Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify signature before deserializing event #578

Merged
merged 1 commit into from
May 31, 2019

Conversation

ob-stripe
Copy link
Contributor

r? @brandur-stripe
cc @stripe/api-libraries @rfk

Verify the signature from the Stripe-Signature header before deserializing the JSON payload into an Event instance.

Fixes #577.

Copy link
Contributor

@brandur-stripe brandur-stripe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yep, good call. LGTM!

@ob-stripe ob-stripe merged commit a48713f into master May 31, 2019
@ob-stripe ob-stripe deleted the ob-check-signature-first branch May 31, 2019 17:31
@ob-stripe
Copy link
Contributor Author

Released as 2.29.1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Check webhook signature before constructing Event from the payload
3 participants