"""Offline HMAC example. Public test key; not an extracted app secret."""
import hashlib
import hmac
import json


def sign(key: bytes, message: bytes) -> str:
    return hmac.new(key, message, hashlib.sha256).hexdigest()


def prepare(key: bytes, timestamp: str, payload: dict) -> tuple[bytes, str]:
    # Illustrative format. A real client's byte order comes from its APK.
    body = json.dumps(payload, separators=(",", ":"), ensure_ascii=False).encode()
    message = timestamp.encode() + b"\nPOST\n/v1/lookup\n" + body
    return body, sign(key, message)


if __name__ == "__main__":
    # RFC 4231, test case 1.
    assert sign(bytes([0x0b]) * 20, b"Hi There") == (
        "b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7"
    )
    body, signature = prepare(b"public-demo-key", "1700000000", {"reference": "ABC123"})
    print(body.decode())
    print(signature)
