Webhook ingress: collapse failure responses to one generic 401 - #448
Merged
TheGreatAxios merged 2 commits intoAug 29, 2026
Merged
TheGreatAxios merged 2 commits into
TheGreatAxios merged 2 commits into
Conversation
Assert unknown-trigger, disabled-trigger, and bad-signature all return the same 401 unauthorized body instead of the current 404/403/401 split, which lets a probe tell the failure modes apart.
Unknown trigger, disabled trigger, and bad/missing signature returned distinct 404/403/401 responses, contradicting the header comment's claim that failures are generic. All three now return the same 401 unauthorized body; the distinguishing detail stays in the server log line only. Fixes CL-7135.
TheGreatAxios
force-pushed
the
cl-7135-webhook-ingress-returns-404403401-by-failure-mode
branch
from
August 29, 2026 04:46
c0a3f1c to
40298c8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CL-7135 — https://linear.app/abklabs/issue/CL-7135
Problem
packages/webhook-triggers/src/ingress-routes.ts's header comment(lines 1-9) says failure responses are "deliberately generic" so a
probe against a wrong triggerId can't distinguish "no such trigger"
from "wrong secret" — but the handler (
:52-82, pre-fix) actuallyreturned distinct 404 (unknown trigger), 403 (disabled trigger), and
401 (bad/missing signature) responses, which is exactly the
distinguishing signal the comment says the endpoint withholds.
Change
all return the same 401
unauthorizedresponse body(
{"error":{"code":"unauthorized","message":"invalid or missing signature"}}) via a sharedunauthorizedResponse()helper.server-side log line only, unchanged.
400 bad_request(malformed JSON body) and Hono's default405 (method not allowed) as-is: both only fire after a trigger is
proven to exist and be correctly signed, so they can't be used to
probe for trigger existence — a caller must already know the
correct secret to reach them.
Caller check
grep -rn "not_found\|forbidden" packages/webhook-triggers apps/web/srcturns up
not_found/forbiddenonly inmanagement-routes.ts(theseparate, session-authenticated management API, untouched by this
change) and its tests.
apps/web/src/webhook-triggers-api.tsonlybuilds the ingress URL for display (
webhookTriggerUrl) — it nevercalls the ingress route or branches on its response, so nothing in
this repo relies on the removed 404/403 distinction.
Tests
packages/webhook-triggers/test/ingress-routes.test.ts: the threefailure-mode tests (unknown trigger, disabled trigger, missing
signature, wrong-secret signature) now assert status 401 and an
identical body. Confirmed red against the pre-fix handler (404/403
returned) and green after.