Repository navigation
Add webhook signature verification and typed event models - #10
Merged
Merged
Conversation
FlutterWave webhooks (https://developer.flutterwave.com/docs/webhooks) are inbound: the merchant hosts an endpoint and Flutterwave POSTs event payloads to it. This library only wrapped outgoing API calls, so add the two pieces an SDK can usefully provide for that flow without needing a server/controller layer of its own: - WebhookSignatureVerifier: constant-time comparison of the `verif-hash` header against the merchant's configured secret hash, per the docs' "Verifying Webhook Signatures" guidance. - Typed payload models under FlutterWave.Core.Webhooks(.Events) for every event shown in the docs (charge.completed, transfer.completed incl. wallet funding/PSA inflow, subscription.cancelled, bvn.completed, singlebillpayment.status, plus the un-enveloped virtual card debit/OTP and refund payloads), via a generic WebhookEvent<TData> envelope where the payload has one. Unit tests cover the verifier's match/mismatch/null-or-empty cases and deserialize each event's actual sample payload from the docs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
FlutterWave's webhooks are inbound — the merchant hosts an endpoint and Flutterwave POSTs event payloads to it — so this SDK (which only wraps outgoing API calls) can't "listen" for them itself. This adds the two pieces it can usefully provide for that flow:
FlutterWave.Core.Webhooks.WebhookSignatureVerifier— constant-time comparison of theverif-hashheader against your configured secret hash, per the docs' "Verifying Webhook Signatures" section.FlutterWave.Core.Webhooks.Events— typed payload models for every event type shown in the docs (charge.completed,transfer.completedcovering successful/failed transfer + wallet funding + PSA inflow,subscription.cancelled,bvn.completed,singlebillpayment.status), plus the un-enveloped virtual card debit/OTP and refund payloads, via a genericWebhookEvent<TData>envelope where the payload has anevent/datawrapper.Test plan
dotnet build FlutterWave.Core.sln— 0 warnings, 0 errorsdotnet test FlutterWave.Core.Tests.Unit— 1296/1296 passing, including 18 new tests: verifier match/mismatch/null-or-empty cases, and deserialization of each event type's actual sample payload from the docs🤖 Generated with Claude Code