verifyNotification method
Verifies a store server notification's signature and returns what it says, re-reading the purchase from the store where the notification does not carry it (Play's do not).
Throws DVStoreRefusal for a signature that does not verify.
Implementation
@override
Future<DVStoreNotification> verifyNotification(
String body,
Map<String, String> headers,
) async {
if (unavailable) throw const DVStoreUnavailable('the store is unreachable');
String? signature;
for (final MapEntry<String, String> header in headers.entries) {
if (header.key.toLowerCase() == signatureHeader.toLowerCase()) {
signature = header.value;
}
}
if (signature == null) {
throw DVStoreRefusal(store, 'the notification is not signed');
}
if (!_constantTimeEquals(signature, _signature(body))) {
throw DVStoreRefusal(store, 'the notification signature does not match');
}
try {
return _notificationFromJson(
(jsonDecode(body) as Map<Object?, Object?>).cast<String, Object?>());
} on Object {
throw DVStoreRefusal(store, 'the notification body is not readable');
}
}