Skip to content

Reject blank webhook secrets 🪿✨ - #1940

Draft
zacchua-stripe wants to merge 2 commits into
masterfrom
reject-blank-webhook-secrets
Draft

zacchua-stripe wants to merge 2 commits into
masterfrom
reject-blank-webhook-secrets

Conversation

@zacchua-stripe

Copy link
Copy Markdown
Contributor

Why?

Reject webhook secrets made entirely of ASCII whitespace so invalid configuration fails with the existing missing-secret errors instead of reaching HMAC verification.

What?

  • Webhook signature verification and StripeEventNotificationHandler now treat space, tab, CR, LF, form feed, and vertical tab-only values as blank while preserving nonblank secrets.

See Also

http://go/j/RUN_DEVSDK-3378

Configuration

  • skip-changefile: This PR is not a user-facing change, so there's no changefile.

Committed-By-Agent: goose
Orbit-Session-Id: a8a3ff0b-2818-4677-9877-6974eda81782
@zacchua-stripe
zacchua-stripe requested a review from a team as a code owner October 2, 2026 23:28
@zacchua-stripe
zacchua-stripe requested review from jar-stripe and removed request for a team October 2, 2026 23:28
@zacchua-stripe
zacchua-stripe marked this pull request as draft October 2, 2026 23:29
Committed-By-Agent: codex
Co-authored-by: codex <noreply@openai.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant