Skip to content

fix(webhooks): raise ValueError for non-ASCII signature in Webhooks.verify - #290

Merged
dielduarte merged 4 commits into
resend:mainfrom
RaphaelFakhri:fix/webhook-verify-non-ascii-signature
Oct 3, 2026
Merged

dielduarte merged 4 commits into
resend:mainfrom
RaphaelFakhri:fix/webhook-verify-non-ascii-signature

Conversation

@RaphaelFakhri

@RaphaelFakhri RaphaelFakhri commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Webhooks.verify raises TypeError instead of ValueError when the svix-signature header contains a non-ASCII character, because hmac.compare_digest rejects non-ASCII str arguments. The fix compares the UTF-8 encoded bytes, so a malformed signature falls through to ValueError("no matching signature found"), the documented failure mode.

Changes

  • Encode both signatures to bytes before hmac.compare_digest in resend/webhooks/_webhooks.py.
  • Add test_verify_non_ascii_signature to tests/webhooks_test.py.

Testing

  • The new test fails before the fix (TypeError) and passes after.
  • pytest tests: 700 passed.
  • flake8 --max-line-length=130 resend is clean.

Summary by cubic

Update Webhooks.verify so a non-ASCII svix-signature header raises the documented ValueError("no matching signature found") instead of a TypeError.

  • Compares UTF-8 encoded bytes in hmac.compare_digest so malformed input falls through to the documented failure mode, covering both non-ASCII characters and unpaired surrogates that arrive via surrogateescape decoding.
  • Adds regression tests for non-ASCII and unpaired-surrogate signatures.
  • Bumps the package version to 2.49.1.

Written for commit e514de0. Summary will update on new commits.

Review in cubic

@github-actions github-actions Bot added the linear-synced PR has been synced to Linear label Sep 29, 2026
dielduarte and others added 3 commits October 2, 2026 21:57
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.04%. Comparing base (7f1acd0) to head (e514de0).
⚠️ Report is 239 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff             @@
##             main     #290       +/-   ##
===========================================
+ Coverage   82.66%   97.04%   +14.37%     
===========================================
  Files           4       74       +70     
  Lines          75     4266     +4191     
===========================================
+ Hits           62     4140     +4078     
- Misses         13      126      +113     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@dielduarte
dielduarte merged commit 4ce466e into resend:main Oct 3, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

linear-synced PR has been synced to Linear

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants