noCV
REPLAY-107 · Make incidents repeatable

Block replay targets outside the approved local receiver

Practice briefBugAdvanced

A fixture author added a destination that points at a metadata endpoint. Move destination control out of fixture data and enforce a fixed local target policy.

Focused work estimate
2h 30m + prerequisites
Priority in the scenario
High
Engineering practice
SSRF prevention · Network boundaries · Input validation

Estimated field mix

  • Security60%
  • Quality engineering20%
  • Networking20%

Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.

Your next step

Review it, then add it to your workspace.

The board opens an editable draft; nothing is saved until you confirm it. Sign-in and workspace permissions apply, and Demo boards remain ephemeral.

Project context

An integration team closes incidents with screenshots of provider dashboards, then struggles to reproduce the same delivery sequence. Build a synthetic event corpus and replay runner against an allowlisted local receiver.

Setup prerequisites

  • Create a local receiver fixture with an inspectable event store.
  • Use generated test signing keys and synthetic payloads only.

Preceding work

Complete these dependencies, or supply their agreed outputs before taking this ticket.

Acceptance criteria

  • Only configured loopback receiver hosts and ports can be selected.
  • Redirects are rejected and userinfo, ambiguous IP syntax, and non-HTTP schemes are denied.
  • The resolved address is validated at connection time; rejected destinations send zero payload bytes, and redirect responses trigger no follow-up request.

Implementation constraints

  • Keep replay configuration separate from imported fixture content.
  • Bound request body size and connection timeout.

Verification to include

  • Replay to the configured local receiver successfully.
  • Reject an external host, unapproved port, and alternate IP notation before any receiver request; for a redirect, allow one request to the approved receiver and assert zero requests to its redirect target.

Deliverables

  • Destination policy and SSRF regression cases

Rollout and recovery

Make the target policy mandatory before exposing fixture import; disable replay on target-validation uncertainty.

Value of the work

For the engineer: Practice protocol verification, controlled fault injection, and reproducible incident investigation.

For the team: Review concrete evidence that webhook consumers tolerate real delivery failure patterns.

Evidence boundaries

Outcome Evidence: Tests, patches, and runbooks are requested deliverables. They become Outcome Evidence only through a qualified Mission and immutable Evidence IDs.

Ownership Evidence: Independent adaptation must be observed under a declared verification policy and cite immutable Evidence IDs. Completing a planning ticket establishes no Ownership Evidence.