We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 9ea7705 commit f6e9bfeCopy full SHA for f6e9bfe
messages/signed-webhooks/verify-signed-webhook.js
@@ -16,7 +16,7 @@ function handleInboundMessage(request, response){
16
let token = request.headers.authorization.split(" ")[1]
17
try{
18
var decoded = jwt.verify(token, NEXMO_API_SIGNATURE_SECRET, {algorithms:['HS256']});
19
- if(sha256(JSON.stringify(payload))!=decoded["payload_body"]){
+ if(sha256(JSON.stringify(payload))!=decoded["payload_hash"]){
20
console.log("tampering detected");
21
response.status(401).send();
22
}
0 commit comments