Issue: Webhook signature validation fails for comma-separated signatures
Issue: Webhook signature validation fails for comma-separated signatures: a task in LegoFlow-SWE (Harbor dataset). When receiving webhook requests, some providers (such as GitHub) send an HTTP header containing multiple HMAC signatures in a comma-separated list. Each signature may be prefixed with…
The task
When receiving webhook requests, some providers (such as GitHub) send an HTTP header containing multiple HMAC signatures in a comma-separated list. Each signature may be prefixed with an algorithm name (e.g., `sha1=`, `sha256=`). The current implementation of `CheckPayloadSignature` and `CheckPayloadSignature256`…
Part of Lego-X/LegoFlow-SWE.