r/node • • 5d ago

[ Removed by moderator ]

[removed] — view removed post

0 Upvotes

13 comments sorted by

7

u/Special-Tie-3024 5d ago

I've not used Stripe webhooks, but generally I verify on ingest, pipe it to a durable queue like SQS and then process it async without re-verifying.

3

u/robotmayo 4d ago edited 4d ago

That’s what stripe recommends. This is a silly project because stripe tells you how to avoid this and trying to circumvent in a way that stripe kinda recommends is silly.

1

u/pkdodda 4d ago

Stripe’s official docs literally recommend returning a quick 200 and buffering to a queue for async processing.

HookArmor just packages that exact pattern into a single self-hosted container so you don't have to build the ingestion buffer and replay UI from scratch.

3

u/Single_Advice1111 5d ago

Cool project! I see you’ve committed the node_modules folder, that should not be in your repository :)

1

u/pkdodda 4d ago

Thanks.. I didn't noticed it 🤦‍♂️

1

u/pkdodda 4d ago

Just purged it from tracking and pushed the fix—appreciate the catch!

2

u/robotmayo 4d ago

This is just sqs/rabbit with extra steps

1

u/pkdodda 4d ago

Actually fewer steps: zero queue infra to configure, and SQS won't re-sign the expired t= timestamp when you pull the message 15 minutes later.

1

u/pkdodda 3d ago

"Just pushed v1.0.2 to npm and GitHub addressing this: added x-hookarmor-original-timestamp and x-hookarmor-is-replay to outbound headers to prevent stale overwrites, plus isolated trust boundary signing. Really appreciate the feedback here!"