noCV
REPLAY-105 · Reproduce delivery failures

Exercise signature rotation without accepting expired requests

Practice briefStoryAdvanced

During key rotation the receiver must accept old and new keys briefly, while still rejecting requests outside the timestamp tolerance. Add a table of rotation boundaries.

Focused work estimate
2h 15m + prerequisites
Priority in the scenario
High
Engineering practice
Security testing · Key rotation · Boundary cases

Estimated field mix

  • Quality engineering60%
  • Security40%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

An integration team closes incidents with screenshots of provider dashboards, then struggles to reproduce the same delivery sequence. Build a synthetic event corpus and replay runner against an allowlisted local receiver.

Setup prerequisites

  • Create a local receiver fixture with an inspectable event store.
  • Use generated test signing keys and synthetic payloads only.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Cases cover current key, overlap key, unknown key, and retired key.
  • Freshness boundaries are tested immediately inside and outside the documented tolerance.
  • Invalid signatures and stale timestamps produce no persisted business effect.

Implementation constraints

  • Use an injected clock and generated lab keys.
  • Verify signature checks occur before trusted event fields are consumed.

Verification to include

  • Accept both keys inside the overlap window and reject the retired key afterward.
  • Send a validly signed but stale event and a fresh tampered event; both must have zero effects.

Deliverables

  • Rotation boundary matrix and receiver assertions

Rollout and recovery

Run rotation cases before changing receiver key policy; keep retired test keys only in synthetic fixtures.

Value of the work

For the engineer: Practice protocol verification, controlled fault injection, and reproducible incident investigation.

For the team: Review concrete evidence that webhook consumers tolerate real delivery failure patterns.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.