Make the retail webhook signature check fail closed and compare in constant time

Fixkamo-shared-library
Ya
25 Agosti 2026, 21:34 UTC
Mwandishi
Kamo
Ahadi ya
7022b25

validateSignature used to return true three ways without verifying anything: a null secret short-circuited, six of eleven provider types fell through default -> true, and validateHmac compared with String.equals, which leaks the position of the first mismatch through timing. The endpoint it guards (POST **************** is public and unauthenticated, so this check was its only guard. Now: a null/blank secret rejects, the provider->header switch is exhaustive over RetailProviderType with no default arm (a twelfth provider becomes a compile error, not a silent accept), and the HMAC compare decodes both sides to bytes and uses MessageDigest.isEqual.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei