Skip to main content
The signature covers the raw request body, so verification belongs in middleware, before anything parses the JSON.

1. The signing middleware

app/Http/Middleware/VerifyCastroSignature.php
Register it and add the key to your config:
config/services.php
bootstrap/app.php

2. Routes

routes/api.php
Your base URL in Castro is then https://your-site.com/api/castro.

3. The controller

app/Http/Controllers/CastroController.php
Use $request->has(), not $request->input() with a default, to decide whether a field was sent. $request->input('title', $post->title) looks like it handles the partial case, but an explicitly-sent empty string still overwrites, and a missing key silently rewrites the same value on every update.

4. Verify it

The conformance script will tell you if the middleware rejects a bad signature and if your PUT really is partial: the two things this file exists to get right.