INNER CODE UNIT · Python

e2b_webhook

tomascupr/sandstorm · src/sandstorm/main.py:328

async def e2b_webhook(request: Request):
    """Receive E2B sandbox lifecycle events for logging and diagnostics."""
    body = await request.body()

    with get_tracer().start_as_current_span("webhook.e2b") as span:
        # Verify HMAC signature when a secret is configured
        if _WEBHOOK_SECRET:
            raw_signature = request.headers.get("e2b-signature", "")
            # Strip optional "sha256=" prefix (common webhook convention)
            signature = raw_signature.removeprefix("sha256=")
            expected = hmac.new(_WEBHOOK_SECRET.encode(), body, hashlib.sha256).hexdigest()
            if not hmac.compare_digest(signature, expected):
                logger.warning("E2B webhook: invalid signature — rejecting")
                sig_err = ValueError("invalid webhook signature")
                set_span_error(span, sig_err)
                record_error(error_type="webhook_signature")
                return JSONResponse({"error": "invalid signature"}, status_code=401)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…