basalt / drives/src / verifyHmacSignature
Function: verifyHmacSignature()
> verifyHmacSignature(input): boolean
Defined in: drives/src/notifications.ts:319
Constant-time HMAC check over a raw body — the Dropbox scheme, and the shape any signed provider uses.
Takes a Buffer, never a parsed object: re-serialising JSON changes the bytes (key order, whitespace, unicode escapes) and the signature stops matching for reasons nobody can debug. A route must therefore keep the raw body, which is why DriveNotificationInput.body is typed the way it is.
Parameters
input
algorithm?
string
body
Buffer
encoding?
"hex" | "base64"
secret
string
signature
string | undefined
Returns
boolean