levi2
March 17, 2025, 9:21am
3
From what I’m now reading elsewhere, this is just Bubble breaking things, they’re probably aware, and there’s no telling even if they are aware that they’re planning to fix it.
Stripe recommends the verification of all webhook messages. This is important to ensure that Stripe sent the message, not someone else.
Stripe generates signatures for each message. According to Stripe documentation, the Stripe-Signature header included in each signed event contains a timestamp and one or more signatures that you must verify. The timestamp is prefixed by t= , and each signature is prefixed by a scheme . Schemes start with v , followed by an integer. Currently, the only valid li…