I am using SendGrid to receive event notifications when emails are delivered, clicked, etc.
They have this "verification" key that they give me and say they use ECDSA to generate public/private key pairs. They gave me a key without telling me what it is, I am assuming it is the public key.
So then when sending the data they give me a signature with a timestamp and the body.
I have the following NodeJS code but really don't know how to approach this. The example object in the buffer is what SG sends.
const ts = res.headers["X-Twilio-Email-Event-Webhook-Timestamp"];
const msg = Buffer.of(ts, [
{
"email": "iekchimzie1@gmail.com",
"event": "open",
"ip": "66.249.93.222",
"sg_content_type": "html",
"sg_event_id": "fRVFj9NaRPuLtgrTJcRZYA",
"sg_message_id": "DZqeK1BjQN-5yOUCykR7WQ.filterdrecv-p3iad2-8ddf98858-xxtk7-19-5EC1C6BE-4F.0",
"sg_template_id": "d-31ad8dd470384ad1aa6f4dc557f7ee65",
"sg_template_name": "Untitled_11565020537169",
"timestamp": 1590198073,
"useragent": "Mozilla/5.0 (Windows NT 5.1; rv:11.0) Gecko Firefox/11.0 (via ggpht.com GoogleImageProxy)"
}
]);
const shaMsg = crypto.createHash('sha256').update(msg).digest()
const isValid = ecdsa.verify(shaMsg, evSig, SG_WEBHOOK_V_KEY);