Skip to content

fix(docs): use a placeholder for example webhook secrets - #181

Merged
nicolasiscoding merged 1 commit into
developfrom
fix/webhook-secret-example-placeholder
Sep 23, 2026
Merged

nicolasiscoding merged 1 commit into
developfrom
fix/webhook-secret-example-placeholder

Conversation

@nicolasiscoding

Copy link
Copy Markdown
Member

Closes #180

GitGuardian flagged the example whsec_ values on the Create Webhook and Regenerate Webhook Secret pages (added in #171) as a Stripe webhook secret. They are in TurboDocx's own webhook-secret format (70 chars), not Stripe's, and are expected to be invented examples; see #180 for the assessment and the owner's DB confirmation step.

Replaces both with whsec_REPLACE_WITH_YOUR_WEBHOOK_SECRET. 2 files, 2 lines. No other realistic whsec_ values exist in the repo content.

Test plan

  • git grep -E "whsec_[0-9a-f]{32,}" on the branch: 0 matches
  • Build/deploy check green

The Create Webhook and Regenerate Webhook Secret response examples used
realistic-looking whsec_ values (TurboDocx format: whsec_ + 64 hex), which
secret scanners report as a Stripe webhook secret. Replace them with an
obvious placeholder.
@nicolasiscoding nicolasiscoding self-assigned this Sep 23, 2026
@nicolasiscoding
nicolasiscoding merged commit 1706bbf into develop Sep 23, 2026
1 check passed

This branch was successfully deployed

1 active deployment
preview — 0b4da59d Deployed Sep 23, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(docs): example webhook secrets flagged by GitGuardian as Stripe secret

1 participant