Skip to content

basalt / drives/src / verifyHmacSignature

Function: verifyHmacSignature() ​

> verifyHmacSignature(input): boolean

Defined in: drives/src/notifications.ts:319

Constant-time HMAC check over a raw body — the Dropbox scheme, and the shape any signed provider uses.

Takes a Buffer, never a parsed object: re-serialising JSON changes the bytes (key order, whitespace, unicode escapes) and the signature stops matching for reasons nobody can debug. A route must therefore keep the raw body, which is why DriveNotificationInput.body is typed the way it is.

Parameters ​

input ​

algorithm? ​

string

body ​

Buffer

encoding? ​

"hex" | "base64"

secret ​

string

signature ​

string | undefined

Returns ​

boolean

Released under the MIT License.