sudsy
55
Assuming you’re replying to my post pointing out that the swagger endpoint can be disabled, I was not in any way suggesting that it would protect from fake calls. I was simply responding to just one of the concerns raised by the OP.
If you haven’t already, you might benefit from reading the entire thread - in particular, the post where I outline the my personal strategy for reducing the risk of fake calls. (And here’s a screenshot to go with it.)
That was already mentioned in this thread, and it’s not the approach I would take (for reasons others have already pointed out in this thread).
It doesn’t. It can, however, add a bit of obscurity as part of a multi-faceted approach to reducing the risk of malicious calls. Even with that setting enabled, though, I feel comfortable with the steps I’ve taken for my sites.
I have no intention of adding extraneous authenticated calls back to Stripe in the context of a webhook.
2 Likes