T09 · Insecure Skill Coding Practices
- Location
scripts/sendgrid_webhook.py:123- Finding
Webhook authentication is optional and fails open when cryptographic verification is unavailable
- Content
View full analysis
bool: """Verify SendGrid webhook signature using ECDSA.""" if not CRYPTO_AVAILABLE: log("Cryptography library not available - skipping signature verification", "WARN") return True ``` ```python # Signature verification public_key = get_webhook_public_key() if public_key: signature = self.headers.get("X-Twilio-Email-Event-Webhook-Signature", "").strip() timestamp = self.headers.get("X-Twilio-Email-Event-Webhook-Timestamp", "").strip() if not signature or not timestamp: log("Webhook denied: missing signature headers", "WARN") self.send_response(403) self.send_header("Content-Type", "application/json") self.end_headers() self.wfile.write(json.dumps({"status": "denied", "reason": "missing_signature"}).encode()) return if not validate_timestamp(timestamp): log("Webhook denied: timestamp invalid", "WARN") self.send_response(403) self.send_header("Content-Type", "application/json") self.end_headers() self.wfile.write(json.dumps({"status": "denied", "reason": "timestamp_invalid"}).encode()) return if not verify_signature(raw_body, signature, timestamp, public_key): log("Webhook denied: signature invalid", "WARN") self.send_response(403) self.send_header("Content-Type", "application/json") self.end_headers() self.wfile.write(json.dumps({"status": "denied", "reason": "signature_invalid"}).encode()) return log("Webhook signature verified ✓") else: log("Webhook received (no signature verification configured)", "WARN") ``` ### Tec ...[truncated 2329 chars]- Remediation
View remediation
