Feature request: Add HMAC signature support for feedback URLs
Open
- Dominant language
- Go
- Stars
- 8.8k
- Forks
- 887
- PR merge metrics
- No merged PRs in 30d
Description
Hi there,
Would it be possible for HMAC signature verification support to be added to this for the feedback URL payloads? This is a really cool project but unfortunately currently is missing integrity verification for feedback events a receiver would encounter.
Contributor guide
No contributing guide indexed for this repository
Research direction
No files, tests, or entry points are named in the issue. Start by locating the feedback URL payload generation and receiving paths, then clarify the signing format, key configuration, and failure behavior with maintainers. Done means feedback payload integrity can be verified through HMAC without breaking existing URL handling.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- backend, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 42/100