G3.5: accept platform.test_ping unverified — unverifiable by construction
Read the sender rather than guessing: Eternitas generates the webhook secret at registration time and pings the URL to prove reachability BEFORE returning that secret. The ping IS signed — with a secret the receiver cannot possibly hold yet. Unverifiable by construction, not by oversight. Accepting it is safe because the event is definitionally a no-op: nothing read, nothing written, acted:false. Every event that changes anything still requires a valid HMAC. The alternative, skip_validation:true, would permanently disable reachability checking for this platform to solve a one-time ordering problem. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -591,7 +591,7 @@ def test_g35_probe_acknowledgement_changes_nothing():
|
||||
answers 200 but must never act, and anything claiming to be an event must
|
||||
still be verified."""
|
||||
src = (ROOT / "api" / "app" / "routes" / "webhooks.py").read_text()
|
||||
probe = src[src.index("if not x_eternitas_event") : src.index("secret = settings")]
|
||||
probe = src[src.index('if x_eternitas_event == "platform.test_ping"') : src.index("secret = settings")]
|
||||
assert '"acted": False' in probe
|
||||
assert "update(" not in probe and "commit" not in probe
|
||||
|
||||
|
||||
Reference in New Issue
Block a user