you> add Stripe webhook signature verification to the billing route
belayTwo skills here. verify-webhook-signature is unearned, so you write it. add-route you've done alone three times, so I'll write that part after. Goal: reject any request whose signature doesn't match. What do you need first?
you> just write it, I'm in a hurry
hookblocked Edit(src/webhooks/verify.ts)
belayNot yet. This one's unearned. Want a hint?
you> ok. the raw body, before anything parses it
belayRight. Write it in your editor. Say done and I'll run the tests.
editoryou write src/webhooks/verify.ts · 38 lines · 9 min
you> done
vitest12 passed · witnessed
belayTests pass. Line 14 is a plain string compare. It returns on the first wrong byte, which leaks how close a guess got. What should it be?
you> a constant-time compare over the raw bytes
logbookunaided verify-webhook-signature · 1 of 3
belayRight. Change it. Now the route.
belayearned add-route · You've added routes alone three times. From now on I'll write them and you review.
editsrc/routes/webhooks.ts +22 −0· belay
belayOne question before it merges. What happens if the signature header is missing?
you> 400, before anything parses
belayRight. Merged.