Skip to content

fix(verify): reject a zero-length signing key instead of throwing - #23

Merged
TheGreatAxios merged 1 commit into
mainfrom
cl-9457-webhooks-zero-length-key
Sep 27, 2026
Merged

TheGreatAxios merged 1 commit into
mainfrom
cl-9457-webhooks-zero-length-key

Conversation

@TheGreatAxios

Copy link
Copy Markdown
Contributor

An empty standard-webhooks secret ("" or whsec_) or an empty Slack secret made WebCrypto throw on a zero-length HMAC key, so the hook answered 500 instead of 401.

Changes

  • verifyStandardWebhooks skips zero-length keys and verifySlack rejects an empty secret, so both return false (401).
  • Tests (each fails before the fix): "" and whsec_ under standard-webhooks, and an empty Slack secret.
  • README: an unprefixed secret that is valid base64 is tried decoded first, then raw; an empty secret never verifies; a crash between claiming a replay key and forwarding holds the key until it expires with its timestamp window.

Checks

bun run check, bun run build and the Node pack smoke pass locally; test:e2e needs Postgres and runs in CI.

Closes CL-9457

An empty standard-webhooks or Slack secret made WebCrypto throw on a zero-length HMAC key, so the hook answered 500. It now fails verification with 401. The README says an unprefixed base64 secret is tried decoded first, then raw, and that a crash between claiming a replay key and forwarding holds the key until it expires.

Closes CL-9457
@TheGreatAxios
TheGreatAxios merged commit cdc6c6d into main Sep 27, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant