Description
X-COMEBACKHERE-Signature signs only the body, so a captured request can be replayed indefinitely.
The README and docs/webhooks.md show that the signature header is an HMAC-SHA256 of the raw body only. That proves the payload came from COMEBACKHERE, but it does not prove it is recent. Anyone who captures one signed request, from a log, a proxy, or a misconfigured receiver, can replay it later and it will still verify, which could trigger a duplicate fulfillment.
The common fix, used by Stripe and others, is to sign a timestamp together with the body and send the timestamp in its own header. Receivers then verify the signature and reject messages older than a tolerance such as five minutes. This issue changes the signing input to timestamp.body, adds an X-COMEBACKHERE-Timestamp header, and updates every documented verification snippet.
This is a breaking change for existing receivers. Propose a migration plan in the PR, for example sending both signature formats for one release.
Requirements and context
- Add
X-COMEBACKHERE-Timestamp header
- Sign
timestamp.body
- Document a recommended 5 minute tolerance
Suggested execution
-
Fork the repo and create a branch
git checkout -b fix/webhook-timestamp-signature
-
Implement changes
- Update
comebackhere-backend/src/services/webhooks.ts
- Update the README and
docs/webhooks.md verification snippet
-
Test and commit
- Update
webhooks.test.ts
- Verify the documented snippet against a real payload
Example commit message
fix(webhooks): include timestamp in signature
Description
X-COMEBACKHERE-Signaturesigns only the body, so a captured request can be replayed indefinitely.The README and
docs/webhooks.mdshow that the signature header is an HMAC-SHA256 of the raw body only. That proves the payload came from COMEBACKHERE, but it does not prove it is recent. Anyone who captures one signed request, from a log, a proxy, or a misconfigured receiver, can replay it later and it will still verify, which could trigger a duplicate fulfillment.The common fix, used by Stripe and others, is to sign a timestamp together with the body and send the timestamp in its own header. Receivers then verify the signature and reject messages older than a tolerance such as five minutes. This issue changes the signing input to
timestamp.body, adds anX-COMEBACKHERE-Timestampheader, and updates every documented verification snippet.This is a breaking change for existing receivers. Propose a migration plan in the PR, for example sending both signature formats for one release.
Requirements and context
X-COMEBACKHERE-Timestampheadertimestamp.bodySuggested execution
Fork the repo and create a branch
Implement changes
comebackhere-backend/src/services/webhooks.tsdocs/webhooks.mdverification snippetTest and commit
webhooks.test.tsExample commit message
fix(webhooks): include timestamp in signature