我有以下HTTPS服务器:
from flask import Flask, request, Response
from viberbot import Api
from viberbot.api.bot_configuration import BotConfiguration
from viberbot.api.messages import VideoMessage
from viberbot.api.messages.text_message import TextMessage
import logging
from viberbot.api.viber_requests import ViberConversationStartedRequest
from viberbot.api.viber_requests import ViberFailedRequest
from viberbot.api.viber_requests import ViberMessageRequest
from viberbot.api.viber_requests import ViberSubscribedRequest
from viberbot.api.viber_requests import ViberUnsubscribedRequest
logger = logging.getLogger(__name__)
app = Flask(__name__)
viber = Api(BotConfiguration(
name='PythonSampleBot',
avatar='http://www.clker.com/cliparts/3/m/v/Y/E/V/small-red-apple-hi.png',
auth_token='xxx-xxx-xxx'
))
@app.route('/', methods=['POST'])
def incoming():
logger.debug("received request. post data: {0}".format(request.get_data()))
# every viber message is signed, you can verify the signature using this method
if not viber.verify_signature(request.get_data(), request.headers.get('X-Viber-Content-Signature')):
return Response(status=403)
# this library supplies a simple way to receive a request object
viber_request = viber.parse_request(request.get_data())
if isinstance(viber_request, ViberMessageRequest):
message = viber_request.message
# lets echo back
viber.send_messages(viber_request.sender.id, [
message
])
elif isinstance(viber_request, ViberSubscribedRequest):
viber.send_messages(viber_request.get_user.id, [
TextMessage(text="thanks for subscribing!")
])
elif isinstance(viber_request, ViberFailedRequest):
logger.warn(
"client failed receiving message. failure: {0}".format(viber_request))
return Response(status=200)
def set_webhook(viber_bot):
viber_bot.set_webhook('https://xxx.xxx.xxx.xxx:4443')
logging.info("Web hook has been set")
if __name__ == "__main__":
context = ('certificate.pem', 'key.pem')
app.run(host='0.0.0.0', port=4443, debug=True, ssl_context=context)
并尝试发送消息:
import json
import requests
webhook_url = 'https://xxx.xxx.xxx.xxx:4443'
data = {
"receiver": "xxx-xxx-xxx",
"type": "text",
"text": "Hello world!"
}
response = requests.post(
webhook_url, data=json.dumps(data),
headers={'Content-Type': 'application/json'},
verify='E:\\Docs\\learn_py\\viberbot\\certificate.pem'
)
if response.status_code != 200:
raise ValueError(
'Request returned an error %s, the response is:\n%s'
% (response.status_code, response.text)
)
我收到403错误
ValueError:请求返回了错误403,响应为:
更新:
403来自:
if not viber.verify_signature(request.get_data(), request.headers.get('X-Viber-Content-Signature')):
return Response(status=403)
答案 0 :(得分:6)
已编辑由于更新。您在verify_signature
上遇到错误。
verify_signature
的定义:
def verify_signature(self, request_data, signature):
return signature == self._calculate_message_signature(request_data)
您正在发送request.headers.get('X-Viber-Content-Signature')
作为签名。因此,您的解决方案是检查__calculate_message_signature(request_data)的结果
requiest_data = request.get_data()。
_calculate_message_signature
的定义是:
def _calculate_message_signature(self, message):
return hmac.new(
bytes(self._bot_configuration.auth_token.encode('ascii')),
msg=message,
digestmod=hashlib.sha256)\
.hexdigest()
我会检查auth_token
中使用的self._bot_configuration.auth_token.encode('ascii')
。是否包含非ASCII字符?如果是,那么您有原因。 (例如)
尝试比较以下结果:
hmac.new(bytes(self._bot_configuration.auth_token.encode('ascii')),
msg=request.get_data(),
digestmod=hashlib.sha256).hexdigest()
收件人:
request.headers.get('X-Viber-Content-Signature')
不同,这就是为什么您收到禁止消息的原因。
答案 1 :(得分:6)
您收到403错误的原因有两个。要模拟来自Viber的Webhook请求,必须发送X-Viber-Content-Signature
标头。此外,该值还必须是使用auth令牌和webhook有效负载(如其API文档中Callbacks下所述)的SHA256哈希值。
我相信您在这里有2个选择。如果您只想验证代码是否正确接收了Webhook,则可以暂时将verify_signature()
行注释掉。 Viber(或任何Webhook源)不需要验证Webhook请求。通常,开发人员会假设像Viber提供的那样的库可以正确地测试其代码,因此通常无需再次测试其功能。您还可以考虑对函数进行模拟,因为在这种情况下,这非常简单。
如果您真的想测试Viber的签名验证,那么您将需要实现我首先提到的两个原因。基本上,这是在测试Webhook发送代码中需要执行的操作。请注意,我仅在下面包括了您需要的新代码,请合并到其他测试代码中。
import json
import hmac
import hashlib
# Compute SHA256 hex digest signature using auth token and payload.
auth_token = 'xxx-xxx-xxx'
signature = hmac.new(
key=auth_token.encode('ascii'),
msg=data.encode('ascii'),
digestmod=hashlib.sha256
).hexdigest()
# Send test webhook request with computed signature in header.
response = requests.post(
webhook_url,
data=json.dumps(data),
headers={
'X-Viber-Content-Signature': signature,
'Content-Type': 'application/json'
},
verify='E:\\Docs\\learn_py\\viberbot\\certificate.pem'
)
请注意,@ tukan指出了viber-bot-python回购中的_calculate_message_signature()
函数,该函数显示了签名的计算方式。