Skip to content

Implement Apple JWS notification verification - #36

Open
singhaditya21 wants to merge 1 commit into
mainfrom
feat/apple-jws-verification-15564359096076898345
Open

Implement Apple JWS notification verification#36
singhaditya21 wants to merge 1 commit into
mainfrom
feat/apple-jws-verification-15564359096076898345

Conversation

@singhaditya21

Copy link
Copy Markdown
Owner

Implemented cryptographic verification for Apple App Store Server Notifications V2. This includes:

  1. Fetching and storing the Apple Root CA - G3 certificate.
  2. Implementing a robust verification utility that checks:
    • JWS header x5c presence and algorithm (ES256).
    • Certificate chain validity (each cert signed by the next).
    • Chain trust anchor (last cert signed by Apple Root CA).
    • JWS signature using the leaf certificate's public key.
  3. Updating the webhook handler to enforce verification before processing notifications.
  4. Adding a comprehensive test suite that generates a temporary PKI to verify the logic against valid and invalid chains/signatures.

PR created automatically by Jules for task 15564359096076898345 started by @singhaditya21

- Added `backend/payment-service/src/utils/apple-cert-verifier.js` to handle JWS signature and certificate chain verification.
- Added Apple Root CA G3 certificate at `backend/payment-service/src/certs/AppleRootCA-G3.pem`.
- Updated `backend/payment-service/src/routes/apple-webhook.js` to use the new verification logic.
- Added `backend/payment-service/tests/test-apple-verifier.js` for unit testing the verification logic using self-signed certs.
- Verified that the implementation correctly validates chains and signatures.

Co-authored-by: singhaditya21 <53948039+singhaditya21@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@singhaditya21

Copy link
Copy Markdown
Owner Author

Reviewed, leaving open. This is the right thing to do — the Apple webhook currently trusts unverified JWS payloads, which is a real security gap.

Two notes:

  1. It commits AppleRootCA-G3.pem. That is a public root certificate so it is not sensitive, but pinning a root in the repo means a silent expiry risk later — worth a comment in the file recording where it came from and when it expires.
  2. backend/payment-service has no test runner wired into CI. The test-apple-verifier.js script here only helps if something runs it; the workflow currently covers the Python API only.

I have not merged it because I cannot exercise the verification path without real Apple notification payloads, and getting signature verification subtly wrong is worse than not having it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant