-
Notifications
You must be signed in to change notification settings - Fork 0
V2-02: Freeze the webhook event and HMAC protocol #9
Copy link
Copy link
Open
Labels
apiREST API or webhook contractREST API or webhook contractsecuritySecurity boundary, threat model, or assurance workSecurity boundary, threat model, or assurance worksize:MMedium change with several acceptance pathsMedium change with several acceptance pathsv2Planned for the v0.2.0 pilot-ready releasePlanned for the v0.2.0 pilot-ready release
Milestone
Description
Metadata
Metadata
Assignees
Labels
apiREST API or webhook contractREST API or webhook contractsecuritySecurity boundary, threat model, or assurance workSecurity boundary, threat model, or assurance worksize:MMedium change with several acceptance pathsMedium change with several acceptance pathsv2Planned for the v0.2.0 pilot-ready releasePlanned for the v0.2.0 pilot-ready release
Outcome
Freeze a vendor-neutral, versioned webhook contract that authenticates exact request bytes and routes valid departures through the existing replay-safe case workflow.
Contract requirements
POST /v1/intake/webhooks/{source_id}.sha256=signature headers.employee.departure.authorizedevent schema.Acceptance criteria
Planning source
.dev/v2/WEBHOOK_SPEC.md.Dependencies
Blocked by #8. Contract changes discovered during M0 must be resolved before implementation issues open.