S
Supanote
Sign in Sign up
Security & Auth

Security Policies & Webhook Verification Templates

RFC 9116 security.txt declarations, Cloudflare Turnstile token validation, Stripe webhook signatures, and Polar.sh billing handlers.

plain Verified Starter

Security.txt Standard Policy (RFC 9116)

Standard RFC 9116 security policy template for /.well-known/security.txt with PGP key and vulnerability disclosure guidelines.

# /.well-known/security.txt
# Conforms to RFC 9116: https://www.rfc-editor.org/rfc/rfc9116

Contact: mailto:security@example.com
Expires: 2027-12-31T23:59:59.000Z
Encryption: https://example.com/pgp-key.txt
Preferred-Languages: en, tr
Canonical:...
javascript Verified Starter

Cloudflare Turnstile Server-Side Verification (Node.js)

Zero-dependency Cloudflare Turnstile token validation middleware with timeout and client IP passing.

'use strict';

/**
 * Validates Cloudflare Turnstile CAPTCHA response token
 * @param {string} token - The cf-turnstile-response string from form body
 * @param {string} remoteIp - Optional remote client IP address
 * @returns {Promise<{ success:...
javascript Verified Starter

Stripe Webhook Signature Verification & Event Dispatcher

Production-ready Stripe webhook handler verifying HMAC signatures, idempotent processing, and subscription lifecycle.

'use strict';

const crypto = require('crypto');

/**
 * Securely verify Stripe webhook signature without external heavy dependencies
 * @param {string|Buffer} payload - Raw HTTP request body buffer
 * @param {string} sigHeader - 'stripe-signature'...
javascript Verified Starter

Polar.sh Webhook Signature Verification & License Handler

Polar.sh billing webhook handler verifying webhook signatures and granting Pro customer licenses.

'use strict';

const crypto = require('crypto');

/**
 * Verify Polar.sh webhook signature using Standard Webhooks HMAC-SHA256
 */
function verifyPolarWebhook(rawBody, headers, webhookSecret) {
  const webhookId = headers['webhook-id'];
  const...
Notification