Skip to content

Reject malformed CoinPay webhook timestamps#40

Open
Autowebassat-blip wants to merge 1 commit into
profullstack:masterfrom
Autowebassat-blip:fix-coinpay-webhook-timestamp
Open

Reject malformed CoinPay webhook timestamps#40
Autowebassat-blip wants to merge 1 commit into
profullstack:masterfrom
Autowebassat-blip:fix-coinpay-webhook-timestamp

Conversation

@Autowebassat-blip

Copy link
Copy Markdown
Contributor

Fixes a CoinPay webhook validation edge case where timestamps with non-digit suffixes could pass the freshness check because parseInt accepted the numeric prefix.

Adds a contract test covering a signed malformed timestamp.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant