Accept Crypto at 0% fee with Crypoverse - BTC, ETH, LTC etc

Accept Crypto at 0% fee with Crypoverse - BTC, ETH, LTC etc 3.1.3

No permission to download

🔴 Security Improvements​

  • Added HMAC-SHA256 webhook signature validation
  • Implemented constant-time comparison to prevent timing attacks
  • Reduced webhook replay window from 30 days → 5 minutes
  • Enforced strict payment amount validation ($0.01 – $1,000,000)
  • Fixed XSS risks in log output

✅ Code & Compliance​

  • Refactored duplicated payment logic
  • Improved validation flow and API secret handling
  • Cleaned up upgrade steps to remove false error logs

🐛 Debug & Logging​

  • Added Debug Mode (bypasses HMAC for testing only, disable in production)
  • Improved webhook logging with detailed rejection reasons
  • Better server-side error visibility
Back
Top Bottom