G3.5: accept platform.test_ping unverified — unverifiable by construction
All checks were successful
check / gate (push) Successful in 19s
canary / probe (push) Successful in 26s

Read the sender rather than guessing: Eternitas generates the webhook secret at
registration time and pings the URL to prove reachability BEFORE returning that
secret. The ping IS signed — with a secret the receiver cannot possibly hold
yet. Unverifiable by construction, not by oversight.

Accepting it is safe because the event is definitionally a no-op: nothing read,
nothing written, acted:false. Every event that changes anything still requires a
valid HMAC. The alternative, skip_validation:true, would permanently disable
reachability checking for this platform to solve a one-time ordering problem.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-12 15:36:03 -04:00
parent 5dd914b8a6
commit a094960da3
2 changed files with 20 additions and 12 deletions

View File

@@ -591,7 +591,7 @@ def test_g35_probe_acknowledgement_changes_nothing():
answers 200 but must never act, and anything claiming to be an event must
still be verified."""
src = (ROOT / "api" / "app" / "routes" / "webhooks.py").read_text()
probe = src[src.index("if not x_eternitas_event") : src.index("secret = settings")]
probe = src[src.index('if x_eternitas_event == "platform.test_ping"') : src.index("secret = settings")]
assert '"acted": False' in probe
assert "update(" not in probe and "commit" not in probe