pub struct WebhookEvent { /* private fields */ }Expand description
A webhook payload whose signature Stripe vouches for.
The struct keeps the three values verification actually needs, so a handler never has to re-parse the header once this is built.
Read accessors are generated by #[derive(Getter)]. The digest is
only meaningful together with the payload and timestamp it was
computed over, so it is exposed read-only: a caller that could
replace the signature independently of the other two could make a
forged event verify against its own digest.
Implementations§
Source§impl WebhookEvent
impl WebhookEvent
Sourcepub fn new(payload: String, timestamp: i64, signature: String) -> Self
pub fn new(payload: String, timestamp: i64, signature: String) -> Self
Build a verification target from the three webhook inputs.
The signature is the bare hex digest, not the whole
Stripe-Signature header; parse_signature_header extracts it.
§Arguments
String- the exact request body Stripe signed.i64- the timestamp Stripe signed, in seconds.String- the hex digest Stripe sent.
§Returns
Self- the assembled verification target.
Sourcepub fn compute_signature(&self, secret: &str) -> Result<String, WebhookError>
pub fn compute_signature(&self, secret: &str) -> Result<String, WebhookError>
Sign the payload the way Stripe does.
Stripe signs the timestamp and the payload joined by a dot, then HMAC-SHA256 hex-encodes the digest, so this builds that exact signed text before hashing.
§Arguments
&str- the endpoint’s webhook signing secret.
§Returns
Result<String, WebhookError>- the hex digest Stripe would have sent, or an error when the secret is empty.
Sourcepub fn is_timestamp_fresh(&self, now: i64, tolerance: i64) -> bool
pub fn is_timestamp_fresh(&self, now: i64, tolerance: i64) -> bool
Return whether the timestamp sits within tolerance of now.
Stripe recommends rejecting anything outside a five-minute window so a captured request cannot be replayed later.
§Arguments
i64- the current time in seconds since the epoch.i64- the accepted drift, in seconds.
§Returns
bool-truewhen the timestamp is inside the window.
Sourcepub fn verify_signature(&self, secret: &str) -> Result<(), WebhookError>
pub fn verify_signature(&self, secret: &str) -> Result<(), WebhookError>
Sourcepub fn parse_signature_header(
header: &str,
payload: &str,
) -> Result<WebhookEvent, WebhookError>
pub fn parse_signature_header( header: &str, payload: &str, ) -> Result<WebhookEvent, WebhookError>
Split a Stripe-Signature header into its timestamp and digest.
Stripe sends comma-separated entries such as
t=1614556800,v1=deadbeef,v0=ignored. The v0 entry is the
legacy scheme and v1 is the current one, so only v1 is
accepted; a header carrying no v1 entry is rejected rather
than downgraded.
§Arguments
&str- the rawStripe-Signatureheader value.&str- the exact request body Stripe signed.
§Returns
Result<WebhookEvent, WebhookError>- the verification target, orMissingSignaturewhen no timestamp orv1digest was present.
Sourcepub fn secret_from_env() -> Result<String, WebhookError>
pub fn secret_from_env() -> Result<String, WebhookError>
Read the webhook signing secret from the process environment.
§Returns
Result<String, WebhookError>- the configured secret, orEmptySecretwhen the variable is unset or blank.
Sourcepub fn verify_webhook(
header: &str,
payload: &str,
secret: &str,
now: i64,
tolerance: i64,
) -> Result<WebhookEvent, WebhookError>
pub fn verify_webhook( header: &str, payload: &str, secret: &str, now: i64, tolerance: i64, ) -> Result<WebhookEvent, WebhookError>
Verify a raw webhook request end to end.
This is the entry point a hyperlane handler calls: it parses the header, then checks freshness and the digest.
§Arguments
&str- the rawStripe-Signatureheader value.&str- the exact request body Stripe signed.&str- the endpoint’s webhook signing secret.i64- the current time in seconds since the epoch.i64- the accepted drift, in seconds.
§Returns
Result<WebhookEvent, WebhookError>- the verified event.