PluginProbe
GiveWP – Donation Plugin and Fundraising Platform / 4.15.4
GiveWP – Donation Plugin and Fundraising Platform v4.15.4
4.16.9 4.16.8.1 4.16.8 4.16.7.2 4.16.7.1 4.16.7 4.16.6.1 4.16.6 4.16.5.1 4.16.5 4.16.4 4.16.3 4.16.2 4.16.1 4.16.0 4.15.5 4.15.4 4.15.3 4.15.2 4.15.1 4.15.0 2.3.0 2.3.1 2.3.2 2.30.0 All 255 releases
give / vendor / stripe / stripe-php / lib / WebhookSignature.php

WebhookSignature.php in GiveWP – Donation Plugin and Fundraising Platform 4.15.4, at vendor/stripe/stripe-php/lib/WebhookSignature.php

141 lines 4.3 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 <?php
2
3 namespace Stripe;
4
5 abstract class WebhookSignature
6 {
7 const EXPECTED_SCHEME = 'v1';
8
9 /**
10 * Verifies the signature header sent by Stripe. Throws an
11 * Exception\SignatureVerificationException exception if the verification fails for
12 * any reason.
13 *
14 * @param string $payload the payload sent by Stripe
15 * @param string $header the contents of the signature header sent by
16 * Stripe
17 * @param string $secret secret used to generate the signature
18 * @param int $tolerance maximum difference allowed between the header's
19 * timestamp and the current time
20 *
21 * @throws Exception\SignatureVerificationException if the verification fails
22 *
23 * @return bool
24 */
25 public static function verifyHeader($payload, $header, $secret, $tolerance = null)
26 {
27 // Extract timestamp and signatures from header
28 $timestamp = self::getTimestamp($header);
29 $signatures = self::getSignatures($header, self::EXPECTED_SCHEME);
30 if (-1 === $timestamp) {
31 throw Exception\SignatureVerificationException::factory(
32 'Unable to extract timestamp and signatures from header',
33 $payload,
34 $header
35 );
36 }
37 if (empty($signatures)) {
38 throw Exception\SignatureVerificationException::factory(
39 'No signatures found with expected scheme',
40 $payload,
41 $header
42 );
43 }
44
45 // Check if expected signature is found in list of signatures from
46 // header
47 $signedPayload = "{$timestamp}.{$payload}";
48 $expectedSignature = self::computeSignature($signedPayload, $secret);
49 $signatureFound = false;
50 foreach ($signatures as $signature) {
51 if (Util\Util::secureCompare($expectedSignature, $signature)) {
52 $signatureFound = true;
53
54 break;
55 }
56 }
57 if (!$signatureFound) {
58 throw Exception\SignatureVerificationException::factory(
59 'No signatures found matching the expected signature for payload',
60 $payload,
61 $header
62 );
63 }
64
65 // Check if timestamp is within tolerance
66 if (($tolerance > 0) && (\abs(\time() - $timestamp) > $tolerance)) {
67 throw Exception\SignatureVerificationException::factory(
68 'Timestamp outside the tolerance zone',
69 $payload,
70 $header
71 );
72 }
73
74 return true;
75 }
76
77 /**
78 * Extracts the timestamp in a signature header.
79 *
80 * @param string $header the signature header
81 *
82 * @return int the timestamp contained in the header, or -1 if no valid
83 * timestamp is found
84 */
85 private static function getTimestamp($header)
86 {
87 $items = \explode(',', $header);
88
89 foreach ($items as $item) {
90 $itemParts = \explode('=', $item, 2);
91 if ('t' === $itemParts[0]) {
92 if (!\is_numeric($itemParts[1])) {
93 return -1;
94 }
95
96 return (int) ($itemParts[1]);
97 }
98 }
99
100 return -1;
101 }
102
103 /**
104 * Extracts the signatures matching a given scheme in a signature header.
105 *
106 * @param string $header the signature header
107 * @param string $scheme the signature scheme to look for
108 *
109 * @return array the list of signatures matching the provided scheme
110 */
111 private static function getSignatures($header, $scheme)
112 {
113 $signatures = [];
114 $items = \explode(',', $header);
115
116 foreach ($items as $item) {
117 $itemParts = \explode('=', $item, 2);
118 if (\trim($itemParts[0]) === $scheme) {
119 $signatures[] = $itemParts[1];
120 }
121 }
122
123 return $signatures;
124 }
125
126 /**
127 * Computes the signature for a given payload and secret.
128 *
129 * The current scheme used by Stripe ("v1") is HMAC/SHA-256.
130 *
131 * @param string $payload the payload to sign
132 * @param string $secret the secret used to generate the signature
133 *
134 * @return string the signature as a string
135 */
136 private static function computeSignature($payload, $secret)
137 {
138 return \hash_hmac('sha256', $payload, $secret);
139 }
140 }
141