Block replay targets outside the approved local receiver
A fixture author added a destination that points at a metadata endpoint. Move destination control out of fixture data and enforce a fixed local target policy.
- Focused work estimate
- 2h 30m + prerequisites
- Priority in the scenario
- High
- Engineering practice
- SSRF prevention · Network boundaries · Input validation
Estimated field mix
- Security60%
- Quality engineering20%
- Networking20%
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Review it, then add it to your workspace.
The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.
Project context
An integration team closes incidents with screenshots of provider dashboards, then struggles to reproduce the same delivery sequence. Build a synthetic event corpus and replay runner against an allowlisted local receiver.
Setup prerequisites
- Create a local receiver fixture with an inspectable event store.
- Use generated test signing keys and synthetic payloads only.
Preceding work
Complete these dependencies, or supply their agreed outputs before taking this ticket.
Acceptance criteria
- Only configured loopback receiver hosts and ports can be selected.
- Redirects are rejected and userinfo, ambiguous IP syntax, and non-HTTP schemes are denied.
- The resolved address is validated at connection time; rejected destinations send zero payload bytes, and redirect responses trigger no follow-up request.
Implementation constraints
- Keep replay configuration separate from imported fixture content.
- Bound request body size and connection timeout.
Verification to include
- Replay to the configured local receiver successfully.
- Reject an external host, unapproved port, and alternate IP notation before any receiver request; for a redirect, allow one request to the approved receiver and assert zero requests to its redirect target.
Deliverables
- Destination policy and SSRF regression cases
Rollout and recovery
Make the target policy mandatory before exposing fixture import; disable replay on target-validation uncertainty.
Value of the work
For the engineer: Practice protocol verification, controlled fault injection, and reproducible incident investigation.
For the team: Review concrete evidence that webhook consumers tolerate real delivery failure patterns.
Evidence boundaries
Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.
Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.