Stripe Webhook in Bubble - big vulnerability to all apps that use them

Thanks for the reply, @Jici.

But HOW? I tried a couple approaches but couldn’t come up with a way to access the raw payload (request body).

The issue is not implementing the verification code, but rather how to get access to the raw payload - i.e. how to get the raw request data from a Bubble endpoint workflow into the context of a plugin.

Or are you saying there’s a way for a plugin itself to function as an endpoint? Maybe there’s something I’m missing.

It almost seems like something that Bubble would have to implement as an internal plugin; and if they did, I would recommend it be a separate plugin that implements an action. That way, it could be used with any Stripe plug-in.

Not that I can see.

1 Like