INNER CODE UNIT · Python
e2b_webhook
tomascupr/sandstorm · src/sandstorm/main.py:328
async def e2b_webhook(request: Request):
"""Receive E2B sandbox lifecycle events for logging and diagnostics."""
body = await request.body()
with get_tracer().start_as_current_span("webhook.e2b") as span:
# Verify HMAC signature when a secret is configured
if _WEBHOOK_SECRET:
raw_signature = request.headers.get("e2b-signature", "")
# Strip optional "sha256=" prefix (common webhook convention)
signature = raw_signature.removeprefix("sha256=")
expected = hmac.new(_WEBHOOK_SECRET.encode(), body, hashlib.sha256).hexdigest()
if not hmac.compare_digest(signature, expected):
logger.warning("E2B webhook: invalid signature — rejecting")
sig_err = ValueError("invalid webhook signature")
set_span_error(span, sig_err)
record_error(error_type="webhook_signature")
return JSONResponse({"error": "invalid signature"}, status_code=401)