Add hash_extension variable to requires_signature function so URL _signature can be verified ignoring the given request extension.