Class: SpreeDoordash::WebhookVerifier
- Inherits:
-
Object
- Object
- SpreeDoordash::WebhookVerifier
- Defined in:
- app/services/spree_doordash/webhook_verifier.rb
Overview
Verifies inbound DoorDash webhooks. Architecturally different from SpreeSquare::WebhookVerifier: DoorDash has no HMAC signing scheme for webhooks. Per DoorDash's own docs (Configure your webhook in the Portal): Basic Auth here means "enter the contents you'd like DoorDash to send in the HTTP Authorization header" — a static string DoorDash echoes back verbatim on every call, not a credential DoorDash itself authenticates. Comparison is still constant-time to avoid a timing oracle on that string.
Class Method Summary collapse
Class Method Details
.valid?(authorization_header:, expected_token:) ⇒ Boolean
11 12 13 14 15 |
# File 'app/services/spree_doordash/webhook_verifier.rb', line 11 def self.valid?(authorization_header:, expected_token:) return false if .blank? || expected_token.blank? ActiveSupport::SecurityUtils.secure_compare(, expected_token) end |