feat(webhook): require line ingress signatures
This commit is contained in:
@@ -79,8 +79,8 @@ func (h *LineWebhookHandler) HandleLineWebhook(c *gin.Context) {
|
||||
}
|
||||
signature := c.GetHeader("X-Line-Signature")
|
||||
|
||||
if channelSecret != "" && signature != "" {
|
||||
if !h.service.VerifySignature(channelSecret, string(body), signature) {
|
||||
if channelSecret != "" {
|
||||
if signature == "" || h.service == nil || !h.service.VerifySignature(channelSecret, string(body), signature) {
|
||||
applogger.L().Warnf("LINE webhook: invalid signature for inbox=%d", inbox.ID)
|
||||
c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid signature"})
|
||||
return
|
||||
|
||||
Reference in New Issue
Block a user