Hi Trello,
I’m trying to write some python code inside of an AWS Lambda function to verify the webhook signature from Trello. I’ve tried to follow the directions at https://developers.trello.com/page/webhooks#section-webhook-signatures but I can’t seem to get this working. Here’s what I have:
import os
import hmac
import hashlib
import base64
def handler(event, context):
header = event['headers']['x-trello-webhook']
sha1_check = base64.b64encode(hmac.new(<MY_TRELLO_API_KEY_TOKEN>, event['body'] + <MY_TRELLO_CALLBACK_URL>, hashlib.sha1).digest())
My code is syntactically correct, but it’s not working. When I attempt to compare header and sha1_check, they are not equal. I confirmed this by echoing their values to the logs. The docs at https://developers.trello.com/page/webhooks#section-webhook-signatures say:
Each webhook trigger contains the HTTP header X-Trello-Webhook. The header is a base64 digest of an HMAC-SHA1 hash. The hashed content is the concatenation of the full request body and the callbackURL exactly as it was provided during webhook creation. The key used to sign this text is your application’s secret.
I think my code takes all of this into account.
Can you help me figure out what is wrong?
Thanks,
Ethan