test(webhook-signature): add regression coverage for WEBHOOK_SIGNATURE_HEADER failure handling #1051 - #1170
Open
Chulexino wants to merge 2 commits into
Open
test(webhook-signature): add regression coverage for WEBHOOK_SIGNATURE_HEADER failure handling #1051#1170Chulexino wants to merge 2 commits into
Chulexino wants to merge 2 commits into
Conversation
…E_HEADER failure handling (RevoraOrg#1051) Pins the explicit empty-result / failure branches named in issue RevoraOrg#1051 so a silent behaviour change fails CI instead of reaching webhook receivers. Test-only change: src/lib/webhookSignature.ts and its public contract are untouched. Exercised cases (50 new tests): - :156 extractSignatureFromHeaders undefined result (absent, unset, empty array, null, non-string, mixed-case key) plus the neighbouring normal path (candidate priority, every supported header name, empty string verbatim) - :214/:218/:221/:234 parseExpiryTimestamp undefined branches, the 1e11 seconds/ms cut-off (inclusive on the ms side), 0 vs unset, anchored numeric string regex - verifyWebhook missing-signature contract: deterministic, non-leaking MISSING_SIGNATURE, ordered after the payload-size check and before the timestamp/replay check - verifyWebhookPayloadDualKey expiry coupling (pinned fail-open, expired flag, Infinity boundary) - verifyWebhookPayload malformed signature-container boundaries (fail closed, equal-length multi-byte value absorbed by the timingSafeEqual guard) Results: - npx jest src/lib/webhookSignature.regression.test.ts -> 50/50 passed - npm run test:coverage:webhook-signature (new script) -> 190/190 passed; src/lib/webhookSignature.ts = 100% stmts / 97.29% branches / 100% funcs / 100% lines against a 95% gate - surrounding suite (webhookSignature, webhookAuth, webhookService, outboxDispatcher, outboxHmacRotationService) -> 334/334 passed - eslint on the new file: 0 problems; tsc error count unchanged (250 before and after, none in the webhookSignature files) Pre-existing and reproduced with this branch stashed: the src/routes/health.test.ts:1126 failure and the npm run audit:ci advisories. Security assumptions, abuse paths and residual risk: docs/webhook-signature-header-regression.md
|
@Chulexino Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # package.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Overview
This PR adds a focused regression suite for the
WEBHOOK_SIGNATURE_HEADERfailure and empty-result paths insrc/lib/webhookSignature.ts(issue #1051), so a silent behaviour change is caught in CI instead of reaching webhook receivers. Test-only change — the implementation file is byte-identical; the existing public contract is pinned, not modified.Related Issue
Closes #1051
Changes
🧪 Webhook Signature Regression Suite
[ADD]
src/lib/webhookSignature.regression.test.tswebhookSignature.ts:156—extractSignatureFromHeadersreturnsundefinedfor absent, unset, empty-array,null, non-string and mixed-case header keys — plus the neighbouring normal path (candidate priority order, every supported header name, empty string returned verbatim).parseExpiryTimestampundefinedbranches at:214(unset),:218(invalidDate),:221(NaN) and:234(out-of-contract runtime types), together with the boundary rules: the1e11seconds/milliseconds cut-off (inclusive on the ms side),0kept distinct from "unset", and the anchored^\d+$numeric-string branch.MISSING_SIGNATUREfor empty/unset/empty-array/empty-string/custom-name-absent headers, ordered after the payload-size check and before the timestamp/replay check, and thrown byassertValidWebhookSignature.verifyWebhookPayloadDualKeyexpiry coupling: unparseable /NaNnextSecretExpiryfails open (documented and deliberate), a passed deadline flipsnextKeyExpired,Infinitynever expires, and nonextSecretkeeps the current key only.verifyWebhookPayloadmalformed signature-container boundaries (fail closed), including an equal-character-length multi-byte value that makescrypto.timingSafeEqualthrow — the defensivecatchabsorbs it, so there is no unhandledRangeError.[ADD]
docs/webhook-signature-header-regression.mdInfinity, negative deadlines), the exercised cases with measured results, and residual risk for reviewers.[MODIFY]
package.jsontest:coverage:webhook-signature— the focused + surrounding suites with a--coverageThresholdof 95% on statements/lines/functions/branches forsrc/lib/webhookSignature.ts.Verification Results
:156,:214,:218,:221,:234evidence lines and their neighbouring normal pathssrc/lib/webhookSignature.tsis untouched (+686/-0 across 3 files)MISSING_SIGNATUREcodes/messages, fixed failure ordering, explicit boundary tables (1e11,0vs unset,Infinity)tsccount unchanged, alert mappings OK — the pre-existing repo-wide build/lint/audit failures are documented indocs/webhook-signature-header-regression.md§5Security notes
MISSING_SIGNATUREis returned, nevervalid: true, and the failure payload carries no key material (asserted).nextSecretExpiryfails open,Infinitymeans never-expiring, and negative numeric deadlines take the seconds branch.