Skip to content

Support notification signature validation #9

@judgej

Description

@judgej

The notification message comes with a signature in the header, for example:

X-Anet-Signature: sha512=8EB900743516AC9415516FF0A1813BB38FBB5CCE6D4256B3FC56BD1FE661258F8CEF6AED0899B9095DFB66596E3F71340CD7A0BB44930618D383266242C70499

This should be used to validate the notification has not been tampered with.

Some details:

The documentation does lack some details about how the notification is actually verified. I think the SDK is probably the main source of information for this.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions