How can I disable laravel spatie signature?

Viewed 883

I am receiving a webhook from a node js server. Anytime the laravel webhook endpoint is hit by the node it returns the error `The signature is invalid.
How can I disable the default signature from laravel spatie or write my own signature? Or even better: how do I send a signature from the node server that will be accepted by laravel spatie?

1 Answers

If you are using laravel-webhook-client there's a section in their documentation that tells you how the signature is verified:

Verifying the signature of incoming webhooks This package assumes that an incoming webhook request has a header that can be used to verify the payload has not been tampered with. The name of the header containing the signature can be configured in the signature_header_name key of the config file. By default, the package uses the DefaultSignatureValidator to validate signatures. This is how that class will compute the signature.

$computedSignature = hash_hmac('sha256', $request->getContent(), $configuredSigningSecret); If the $computedSignature does match the value, the request will be passed to the webhook profile. If $computedSignature does not match the value in the signature header, the package will respond with a 500 and discard the request.

If you want to keep the signature verification in place, create a signature and add to the request header in Node using the mechanism as above.

If you don't want to ignore the signature, send a blank header and create your own SignatureValidator class along the lines of:

class YourSignatureValidator implements SpatieSignatureValidator {
  public function isValid(): bool {
    return true;
  }
}

Then point to that validator class in the configuration as mentioned here:

'signature_validator' => \App\YourSignatureValidator::class,
Related