feat(webhook): require line ingress signatures

This commit is contained in:
2026-06-05 00:35:30 +08:00
parent 894b1326e6
commit 0439f3bf87
3 changed files with 55 additions and 3 deletions
+2 -2
View File
@@ -79,8 +79,8 @@ func (h *LineWebhookHandler) HandleLineWebhook(c *gin.Context) {
}
signature := c.GetHeader("X-Line-Signature")
if channelSecret != "" && signature != "" {
if !h.service.VerifySignature(channelSecret, string(body), signature) {
if channelSecret != "" {
if signature == "" || h.service == nil || !h.service.VerifySignature(channelSecret, string(body), signature) {
applogger.L().Warnf("LINE webhook: invalid signature for inbox=%d", inbox.ID)
c.JSON(http.StatusUnauthorized, gin.H{"error": "invalid signature"})
return