簡體   English   中英

在python 3中生成HMAC Sha256

[英]Generate HMAC Sha256 in python 3

我編寫代碼來驗證帶有 JSON 的 HMAC Auth 傳入 POST 請求到我們的 API。 我收到的 HMAC 是OD5ZxL4tdGgWr78e9vO3cYrjuOFT8WOrTbTIuuIH1PQ=

當我嘗試使用 Python 自己生成它時,它總是不同的。

這是我收到的 JSON 請求:

{
    "shipper_id": 4841,
    "status": "Cancelled",
    "shipper_ref_no": "",
    "tracking_ref_no": "",
    "shipper_order_ref_no": "",
    "timestamp": "2018-05-23T15:13:28+0800",
    "id": "61185ecf-3484-4985-b625-ffe30ba36e28",
    "previous_status": "Pending Pickup",
    "tracking_id": "NVSGBHINK000000001"
}

客戶端密碼是817a3723917f4c7fac24b1f1b324bbab

我收到的 HMAC 秘密是OD5ZxL4tdGgWr78e9vO3cYrjuOFT8WOrTbTIuuIH1PQ=

這是我用 PHP 編寫時的代碼:

<?php
define('CLIENT_SECRET', 'my_shared_secret');
function verify_webhook($data, $hmac_header){
    $calculated_hmac = base64_encode(hash_hmac('sha256', $data, CLIENT_SECRET, true));
    return ($hmac_header == $calculated_hmac);
}  
$hmac_header = $_SERVER['X-NINJAVAN-HMAC-SHA256'];
$data = file_get_contents('php://input');  
$verified = verify_webhook($data, $hmac_header);
error_log('Webhook verified: '.var_export($verified, true)); //check error.log to see result
?>

但我不知道如何在 Python 3 中做到這一點。

在 Python 3 中,您基本上需要以下內容,取自您處理 GitHub webhook 請求的方式。

import hashlib
import hmac

secret = 'CLIENT_SECRET'
data = rsp.content # assumes you're using requests for data/sig
signature = rsp.headers['X-Something-Signature']
signature_computed = 'sha1=' + hmac.new(
    key=secret.encode('utf-8'),
    msg=data.encode('utf-8'),
    digestmod=hashlib.sha1
).hexdigest()
if not hmac.compare_digest(signature, signature_computed):
    log("Invalid payload")

如果您想重新創建從 PHP 到 Python 的散列代碼,請這樣做:

def create_signature(key, data):
    sig_hash =  hmac.new(key.encode('utf8'), data.encode('utf8'), hashlib.sha256).digest()
    base64_message = base64.b64encode(sig_hash).decode()
    return base64_message

這將創建與您的 PHP 代碼正在創建的簽名相匹配的簽名。 只需將簽名與標頭中發送的內容進行比較。

from collections import OrderedDict

params = orderedDict()

params["shipper_id"] = 4841
params["status"] = "Cancelled"
params["shipper_ref_no"] = ""
params["tracking_ref_no"] = ""
params["shipper_order_ref_no"] = ""
params["timestamp"] = "2018-05-23T15:13:28+0800"
params["id"] = "61185ecf-3484-4985-b625-ffe30ba36e28"
params["previous_status"] = "Pending Pickup"
params["tracking_id"] = "NVSGBHINK000000001"
mes = json(params, separator = (";",",")).highdigest()
sighnature = hmac.new(mes, sha256)
# separators = (";",",") - i'm not shure
params['sighnature'] = sighnature
r = response.post(url,params,sighnature)
print(r.text())

暫無
暫無

聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.

 
粵ICP備18138465號  © 2020-2024 STACKOOM.COM