Generate signatures from raw bytes and an injected clock
The receiver accepts fresh signatures but rejects replay fixtures because timestamp generation depends on the wall clock. Add a deterministic signer for the lab contract.
- Focused work estimate
- 1h 30m + prerequisites
- Priority in the scenario
- High
- Engineering practice
- HMAC · Protocol testing · Clock control
Estimated field mix
- Quality engineering50%
- Security30%
- Integrations20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
An integration team closes incidents with screenshots of provider dashboards, then struggles to reproduce the same delivery sequence. Build a synthetic event corpus and replay runner against an allowlisted local receiver.
Setup prerequisites
- Create a local receiver fixture with an inspectable event store.
- Use generated test signing keys and synthetic payloads only.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Signing covers the timestamp and exact raw body according to the documented lab protocol.
- The clock and generated test key are supplied explicitly.
- Signature values and secret keys are not printed in ordinary run logs.
Implementation constraints
- Use an established HMAC implementation and document byte encoding.
Verification to include
- Check a fixed key/time/body vector against an independently calculated digest.
- Change only whitespace or timestamp and confirm the signature changes.
Deliverables
- Test signer and fixed signature vectors
Rollout and recovery
Restrict signing to the local lab adapter; rotate fixture keys by changing the versioned test configuration.
Value of the work
For the engineer: Practice protocol verification, controlled fault injection, and reproducible incident investigation.
For the team: Review concrete evidence that webhook consumers tolerate real delivery failure patterns.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.