-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathwebhook-receiver.php
More file actions
59 lines (49 loc) · 1.71 KB
/
Copy pathwebhook-receiver.php
File metadata and controls
59 lines (49 loc) · 1.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
<?php
/**
* Drop this behind a web server as your webhook endpoint, or run it directly:
*
* GOAL_WEBHOOK_SECRET=... php -S localhost:3100 examples/webhook-receiver.php
*
* The important part is that verification runs on the raw request body. `$_POST` is parsed
* and re-ordered, which changes the bytes and breaks the HMAC; `php://input` is not.
*/
declare(strict_types=1);
require __DIR__ . '/../vendor/autoload.php';
use GoalApi\Exceptions\WebhookSignatureException;
use GoalApi\Webhook;
$secret = getenv('GOAL_WEBHOOK_SECRET') ?: '';
if ($secret === '') {
fwrite(STDERR, "GOAL_WEBHOOK_SECRET is not set.\n");
exit(2);
}
if (($_SERVER['REQUEST_METHOD'] ?? 'GET') !== 'POST') {
http_response_code(405);
exit;
}
try {
$event = Webhook::verify(
file_get_contents('php://input') ?: '',
$_SERVER[Webhook::SIGNATURE_HEADER] ?? null,
$secret,
);
} catch (WebhookSignatureException $error) {
error_log('rejected: ' . $error->getMessage());
http_response_code(400);
exit;
}
$type = $_SERVER[Webhook::EVENT_HEADER] ?? '';
error_log(sprintf('%s delivery=%s', $type, $_SERVER[Webhook::DELIVERY_HEADER] ?? '?'));
match ($type) {
Webhook::EVENT_GOAL_SCORED => error_log(sprintf(
' %s %s-%s %s',
$event['homeTeam']['name'] ?? '?',
$event['homeScore'] ?? '?',
$event['awayScore'] ?? '?',
$event['awayTeam']['name'] ?? '?',
)),
Webhook::EVENT_MATCH_FINISHED => error_log(' full time'),
default => error_log(' ' . substr(json_encode($event) ?: '', 0, 120)),
};
// Ack fast. Retries are ~1m, 5m, 25m, 2h, 10h, so a slow handler earns duplicate
// deliveries; queue the real work instead of doing it here.
http_response_code(200);