verifyNotification method

  1. @override
Future<DVStoreNotification> verifyNotification(
  1. String body,
  2. Map<String, String> headers
)
override

Verifies a store server notification's signature and returns what it says, re-reading the purchase from the store where the notification does not carry it (Play's do not).

Throws DVStoreRefusal for a signature that does not verify.

Implementation

@override
Future<DVStoreNotification> verifyNotification(
  String body,
  Map<String, String> headers,
) async {
  if (unavailable) throw const DVStoreUnavailable('the store is unreachable');
  String? signature;
  for (final MapEntry<String, String> header in headers.entries) {
    if (header.key.toLowerCase() == signatureHeader.toLowerCase()) {
      signature = header.value;
    }
  }
  if (signature == null) {
    throw DVStoreRefusal(store, 'the notification is not signed');
  }
  if (!_constantTimeEquals(signature, _signature(body))) {
    throw DVStoreRefusal(store, 'the notification signature does not match');
  }
  try {
    return _notificationFromJson(
        (jsonDecode(body) as Map<Object?, Object?>).cast<String, Object?>());
  } on Object {
    throw DVStoreRefusal(store, 'the notification body is not readable');
  }
}