How do I verify a ECDSA signature?

Viewed 782

I am using SendGrid to receive event notifications when emails are delivered, clicked, etc.

They have this "verification" key that they give me and say they use ECDSA to generate public/private key pairs. They gave me a key without telling me what it is, I am assuming it is the public key.

So then when sending the data they give me a signature with a timestamp and the body.

https://sendgrid.com/docs/for-developers/tracking-events/getting-started-event-webhook-security-features/#manage-the-signed-event-webhook-using-the-api

I have the following NodeJS code but really don't know how to approach this. The example object in the buffer is what SG sends.

    const ts = res.headers["X-Twilio-Email-Event-Webhook-Timestamp"];


    const msg = Buffer.of(ts, [
        {
            "email": "iekchimzie1@gmail.com",
            "event": "open",
            "ip": "66.249.93.222",
            "sg_content_type": "html",
            "sg_event_id": "fRVFj9NaRPuLtgrTJcRZYA",
            "sg_message_id": "DZqeK1BjQN-5yOUCykR7WQ.filterdrecv-p3iad2-8ddf98858-xxtk7-19-5EC1C6BE-4F.0",
            "sg_template_id": "d-31ad8dd470384ad1aa6f4dc557f7ee65",
            "sg_template_name": "Untitled_11565020537169",
            "timestamp": 1590198073,
            "useragent": "Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko Firefox/11.0 (via ggpht.com GoogleImageProxy)"
        }
    ]);
    const shaMsg = crypto.createHash('sha256').update(msg).digest()

    const isValid = ecdsa.verify(shaMsg, evSig, SG_WEBHOOK_V_KEY);


0 Answers
Related