Stripe Payments & SaaS Billing Systems · Ders

Webhook İmzalarını Güvenli Biçimde Doğrulama

Stripe webhook imzalarını doğrulayarak ve güvenli uç nokta uygulamalarını izleyerek ödeme arka ucunuzu sahte olaylara karşı koruyun.

4. ders / 413 adım

Webhook İmzalarını Güvenli Biçimde Doğrulama, CoddyKit'te ücretsiz bir Stripe Payments & SaaS Billing Systems dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Stripe Payments & SaaS Billing Systems öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Stripe Payments & SaaS Billing Systems kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

Why Verify Webhooks?

Your webhook endpoint is public. Without verification, an attacker could POST a fake payment_succeeded event and unlock paid features for free.

The Signing Secret

Each webhook endpoint has a signing secret (starts with whsec_). Stripe uses it to sign every event it sends you.

The Stripe-Signature Header

Every webhook request carries a Stripe-Signature header containing a timestamp and an HMAC signature of the payload.

// Stripe-Signature: t=1700000000,v1=5257a8...

Use the Raw Body

Signature verification needs the exact raw request body. If a framework parses JSON first, the bytes change and verification fails.

app.post('/webhook',
  express.raw({ type: 'application/json' }),
  handler
);

Verifying with the SDK

The Stripe SDK does the HMAC math for you via constructEvent.

function verify(rawBody, sig, secret, stripe) {
  return stripe.webhooks.constructEvent(rawBody, sig, secret);
}

Handling Verification Failure

If verification throws, reject the request with a 400. Never process an unverified event.

function process(ok) {
  if (!ok) return { status: 400, body: 'invalid signature' };
  return { status: 200, body: 'received' };
}
console.log(process(false));

Timestamp Tolerance

The signature includes a timestamp. Stripe rejects events older than a tolerance window to block replay attacks with captured payloads.

Constant-Time Comparison

Under the hood, signatures are compared in constant time to avoid timing attacks. The SDK handles this; never hand-roll a simple equality check.

Respond Fast, Process Later

Acknowledge with 200 quickly, then do heavy work asynchronously. Slow responses make Stripe retry and can cause duplicates.

Keep the Secret Safe

Store the signing secret in environment variables, never in source control. Rotate it if it leaks, using the dashboard.

const secret = process.env.STRIPE_WEBHOOK_SECRET;
console.log(Boolean(secret));

Per-Endpoint Secrets

Each registered endpoint has its own secret. Use the correct one for the URL receiving the event, especially across test and live modes.

Quick Check

Why must you use the raw request body for verification?

Recap

You secured your webhook endpoint:

  • Verify the Stripe-Signature with the signing secret
  • Use the raw body and the SDK constructEvent
  • Reject failures and rely on timestamp tolerance against replays
  • Keep secrets in env vars and respond fast
Başlamak ücretsiz

Yapay zeka eğitmeniyle Stripe Payments & SaaS Billing Systems öğren — ücretsiz

Tarayıcında gerçek kod yaz ve çalıştır, 7/24 yapay zeka eğitmeninden anında yardım al; web'de ya da uygulamada kaldığın yerden devam et.

Kurslar
12
Dersler
48

Sıkça Sorulan Sorular

“Webhook İmzalarını Güvenli Biçimde Doğrulama” dersi ücretsiz mi?

Evet — “Webhook İmzalarını Güvenli Biçimde Doğrulama” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Stripe Payments & SaaS Billing Systems kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Stripe Payments & SaaS Billing Systems kursu toplamda 4 dersten oluşur.

“Webhook İmzalarını Güvenli Biçimde Doğrulama” dersinde ne öğreneceğim?

Stripe webhook imzalarını doğrulayarak ve güvenli uç nokta uygulamalarını izleyerek ödeme arka ucunuzu sahte olaylara karşı koruyun. Stripe Payments & SaaS Billing Systems ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Stripe Payments & SaaS Billing Systems öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Stripe Payments & SaaS Billing Systems, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.

“Webhook İmzalarını Güvenli Biçimde Doğrulama” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Stripe Payments & SaaS Billing Systems dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Stripe Payments & SaaS Billing Systems dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Ödeme Yöntemlerini Güvenle Saklama (Token'lar)
  2. Güçlü Müşteri Kimlik Doğrulamasını (SCA) Uygulama
  3. Geliştiriciler için PCI Uyumluluğu En İyi Uygulamaları
  4. Webhook İmzalarını Güvenli Biçimde Doğrulama
← Stripe Payments & SaaS Billing Systems Sayfasına Dön