stripe-pay-server 10.2.3

Server-side transport for the Stripe payment SDK: signed webhook verification with constant-time comparison.
Documentation
use super::*;

/// A webhook payload whose signature Stripe vouches for.
///
/// The struct keeps the three values verification actually needs, so a
/// handler never has to re-parse the header once this is built.
///
/// Read accessors are generated by `#[derive(Getter)]`. The digest is
/// only meaningful together with the payload and timestamp it was
/// computed over, so it is exposed read-only: a caller that could
/// replace the signature independently of the other two could make a
/// forged event verify against its own digest.
#[derive(Clone, Debug, Eq, Getter, PartialEq)]
pub struct WebhookEvent {
    /// The exact bytes Stripe signed.
    pub(super) payload: String,
    /// The timestamp Stripe signed, in seconds since the epoch.
    #[get(type(copy))]
    pub(super) timestamp: i64,
    /// The hex digest Stripe sent, without the `v1=` prefix.
    pub(super) signature: String,
}