Overview
Build Express/Next.js middleware for receiving StellarSplit invoice webhooks with HMAC-SHA256 signature verification, timestamp window validation, and nonce-based replay attack protection.
Requirements
- createWebhookMiddleware(secret, options?) returns RequestHandler
- WebhookOptions { toleranceSeconds, nonceWindowSize }
- Verify X-StellarSplit-Signature header (HMAC-SHA256 of timestamp + body)
- Reject requests outside toleranceSeconds window
- Reject replayed nonces using in-memory LRU nonce cache
- Typed event emitter: on(event: InvoiceEventType, handler)
- Tests: valid webhook passes, expired timestamp rejected, replayed nonce rejected, tampered signature rejected
Acceptance Criteria
Definition of Done
All CI checks must pass before the PR is reviewed.
Overview
Build Express/Next.js middleware for receiving StellarSplit invoice webhooks with HMAC-SHA256 signature verification, timestamp window validation, and nonce-based replay attack protection.
Requirements
Acceptance Criteria
Definition of Done
All CI checks must pass before the PR is reviewed.