KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
I wrote a method to verify a gigya signature against a specified timestamp and UID, based on Gigya's instructions for constructing a signature . Here is Gigya's psuedo code for doing that: string constructSignature(string timestamp, string UID, string secretKey) { // Construct a "base string" for signing baseString = timestamp + "_" + UID; // Convert the base string into a binary array binaryBaseString = ConvertUTF8ToBytes(baseString); // Convert secretKey from BASE64 to a binary array binaryKey = ConvertFromBase64ToBytes(secretKey); // Use the HMAC-SHA1 algorithm to calculate the signature binarySignature = hmacsha1(binaryKey, baseString); // Convert the signature to a BASE64 signature = ConvertToBase64(binarySignature); return signature; } [sic] Here's my method (exception handling omitted): public boolean verifyGigyaSig(String uid, String timestamp, String signature) { // Construct the "base string" String baseString = timestamp + "_" + uid; // Convert the base string into a binary array byte[] baseBytes = baseString.getBytes("UTF-8"); // Convert secretKey from BASE64 to a binary array String secretKey = MyConfig.getGigyaSecretKey(); byte[] secretKeyBytes = Base64.decodeBase64(secretKey); // Use the HMAC-SHA1 algorithm to calculate the signature Mac mac = Mac.getInstance("HmacSHA1"); mac.init(new SecretKeySpec(secretKeyBytes, "HmacSHA1")); byte[] signatureBytes = mac.doFinal(baseBytes); // Convert the signature to a BASE64 String calculatedSignature = Base64.encodeBase64String(signatureBytes); /
Tags (comma-separated)
Save Edits
Cancel