Skip to content

feat(webhooks): webhook signature verification tests — Issue #807 - #997

Merged
github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-807-webhook-signature-verification
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-807-webhook-signature-verification

Conversation

@Prozaks

@Prozaks Prozaks commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds a comprehensive test suite for the webhook signature verification service (Issue #807).

The core service at src/services/webhooks/verification.ts was already implemented. This PR adds thorough test coverage across 8 categories.

Test coverage (44 tests)

  1. HMAC-SHA256 signature generation — consistency, format ([a-f0-9]{64}), message format {timestamp}.{payload}, different inputs produce different signatures
  2. Verification success paths — valid sig, key rotation (multiple active secrets), expired secrets excluded, keyId filtering
  3. Verification failure paths — invalid sig, no active secrets, old timestamps, far-future timestamps, near-future within tolerance, empty/malformed signatures
  4. Replay protection boundaries — timestamp well inside tolerance passes, 1s beyond tolerance fails, custom toleranceSeconds respected
  5. Secret lifecycle management — create, getActiveSecretForProvider (newest), getActiveSecretsForProvider (sorted), rotate (grace period), deactivate, getAllWebhookSecrets
  6. Event queue management — queue, limit, retry capping at 3, marking processed, verified on valid retry
  7. Constant-time comparison — wrong length, all-zeros, one-bit flip all rejected
  8. Multi-provider isolation — all 4 providers work independently, secrets don't cross-contaminate

Test results

Test Files  1 passed
     Tests  44 passed
  Duration  ~1.25s

Closes #807

@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks is attempting to deploy a commit to the smartdevs17's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@github-actions
github-actions Bot merged commit a57a830 into Smartdevs17:main Sep 28, 2026
14 of 24 checks passed
…s17#807

- Add comprehensive vitest test suite (44 tests) covering:
  1. HMAC-SHA256 signature generation and format validation
  2. Signature verification success paths (key rotation, keyId filtering)
  3. Signature verification failure paths (invalid sig, no secrets,
     out-of-tolerance timestamps, empty/malformed signatures)
  4. Replay protection boundary conditions and custom toleranceSeconds
  5. Secret lifecycle management (create, rotate, deactivate, grace period)
  6. Event queue management (queue, limit, retry capping at 3, marking processed)
  7. Constant-time comparison (timing attack prevention)
  8. Multiple provider isolation (stripe/paypal/github/custom)

Closes Smartdevs17#807
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Implement webhook signature verification

1 participant