Security & Auth
Security Policies & Webhook Verification Templates
RFC 9116 security.txt declarations, Cloudflare Turnstile token validation, Stripe webhook signatures, and Polar.sh billing handlers.
plain
Verified Starter
Security.txt Standard Policy (RFC 9116)
Standard RFC 9116 security policy template for /.well-known/security.txt with PGP key and vulnerability disclosure guidelines.
# /.well-known/security.txt
# Conforms to RFC 9116: https://www.rfc-editor.org/rfc/rfc9116
Contact: mailto:security@example.com
Expires: 2027-12-31T23:59:59.000Z
Encryption: https://example.com/pgp-key.txt
Preferred-Languages: en, tr
Canonical:...
javascript
Verified Starter
Cloudflare Turnstile Server-Side Verification (Node.js)
Zero-dependency Cloudflare Turnstile token validation middleware with timeout and client IP passing.
'use strict';
/**
* Validates Cloudflare Turnstile CAPTCHA response token
* @param {string} token - The cf-turnstile-response string from form body
* @param {string} remoteIp - Optional remote client IP address
* @returns {Promise<{ success:...
javascript
Verified Starter
Stripe Webhook Signature Verification & Event Dispatcher
Production-ready Stripe webhook handler verifying HMAC signatures, idempotent processing, and subscription lifecycle.
'use strict';
const crypto = require('crypto');
/**
* Securely verify Stripe webhook signature without external heavy dependencies
* @param {string|Buffer} payload - Raw HTTP request body buffer
* @param {string} sigHeader - 'stripe-signature'...
javascript
Verified Starter
Polar.sh Webhook Signature Verification & License Handler
Polar.sh billing webhook handler verifying webhook signatures and granting Pro customer licenses.
'use strict';
const crypto = require('crypto');
/**
* Verify Polar.sh webhook signature using Standard Webhooks HMAC-SHA256
*/
function verifyPolarWebhook(rawBody, headers, webhookSecret) {
const webhookId = headers['webhook-id'];
const...