Skip to content

Security: Secure webhooks and prevent duplicate scheduled job executions - #4

Open
magqqgq wants to merge 1 commit into
sapiom:mainfrom
magqqgq:magqqgq-patch-2
Open

Security: Secure webhooks and prevent duplicate scheduled job executions#4
magqqgq wants to merge 1 commit into
sapiom:mainfrom
magqqgq:magqqgq-patch-2

Conversation

@magqqgq

@magqqgq magqqgq commented Aug 16, 2026

Copy link
Copy Markdown

This PR remediates a HIGH-severity vulnerability where the job webhook endpoint accepted unsigned requests and lacked idempotency controls. These issues previously allowed unauthenticated users to trigger Inngest events arbitrarily, causing duplicate job runs and unmetered consumption of paid services.

Changes:

Provider Signature Verification: Integrated @upstash/qstash receiver validation in app/api/jobs/webhook/route.ts to strictly verify QStash signatures before processing any payloads.

Error Propagation: The webhook now correctly returns a 500 status code upon inngest.send failures, properly allowing the upstream scheduler to retry delivery instead of swallowing errors and falsely returning a 200 OK.

Idempotency & Replay Prevention: Implemented an atomic SETNX-based lock (checkAndLockMessage) in lib/jobs.ts mapped to the Upstash-Message-Id header to persist one-time delivery IDs.

Atomic State Transition: Updated startJob to perform a state transition check. It now aggressively rejects duplicate execution requests if a job is already 'running' or 'complete'.

This PR remediates a HIGH-severity vulnerability where the job webhook endpoint accepted unsigned requests and lacked idempotency controls. These issues previously allowed unauthenticated users to trigger Inngest events arbitrarily, causing duplicate job runs and unmetered consumption of paid services.

Changes:  

Provider Signature Verification: Integrated @upstash/qstash receiver validation in app/api/jobs/webhook/route.ts to strictly verify QStash signatures before processing any payloads.

Error Propagation: The webhook now correctly returns a 500 status code upon inngest.send failures, properly allowing the upstream scheduler to retry delivery instead of swallowing errors and falsely returning a 200 OK.

Idempotency & Replay Prevention: Implemented an atomic SETNX-based lock (checkAndLockMessage) in lib/jobs.ts mapped to the Upstash-Message-Id header to persist one-time delivery IDs.

Atomic State Transition: Updated startJob to perform a state transition check. It now aggressively rejects duplicate execution requests if a job is already 'running' or 'complete'.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant