Stripe Payments & SaaS Billing Systems · บทเรียน

การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย

ปกป้องแบ็กเอนด์การชำระเงินจากเหตุการณ์ปลอมด้วยการตรวจสอบลายเซ็น Stripe webhook และปฏิบัติตามแนวทางรักษาความปลอดภัยของปลายทาง

บทเรียน 4 จาก 413 ขั้นตอน

การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย เป็นบทเรียน Stripe Payments & SaaS Billing Systems ฟรีบน CoddyKit นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน คุณสามารถอ่านบทเรียนทั้งหมดด้านล่างฟรี — จากนั้นลองปฏิบัติด้วยตัวคุณเองในเบราว์เซอร์พร้อมตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7 บทเรียนนี้เป็นส่วนหนึ่งของเส้นทางการเรียน Stripe Payments & SaaS Billing Systems และความก้าวหน้าของคุณจะซิงค์ข้ามเว็บและแอป CoddyKit คอร์ส Stripe Payments & SaaS Billing Systems มีบทเรียนทั้งหมด 4 บทเรียน

บางส่วนของบทเรียนนี้ยังไม่ได้รับการแปล และแสดงเป็นภาษาอังกฤษ

Why Verify Webhooks?

Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.

The Signing Secret

Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.

The Stripe-Signature Header

Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.

// Stripe-Signature: t=1700000000,v1=5257a8...

Use the Raw Body

Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.

app.post('/webhook',
  express.raw({ type: 'application/json' }),
  handler
);

Verifying with the SDK

The Stripe SDK does the HMAC math for you via constructEvent.

function verify(rawBody, sig, secret, stripe) {
  return stripe.webhooks.constructEvent(rawBody, sig, secret);
}

Handling Verification Failure

If verification throws, reject the request with a 400. Never process an unverified event.

function process(ok) {
  if (!ok) return { status: 400, body: 'invalid signature' };
  return { status: 200, body: 'received' };
}
console.log(process(false));

Timestamp Tolerance

The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.

Constant-Time Comparison

Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.

Respond Fast, Process Later

Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.

Keep the Secret Safe

Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.

const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));

Per-Endpoint Secrets

Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.

Quick Check

Why must you use the raw request body for verification?

Recap

You secured your webhook endpoint:

  • Verify the Stripe-Signature with the signing secret
  • Use the raw body and the SDK constructEvent
  • Reject failures and rely on timestamp tolerance against replays
  • Keep secrets in env vars and respond fast
เริ่มต้นได้ฟรี

เรียนรู้ Stripe Payments & SaaS Billing Systems ด้วย AI tutor — ฟรี

เขียนและเรียกใช้โค้ดจริงในเบราว์เซอร์ของคุณ รับความช่วยเหลือทันทีจาก AI tutor 24/7 และเรียนรู้ต่อจากที่คุณหยุดบนเว็บหรือในแอป

คอร์ส
12
บทเรียน
48

คำถามที่พบบ่อย

บทเรียน “การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย” ฟรีหรือไม่

ใช่ — ข้อความเต็มของ “การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย” ฟรีให้อ่านที่นี่บนเว็บ เพื่อปฏิบัติแบบโต้ตอบ (ตัวแก้ไขโค้ดในตัวและติวเตอร์ AI ตลอด 24/7) และปลดล็อคส่วนที่เหลือของคอร์ส Stripe Payments & SaaS Billing Systems ให้อัปเกรดเป็น CoddyKit PRO คอร์ส Stripe Payments & SaaS Billing Systems มีบทเรียนทั้งหมด 4 บทเรียน

คุณจะเรียนรู้อะไรในบทเรียน “การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย”

ปกป้องแบ็กเอนด์การชำระเงินจากเหตุการณ์ปลอมด้วยการตรวจสอบลายเซ็น Stripe webhook และปฏิบัติตามแนวทางรักษาความปลอดภัยของปลายทาง คุณปฏิบัติ Stripe Payments & SaaS Billing Systems ด้วยโค้ดที่ใช้งานได้จริงที่คุณเรียกใช้โดยตรงในเบราว์เซอร์ และติวเตอร์ AI ตลอด 24/7 ตอบคำถามของคุณขณะที่คุณไปผ่านบทเรียน

คุณต้องมีประสบการณ์ก่อนที่จะเริ่มเรียน Stripe Payments & SaaS Billing Systems หรือไม่

ไม่จำเป็นต้องมีประสบการณ์มาก่อน Stripe Payments & SaaS Billing Systems บน CoddyKit ออกแบบมาสำหรับผู้เริ่มต้นไปจนถึงผู้เรียนขั้นสูง คุณสามารถเริ่มต้นที่นี่หรือเริ่มจากตัวแรกและเรียนด้วยความเร็วของคุณเอง นี่คือบทเรียนที่ 4 จากทั้งหมด 4 บทเรียน

บทเรียน “การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย” ใช้เวลานานแค่ไหน

บทเรียน CoddyKit ส่วนใหญ่ใช้เวลาประมาณ 5–10 นาที แต่ละบทเรียนจึงสั้นและเป็นแบบโต้ตอบ คุณสามารถก้าวหน้าอย่างต่อเนื่องและกลับมาเรียนต่อจากตรงที่เพิ่งหยุดบนเว็บและแอปได้เลย

ฉันเขียนและรันโค้ดในบทเรียน Stripe Payments & SaaS Billing Systems นี้ได้ไหม

ได้ บทเรียน Stripe Payments & SaaS Billing Systems ทุกบทมีตัวแก้ไขโค้ดในตัว คุณจึงเขียนและรันโค้ดจริงได้เลยในเบราว์เซอร์ และได้รับข้อเสนอแนะจาก AI ในทันที — ไม่ต้องติดตั้งในเครื่องของคุณ

บทเรียนทั้งหมดในหลักสูตรนี้

  1. การจัดเก็บวิธีการชำระเงินอย่างปลอดภัย (โทเค็น)
  2. การนำการตรวจสอบสิทธิ์ลูกค้าที่เข้มงวด (SCA) มาใช้
  3. แนวทางปฏิบัติที่ดีที่สุดสำหรับนักพัฒนาเพื่อให้สอดคล้องกับ PCI
  4. การตรวจสอบลายเซ็น Webhook อย่างปลอดภัย
← กลับไปที่ Stripe Payments & SaaS Billing Systems