Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature] Implement endpoint signing similar to Stripe #14

Open
manast opened this issue Feb 29, 2024 · 0 comments
Open

[Feature] Implement endpoint signing similar to Stripe #14

manast opened this issue Feb 29, 2024 · 0 comments

Comments

@manast
Copy link
Contributor

manast commented Feb 29, 2024

In order to secure endpoints to be called from untrusted sources, we should implement a signing mechanism similar to the one Stripe is using:
https://docs.stripe.com/webhooks

Basically, a timestamp+signature is provided, the endpoint should compute a signature using an endpoint secret and calculating an HMAC with the timestamp + request body.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant