diff --git a/.github/workflows/craftgate-build.yml b/.github/workflows/craftgate-build.yml index f8a397d..ed7b61d 100644 --- a/.github/workflows/craftgate-build.yml +++ b/.github/workflows/craftgate-build.yml @@ -39,7 +39,7 @@ jobs: run: python -m compileall craftgate - name: Run unit tests - run: python -m unittest tests.test_idempotency -v + run: python -m unittest tests.test_idempotency tests.test_hook_sample -v - name: Build distribution and verify metadata if: matrix.python-version == '3.12' diff --git a/craftgate/adapter/hook_adapter.py b/craftgate/adapter/hook_adapter.py index acd30ee..a04b4a8 100644 --- a/craftgate/adapter/hook_adapter.py +++ b/craftgate/adapter/hook_adapter.py @@ -16,10 +16,13 @@ def is_webhook_verified(self, merchant_hook_key: str, incoming_signature: str, w if merchant_hook_key is None or incoming_signature is None or webhook_data is None: return False + event_type = getattr(webhook_data.event_type, "value", webhook_data.event_type) + status = getattr(webhook_data.status, "value", webhook_data.status) + data = "{}{}{}{}".format( - webhook_data.event_type, + event_type, webhook_data.event_timestamp, - webhook_data.status, + status, webhook_data.payload_id ) diff --git a/tests/test_hook_sample.py b/tests/test_hook_sample.py index 5ec47bc..e3895e4 100644 --- a/tests/test_hook_sample.py +++ b/tests/test_hook_sample.py @@ -47,6 +47,30 @@ def test_should_not_verify_webhook_signature(self): is_verified = self.hook.is_webhook_verified(merchant_hook_key, incoming_signature, webhook_data) self.assertFalse(is_verified) + def test_should_verify_webhook_signature_with_string_values(self): + merchant_hook_key = "Aoh7tReTybO6wOjBmOJFFsOR53SBojEp" + incoming_signature = "0wRB5XqWJxwwPbn5Z9TcbHh8EGYFufSYTsRMB74N094=" + webhook_data = WebhookData( + event_type="API_VERIFY_AND_AUTH", + event_time=datetime(2025, 7, 21, 16, 40, 21, 395655), + event_timestamp=1661521221, + status="SUCCESS", + payload_id="584" + ) + is_verified = self.hook.is_webhook_verified(merchant_hook_key, incoming_signature, webhook_data) + self.assertTrue(is_verified) + + def test_should_return_false_when_arguments_are_none(self): + webhook_data = WebhookData( + event_type=WebhookEventType.API_VERIFY_AND_AUTH, + event_timestamp=1661521221, + status=WebhookStatus.SUCCESS, + payload_id="584" + ) + self.assertFalse(self.hook.is_webhook_verified(None, "sig", webhook_data)) + self.assertFalse(self.hook.is_webhook_verified("key", None, webhook_data)) + self.assertFalse(self.hook.is_webhook_verified("key", "sig", None)) + if __name__ == "__main__": unittest.main()