Skip to content

fix(billing): reject Stripe webhooks with no signature header - #864

Merged
neoneye merged 1 commit into
mainfrom
fix/stripe-webhook-signature-header
Aug 29, 2026
Merged

fix(billing): reject Stripe webhooks with no signature header#864
neoneye merged 1 commit into
mainfrom
fix/stripe-webhook-signature-header

Conversation

@neoneye

@neoneye neoneye commented Aug 29, 2026

Copy link
Copy Markdown
Member

Unblocks the typecheck failure on #860 (bump stripe 15.3.1 -> 15.5.1).

stripe 15.5.1 tightened Webhook.construct_event's sig_header parameter to str, so passing the possibly-absent Stripe-Signature header straight through fails pyright:

frontend_multi_user/src/billing.py:292:61 - error: Argument of type \"str | None\" cannot be assigned to parameter \"sig_header\" of type \"str\"

This raises explicitly when the header is missing. The raise lands in the existing except block, so behaviour is unchanged: logged, recorded with has_signature_header=False, answered with 400 - the same outcome construct_event produced for a missing signature.

Verified against stripe 15.5.1 with pyright: the old call pattern reproduces the CI error, the guarded one is clean.

After this merges, #860 needs a dependabot rebase to pick it up.

stripe 15.5.1 tightened the type of Webhook.construct_event's sig_header parameter to str, so passing the possibly-absent Stripe-Signature header straight through fails pyright. Raise explicitly when the header is missing instead.

The raise lands in the existing except block, so the response is unchanged: the rejection is logged, recorded with has_signature_header=False, and answered with 400 - the same outcome construct_event produced for a missing signature.

Unblocks the typecheck job on the stripe 15.5.1 bump (#860).
@neoneye
neoneye merged commit 39ce8a6 into main Aug 29, 2026
3 checks passed
@neoneye
neoneye deleted the fix/stripe-webhook-signature-header branch August 29, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant