Skip to content

Fix webhook signature verification for Python 3.11+ and add CI test coverage - #49

Open
cobanfurkanx wants to merge 1 commit into
craftgate:masterfrom
cobanfurkanx:fix-webhook-signature-verification
Open

cobanfurkanx wants to merge 1 commit into
craftgate:masterfrom
cobanfurkanx:fix-webhook-signature-verification

Conversation

@cobanfurkanx

Copy link
Copy Markdown

Summary

In Python 3.11+, string formatting on \Enum\ types returns the enum representation (e.g. \WebhookEventType.API_VERIFY_AND_AUTH) instead of the member value (\API_VERIFY_AND_AUTH).

Because \HookAdapter.is_webhook_verified\ relied on string formatting of \webhook_data.event_type\ and \webhook_data.status, the computed HMAC payload differed from the signature on Python 3.11/3.12, causing \is_webhook_verified\ to fail.

Changes

  • Extract .value\ from \webhook_data.event_type\ and \webhook_data.status\ via \getattr, supporting both \Enum\ instances and plain strings.
  • Add test cases in \ est_hook_sample.py\ for string values and \None\ argument handling.
  • Include \ ests.test_hook_sample\ in .github/workflows/craftgate-build.yml\ so webhook verification is verified across the Python 3.7-3.12 test matrix in CI.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant