stripe-pay-server
Server-side transport for the stripe-pay SDK family.
Overview
stripe-pay-server verifies that a webhook payload really came from Stripe, and builds the form bodies the Stripe API expects. It depends on stripe-pay-core for the shared domain types.
Webhook verification
Stripe signs "{timestamp}.{payload}" with HMAC-SHA256 and delivers the hex digest in the Stripe-Signature header alongside the timestamp. stripe-pay-server parses that header, enforces a timestamp tolerance, and compares digests in constant time so a forged request cannot learn how many leading bytes matched by timing the response.
use ;
let event = verify_webhook?;
Rejections are typed: MissingSignature, TimestampOutOfTolerance, EmptySecret, and SignatureMismatch.
Request bodies
encode_create_payment_intent, encode_create_refund, encode_confirm_payment_intent, and encode_create_customer produce percent-encoded bodies matching Stripe's application/x-www-form-urlencoded contract.
Usage
use ;
let digest = new
.compute_signature?;
Licence
MIT. See LICENSE.