Your webhook sender is an SSRF gadget
Most writing about webhook security is about the receiving end. Verify the signature, compare in constant time, reject a stale timestamp. All correct, all about the wrong direction for the problem I w
paymos-engineering.hashnode.dev5 min read