Skip to content

Support signed plugin webhooks with raw request bodies - #10

Merged
rondlite merged 2 commits into
mainfrom
fix/plugin-webhook-signatures
Sep 13, 2026
Merged

rondlite merged 2 commits into
mainfrom
fix/plugin-webhook-signatures

Conversation

@rondlite

Copy link
Copy Markdown
Collaborator

Plugins cannot verify signed webhook requests while the loader hides HTTP headers and parses the request body as JSON. Add opt-in rawBody: true routes that receive original bytes and headers, enabling endpoint-secret verification in the private membership payment plugin.

The buffer parser is encapsulated per route and retains Fastify's body-size limit. Existing routes retain JSON parsing, schema validation, authentication, and error mapping. SDK 1.0.10 exposes the optional transport fields; installations also need this server change, since upgrading the SDK alone does not update an existing server image.

Validation: server TypeScript build; all 14 plugin-route integration tests, including exact UTF-8/whitespace bytes, headers, malformed JSON, body limits and ordinary-route isolation; SDK suite and added opt-in contract test passed. The private payment plugin additionally passes 34 tests including real Stripe signatures, changed payloads, wrong/missing secrets, stale timestamps, duplicate delivery, and checkout refusal without a webhook secret.

@rondlite
rondlite marked this pull request as ready for review September 13, 2026 21:13
@rondlite
rondlite merged commit 0086d4f into main Sep 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant