Change type
Emergency — hotfix
Risk / impact
Low
Security impact assessed?
Yes — described below
Details — description & full context
GitGuardian alert (2026-09-23 16:02:48 UTC, TurboDocx/Docs) flagged a "Stripe Webhook Secret". Source: the example responses on docs/API/create-webhook.api.mdx and docs/API/regenerate-webhook-secret.api.mdx, added in the API-reference enrichment (#171, commit 645291e) and merged to develop.
Assessment:
- The values are in TurboDocx's own outbound-webhook secret format (
whsec_ + 64 hex = 70 chars, generated in RapidDocxBackend src/models/Webhook/index.ts), not Stripe's shorter format. GitGuardian labels any whsec_ value as Stripe. The Stripe → Lambda billing webhook is not involved.
- The values were written by a docs agent reading backend code only (no database, Stripe, or config access), so they are expected to be invented examples. Owner to confirm with a SHA-256 match against the production
webhooks.secret column (hashes of the two values recorded in the investigating session; 0 rows = fake).
- Not live on docs.turbodocx.com:
develop had not been promoted to main.
Fix: replace both example values with the placeholder whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET. A scan of docs/, src/, and static/ on develop found no other realistic whsec_ values.
Component / area
Docs: API reference (webhooks)
Testing & validation
Rollback plan
Revert the PR (would restore realistic-looking example values; not recommended).
Breaking change for consumers?
No
Reviewer / approver
Nicolas (repo owner), approved in session 2026-09-23.
Change type
Emergency — hotfix
Risk / impact
Low
Security impact assessed?
Yes — described below
Details — description & full context
GitGuardian alert (2026-09-23 16:02:48 UTC, TurboDocx/Docs) flagged a "Stripe Webhook Secret". Source: the example responses on
docs/API/create-webhook.api.mdxanddocs/API/regenerate-webhook-secret.api.mdx, added in the API-reference enrichment (#171, commit 645291e) and merged todevelop.Assessment:
whsec_+ 64 hex = 70 chars, generated in RapidDocxBackendsrc/models/Webhook/index.ts), not Stripe's shorter format. GitGuardian labels anywhsec_value as Stripe. The Stripe → Lambda billing webhook is not involved.webhooks.secretcolumn (hashes of the two values recorded in the investigating session; 0 rows = fake).develophad not been promoted tomain.Fix: replace both example values with the placeholder
whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET. A scan ofdocs/,src/, andstatic/ondevelopfound no other realisticwhsec_values.Component / area
Docs: API reference (webhooks)
Testing & validation
whsec_values remain in the repo content (git grep -E "whsec_[0-9a-f]{32,}": 0)webhookshash check returns 0 rows, then resolves the GitGuardian incident as a false positiveRollback plan
Revert the PR (would restore realistic-looking example values; not recommended).
Breaking change for consumers?
No
Reviewer / approver
Nicolas (repo owner), approved in session 2026-09-23.