Skip to content

fix: verify raw bytes, decode Standard Webhooks secrets, cap body size - #21

Merged
TheGreatAxios merged 1 commit into
cl-9396-webhooks-align-repo-scaffolding-with-the-package-standardfrom
cl-9451-webhooks-verify-raw-body-and-decode-secrets
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
cl-9396-webhooks-align-repo-scaffolding-with-the-package-standardfrom
cl-9451-webhooks-verify-raw-body-and-decode-secrets

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

Closes CL-9451

  • Signatures are computed over c.req.arrayBuffer() bytes, so a sender that signs non-UTF-8 or unnormalized bytes verifies. The verified bytes are decoded strictly as UTF-8 and forwarded unchanged; a body that is not UTF-8 gets 415 instead of being mangled with replacement characters, since trigger mail carries text.
  • Standard Webhooks secrets are base64-decoded after stripping an optional whsec_ prefix. whsec_ secrets verify exactly as before. Compatibility call-out: 0.1 used an unprefixed secret as raw bytes (and the README said so), so an unprefixed secret is tried under both the spec key and the raw key. A whsec_ secret is never used raw.
  • verifyBearer rejects an empty secret.
  • Hono's bodyLimit caps the body at 1 MiB (413) before anything is read or hashed.

Tests for each were added first and failed before the fix.

Reject an empty bearer secret. Unprefixed Standard Webhooks secrets
still verify as raw bytes, as 0.1 read them. Refs CL-9451.
@TheGreatAxios
TheGreatAxios added this pull request to stack #18 September 27, 2026 02:07
@TheGreatAxios
TheGreatAxios merged commit 9895b56 into main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant