waiaconnect

Documentazione / Essenziale

Autenticare il webhook: header statico o firma

Markdown

Ogni consegna viaggia SEMPRE firmata e, IN PIÙ, può portare un header statico (un token fisso in un header a tua scelta, es. X-Connect-Token) se lo attivi sul tuo endpoint. Non sono modalità che si escludono: scegli tu come validare.

Header statico — più comodo e più debole. Su HTTPS dimostra che chi chiama conosce il token, ma NON verifica che il corpo non sia stato alterato, né impedisce un replay. È l'opzione per gli strumenti senza codice (n8n/Make/Zapier), che lo validano con la loro autenticazione nativa tramite header.

Firma HMAC — verifica l'integrità del corpo E protegge dal replay (il timestamp è dentro l'HMAC). Richiede di scrivere un po' di codice. È la garanzia forte.

Scegliere la comodità va bene; sceglierla senza sapere cosa perdi, no. Se puoi, valida la firma; se usi strumenti no-code, attiva l'header statico e validalo con il tuo strumento.

# Static header check on the server that RECEIVES the webhook.
# Connect sends your token in the "X-Connect-Token" header on every delivery.
# Compare it in CONSTANT time against the token you stored.
#   if [ "$http_x_connect_token" != "$YOUR_TOKEN" ]; then reject 401; fi
import crypto from "crypto";
const TOKEN = "wct_YOUR_TOKEN"; // the wct_… you stored (from the panel)

function checkHeader(req) {
  const got = req.header("X-Connect-Token") || "";
  const a = Buffer.from(got), b = Buffer.from(TOKEN);
  // constant-time compare (avoid a length/timing leak)
  return a.length === b.length && crypto.timingSafeEqual(a, b);
}
<?php
$TOKEN = "wct_YOUR_TOKEN"; // the wct_… you stored (from the panel)

function checkHeader(array $headers): bool {
  $got = $headers["X-Connect-Token"] ?? "";
  return hash_equals($GLOBALS["TOKEN"], $got); // constant-time compare
}
import hmac

TOKEN = "wct_YOUR_TOKEN"  # the wct_… you stored (from the panel)

def check_header(headers) -> bool:
    got = headers.get("X-Connect-Token", "")
    return hmac.compare_digest(got, TOKEN)  # constant-time compare

L'header si chiama come vuoi tu (predefinito X-Connect-Token), MAI Authorization. Lo generi/ruoti sul tuo endpoint (Webhook) e viene mostrato UNA sola volta.

Confronta il token in tempo costante (come sotto). L'esempio di verifica della firma è in 'Verificare la firma'.