Skip to content

Add timestamp to webhook signature to prevent replay #693

Description

Description

X-COMEBACKHERE-Signature signs only the body, so a captured request can be replayed indefinitely.

The README and docs/webhooks.md show that the signature header is an HMAC-SHA256 of the raw body only. That proves the payload came from COMEBACKHERE, but it does not prove it is recent. Anyone who captures one signed request, from a log, a proxy, or a misconfigured receiver, can replay it later and it will still verify, which could trigger a duplicate fulfillment.

The common fix, used by Stripe and others, is to sign a timestamp together with the body and send the timestamp in its own header. Receivers then verify the signature and reject messages older than a tolerance such as five minutes. This issue changes the signing input to timestamp.body, adds an X-COMEBACKHERE-Timestamp header, and updates every documented verification snippet.

This is a breaking change for existing receivers. Propose a migration plan in the PR, for example sending both signature formats for one release.

Requirements and context

  • Add X-COMEBACKHERE-Timestamp header
  • Sign timestamp.body
  • Document a recommended 5 minute tolerance

Suggested execution

  1. Fork the repo and create a branch

    git checkout -b fix/webhook-timestamp-signature
  2. Implement changes

    • Update comebackhere-backend/src/services/webhooks.ts
    • Update the README and docs/webhooks.md verification snippet
  3. Test and commit

    • Update webhooks.test.ts
    • Verify the documented snippet against a real payload

Example commit message

fix(webhooks): include timestamp in signature

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Stellar WaveIssues in the Stellar wave program

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions