Skip to content

fix(docs): example webhook secrets flagged by GitGuardian as Stripe secret #180

Description

@nicolasiscoding

Change type

Emergency — hotfix

Risk / impact

Low

Security impact assessed?

Yes — described below

Details — description & full context

GitGuardian alert (2026-09-23 16:02:48 UTC, TurboDocx/Docs) flagged a "Stripe Webhook Secret". Source: the example responses on docs/API/create-webhook.api.mdx and docs/API/regenerate-webhook-secret.api.mdx, added in the API-reference enrichment (#171, commit 645291e) and merged to develop.

Assessment:

  • The values are in TurboDocx's own outbound-webhook secret format (whsec_ + 64 hex = 70 chars, generated in RapidDocxBackend src/models/Webhook/index.ts), not Stripe's shorter format. GitGuardian labels any whsec_ value as Stripe. The Stripe → Lambda billing webhook is not involved.
  • The values were written by a docs agent reading backend code only (no database, Stripe, or config access), so they are expected to be invented examples. Owner to confirm with a SHA-256 match against the production webhooks.secret column (hashes of the two values recorded in the investigating session; 0 rows = fake).
  • Not live on docs.turbodocx.com: develop had not been promoted to main.

Fix: replace both example values with the placeholder whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET. A scan of docs/, src/, and static/ on develop found no other realistic whsec_ values.

Component / area

Docs: API reference (webhooks)

Testing & validation

  • No realistic whsec_ values remain in the repo content (git grep -E "whsec_[0-9a-f]{32,}": 0)
  • CI / build passes on the implementing PR
  • Owner confirms the production webhooks hash check returns 0 rows, then resolves the GitGuardian incident as a false positive

Rollback plan

Revert the PR (would restore realistic-looking example values; not recommended).

Breaking change for consumers?

No

Reviewer / approver

Nicolas (repo owner), approved in session 2026-09-23.

Activity

  1. nicolasiscoding commented on Sep 23, 2026

    @nicolasiscoding
    MemberAuthor

    Approved by @nicolasiscoding (repo owner), 2026-09-23. Merged to develop via PR #181 (rebase); build/deploy check green. Realistic example secrets removed from repo content (0 matches for whsec_ + 32+ hex). Remaining owner step: run the SHA-256 match against production webhooks.secret; if 0 rows, resolve the GitGuardian incident as a false positive.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

changeSOC 2 change management recorddocumentationImprovements or additions to documentation

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions