Skip to content

[Backend] Add HMAC Signature Validation for Inbound Webhook Calls - #770

Merged
EDOHWARES merged 3 commits into
SoroLabs:mainfrom
TochukwuJustice:feature/issue-24-webhook-security
Aug 1, 2026
Merged

[Backend] Add HMAC Signature Validation for Inbound Webhook Calls#770
EDOHWARES merged 3 commits into
SoroLabs:mainfrom
TochukwuJustice:feature/issue-24-webhook-security

Conversation

@TochukwuJustice

Copy link
Copy Markdown
Contributor

closes #582

Summary of Changes

Signature Validation Extractor (webhook_validation.rs): Implemented a reusable Axum ValidatedWebhook extractor to intercept incoming webhook requests, parse cryptographic headers (x-soroscope-signature, x-soroscope-timestamp, and x-soroscope-delivery), and verify the payload signature.
Replay Attack Mitigation: Enforced request freshness validation ensuring incoming webhook timestamps fall within a ±5-minute window (MAX_TIMESTAMP_SKEW_SECS = 300) compared to the server clock.
Constant-Time Verification: Utilized HmacSha256::verify_slice to verify the HMAC-SHA256 signature over .<body_bytes>, mitigating timing-based forgery attacks.
Router Configuration: Registered a new inbound webhook endpoint /api/v1/webhooks/incoming in main.rs protected by signature validation. Loaded the pre-shared secret key dynamically from the SOROSCOPE_INBOUND_WEBHOOK_SECRET environment variable or state Extensions.
Testing: Added unit and Axum integration tests validating signature verification, timestamp skew boundaries, and rejection of missing headers or incorrect signatures.

Reason for Changes

Inbound webhook endpoints previously lacked authentication, allowing unauthorized external services to forge event payloads. Validating HMAC SHA-256 signatures ensures only signed requests from trusted providers are processed.

…e-synchronization

Queries the database for the last processed ledger sequence when the
in-memory state is uninitialized, detects gaps on reconnection, and
sequentially catch-up replays missed ledgers.
@drips-wave

drips-wave Bot commented Jul 30, 2026

Copy link
Copy Markdown

@TochukwuJustice Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@EDOHWARES

Copy link
Copy Markdown
Collaborator

Nice implementation, LGTM!

@EDOHWARES
EDOHWARES merged commit 1235bfd into SoroLabs:main Aug 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Backend] Add HMAC Signature Validation for Inbound Webhook Calls

2 participants