterministic SHA-256 hex key from invoiceId, payer, amount - isKnownKey / registerKey / clearKeys: in-memory Set-backed registry - Exported from index.ts alongside existing Deduplicator - Unit tests: determinism, input sensitivity, nonce variation, registry lifecycle Closes Stellar-split#612
…#614) - searchByMemo(invoices, query, opts?) filters invoices by memo substring - case-insensitive by default; opts.caseSensitive=true for exact case - empty query returns all invoices unchanged - invoices with undefined/null memo are skipped without error - 6 unit tests covering all acceptance criteria Closes Stellar-split#614
…r class (Stellar-split#617) - verifyWebhookSignature(payload, signature, secret): boolean — HMAC-SHA256 with timing-safe comparison - verifyWebhookSignatureOrThrow: wrapper that throws WebhookVerificationError - WebhookVerificationError: typed error for consumers who prefer throwing - Exported from src/index.ts alongside existing webhookMiddleware exports - 7 unit tests covering valid/invalid signatures, tampered payloads, malformed input, and error class Closes Stellar-split#617
… add WebhookVerificationError (Stellar-split#617)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #617
What
Exposes webhook signature verification as a first-class, standalone SDK export with a dedicated error type.
Changes
verifyWebhookSignature(payload, signature, secret): boolean— HMAC-SHA256 withcrypto.timingSafeEqualverifyWebhookSignatureOrThrow— wrapper that throwsWebhookVerificationErroron mismatchWebhookVerificationError— typed error for consumers who prefer throwing over boolean returnssrc/index.tsalongside existing webhook middlewareVerification
test/webhookVerify.test.ts