Request/Response (Express,
raw Node). body MUST be the exact bytes POSTed — never a re-encoded
JSON/text body — so both the protobuf decode (fusor) and the HMAC
verification (native Spectrum webhook) work.
headers ARE read for native Spectrum webhooks: X-Spectrum-Signature /
X-Spectrum-Timestamp carry the HMAC verified against
Spectrum({ webhookSecret }), and the signature header also selects the
native path. For fusor envelopes they are ignored (authenticity is the
per-platform verify() reading the inner reconstructed request). The natural
{ headers: req.headers, body: req.body } shape works for both.
Properties
ArrayBuffer | Uint8Array<ArrayBufferLike>
required
Record<string, string>