diff --git a/docs/en/latest/plugins/hmac-auth.md b/docs/en/latest/plugins/hmac-auth.md index da2d9486c47c..5ddd1189ac5f 100644 --- a/docs/en/latest/plugins/hmac-auth.md +++ b/docs/en/latest/plugins/hmac-auth.md @@ -894,27 +894,29 @@ gmt_time = datetime.now(timezone.utc).strftime('%a, %d %b %Y %H:%M:%S GMT') # the date and any subsequent custom headers should be lowercased and separated by a # single space character, i.e. `:` # https://datatracker.ietf.org/doc/html/draft-cavage-http-signatures-12#section-2.1.6 +# create the SHA-256 digest of the request body and base64 encode it +body_digest = hashlib.sha256(body.encode('utf-8')).digest() +body_digest_base64 = base64.b64encode(body_digest).decode('utf-8') +digest_header = f"SHA-256={body_digest_base64}" + signing_string = ( f"{key_id}\n" f"{request_method} {request_path}\n" f"date: {gmt_time}\n" + f"digest: {digest_header}\n" ) # create signature signature = hmac.new(secret_key, signing_string.encode('utf-8'), hashlib.sha256).digest() signature_base64 = base64.b64encode(signature).decode('utf-8') -# create the SHA-256 digest of the request body and base64 encode it -body_digest = hashlib.sha256(body.encode('utf-8')).digest() -body_digest_base64 = base64.b64encode(body_digest).decode('utf-8') - # construct the request headers headers = { "Date": gmt_time, - "Digest": f"SHA-256={body_digest_base64}", + "Digest": digest_header, "Authorization": ( f'Signature keyId="{key_id}",algorithm="hmac-sha256",' - f'headers="@request-target date",' + f'headers="@request-target date digest",' f'signature="{signature_base64}"' ) }