B4X Requires Chilkat v11.0.0+
B4X
Verify Signature of Alexa Custom Skill Request
See more HTTP Misc Examples
This example verifies the signature of an Alexa Custom Skill Request.Chilkat B4X Downloads
Dim success As Boolean = False
' This example assumes you have a web service that will receive requests from Alexa.
' A sample request sent by Alexa will look like the following:
' Connection: Keep-Alive
' Content-Length: 2583
' Content-Type: application/json; charset=utf-8
' Accept: application/json
' Accept-Charset: utf-8
' Host: your.web.server.com
' User-Agent: Apache-HttpClient/4.5.x (Java/1.8.0_172)
' Signature: dSUmPwxc9...aKAf8mpEXg==
' SignatureCertChainUrl: https://s3.amazonaws.com/echo.api/echo-api-cert-6-ats.pem
'
' {"version":"1.0","session":{"new":true,"sessionId":"amzn1.echo-api.session.433 ... }}
' First, assume we've written code to get the 3 pieces of data we need:
Dim signature As String = "dSUmPwxc9...aKAf8mpEXg=="
Dim certChainUrl As String = "https://s3.amazonaws.com/echo.api/echo-api-cert-6-ats.pem"
Dim jsonBody As String = "{" & Chr(34) & "version" & Chr(34) & ":" & Chr(34) & "1.0" & Chr(34) & "," & Chr(34) & "session" & Chr(34) & ":{" & Chr(34) & "new" & Chr(34) & ":true," & Chr(34) & "sessionId" & Chr(34) & ":" & Chr(34) & "amzn1.echo-api.session.433 ... }}"
' To validate the signature, we do the following:
' First, download the PEM-encoded X.509 certificate chain that Alexa used to sign the message
Dim http As ChilkatHttp
http.Initialize("http")
Dim sbPem As ChilkatStringBuilder
sbPem.Initialize
success = http.QuickGetSb(certChainUrl, sbPem)
If success = False Then
Log(http.LastErrorText)
Return
End If
Dim pem As ChilkatPem
pem.Initialize
success = pem.LoadPem(sbPem.GetAsString, "passwordNotUsed")
If success = False Then
Log(pem.LastErrorText)
Return
End If
' The 1st certificate should be the signing certificate.
Dim cert As ChilkatCert = pem.GetCert(0)
If pem.LastMethodSuccess = False Then
Log(pem.LastErrorText)
Return
End If
' Get the public key from the cert.
Dim pubKey As ChilkatPublicKey
pubKey.Initialize
cert.GetPublicKey(pubKey)
' Use the public key extracted from the signing certificate to decrypt the encrypted signature to produce the asserted hash value.
Dim rsa As ChilkatRsa
rsa.Initialize
success = rsa.UsePublicKey(pubKey)
If success = False Then
Log(cert.LastErrorText)
Return
End If
' RSA "decrypt" the signature.
' (Amazon's documentation is confusing, because we're simply verifiying the signature against the SHA-1 hash
' of the request body. This happens in a single call to VerifyStringENC...)
rsa.EncodingMode = "base64"
Dim bVerified As Boolean = rsa.VerifyStringENC(jsonBody, "sha1", signature)
If bVerified = True Then
Log("The signature is verified against the JSON body of the request. Yay!")
Else
Log("Sorry, not verified. Crud!")
End If