Compare commits

..

2 Commits

Author SHA1 Message Date
khwezi 0d5702f0fe Merge pull request 'Using IFormCollection for VerifyIncomingSignatureFromForm' (#112) from payments into master
Reviewed-on: #112
2026-06-13 16:05:57 +02:00
Khwezi Mngoma e4c3779092 Using IFormCollection for VerifyIncomingSignatureFromForm
continuous-integration/drone/pr Build is passing
2026-06-13 16:03:31 +02:00
@@ -48,21 +48,24 @@ public sealed partial class PayfastService(IDbContextFactory<MidrandBooksDbConte
} }
} }
public static bool VerifyIncomingSignature(IDictionary<string, string> formFields, string passphrase) public static bool VerifyIncomingSignatureFromForm(IFormCollection formCollection, string passphrase)
{ {
if (!formFields.TryGetValue("signature", out string? incomingSignature)) var sortedFields = new Dictionary<string, string>(StringComparer.Ordinal);
return false;
foreach (var field in formCollection)
{
sortedFields.Add(field.Key, field.Value.ToString());
}
if (!sortedFields.TryGetValue("signature", out var incomingSignature)) return false;
var stringBuilder = new StringBuilder(); var stringBuilder = new StringBuilder();
foreach (var key in formFields.Keys) foreach (var key in sortedFields.Keys)
{ {
if (key.Equals("signature", StringComparison.OrdinalIgnoreCase)) if (key.Equals("signature", StringComparison.OrdinalIgnoreCase)) continue;
continue;
string rawValue = formFields[key] ?? string.Empty; string encodedVal = HttpUtility.UrlEncode(sortedFields[key].Trim());
string encodedVal = HttpUtility.UrlEncode(rawValue.Trim());
string cleanVal = PercentEncodingRegex.Replace(encodedVal, m => m.Value.ToUpperInvariant()); string cleanVal = PercentEncodingRegex.Replace(encodedVal, m => m.Value.ToUpperInvariant());
stringBuilder.Append($"{key}={cleanVal}&"); stringBuilder.Append($"{key}={cleanVal}&");