[Backend] Add HMAC Signature Validation for Inbound Webhook Calls - #770
Merged
EDOHWARES merged 3 commits intoAug 1, 2026
Merged
Conversation
…e-synchronization Queries the database for the last processed ledger sequence when the in-memory state is uninitialized, detects gaps on reconnection, and sequentially catch-up replays missed ledgers.
|
@TochukwuJustice Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Collaborator
|
Nice implementation, LGTM! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
closes #582
Summary of Changes
Signature Validation Extractor (webhook_validation.rs): Implemented a reusable Axum ValidatedWebhook extractor to intercept incoming webhook requests, parse cryptographic headers (x-soroscope-signature, x-soroscope-timestamp, and x-soroscope-delivery), and verify the payload signature.
Replay Attack Mitigation: Enforced request freshness validation ensuring incoming webhook timestamps fall within a ±5-minute window (MAX_TIMESTAMP_SKEW_SECS = 300) compared to the server clock.
Constant-Time Verification: Utilized HmacSha256::verify_slice to verify the HMAC-SHA256 signature over .<body_bytes>, mitigating timing-based forgery attacks.
Router Configuration: Registered a new inbound webhook endpoint /api/v1/webhooks/incoming in main.rs protected by signature validation. Loaded the pre-shared secret key dynamically from the SOROSCOPE_INBOUND_WEBHOOK_SECRET environment variable or state Extensions.
Testing: Added unit and Axum integration tests validating signature verification, timestamp skew boundaries, and rejection of missing headers or incorrect signatures.
Reason for Changes
Inbound webhook endpoints previously lacked authentication, allowing unauthorized external services to forge event payloads. Validating HMAC SHA-256 signatures ensures only signed requests from trusted providers are processed.