Skip to main content

Module webhook

Module webhook 

Source
Expand description

The generic webhook: stable JSON, signed with the channel’s secret.

Receivers verify X-CodoSEO-Signature: sha256=<hex> — an HMAC-SHA256 with the channel secret over {timestamp}.{body}, where timestamp is the X-CodoSEO-Timestamp header (unix seconds) and body the raw request body. Reject timestamps that are too old to stop replays.

Constants§

SIGNATURE_HEADER
TIMESTAMP_HEADER

Functions§

payload
{event, site, dashboard_url, crawl_id, changes: [...], more}. event is changes, unreachable or test; crawl_id is null for a test.
sign
sha256=<lowercase hex> over {timestamp}.{body}.
verify
Checks a signature header value in constant time.