1. Go to this page and download the library: Download silversoft/api-signer library. Choose the download type require.
2. Extract the ZIP file and open the index.php.
3. Add this code to the index.php.
<?php
require_once('vendor/autoload.php');
/* Start to develop here. Best regards https://php-download.com/ */
silversoft / api-signer example snippets
use Silversoft\ApiSigner\{ApiSigner, Credential};
$credential = new Credential('moja-usluga', getenv('API_SECRET'));
$signed = ApiSigner::prepare(
$credential,
'POST',
'https://api.example.com/v1/users/update',
['user' => ['id' => 1, 'email' => '[email protected]']]
);
// $signed->headers — Signature-Input, Signature, Content-Digest, Content-Type
// $signed->body — dokładnie te bajty, które zostały podpisane
// $signed->headerLines() — linie „Nazwa: wartość” dla CURLOPT_HTTPHEADER
use Silversoft\ApiSigner\{Credential, Policy, Request, Verifier};
$request = new Request(
$_SERVER['REQUEST_METHOD'],
parse_url($_SERVER['REQUEST_URI'], PHP_URL_PATH),
(string) parse_url($_SERVER['REQUEST_URI'], PHP_URL_QUERY),
fopen('php://input', 'rb'), // strumień: ciało nigdy nie jest trzymane dwa razy
getallheaders()
);
$keys = exit;
}
$policy = new Policy();
$policy->keyid', 'created', 'expires', 'alg'];
$policy->allowedAlgorithms = ['hmac-sha256'];
$policy->maxLifetime = 300; // sekundy; klient nie wystawi sobie podpisu na rok
$policy->clockSkew = 30; // sekundy
$policy->
$policy->nonceStore = static function (string $keyId, string $nonce, int $ttl): bool {
return $cache->add("api-nonce:{$keyId}:{$nonce}", 1, $ttl); // false => już użyty
};
$request = new Request('POST', $path, $query, fopen('php://input', 'rb'), getallheaders());