f59db9565c
Gaiia webhook: clean rewrite per exact docs, detailed logging on failure
2026-02-14 16:57:55 -06:00
2c55ab5b77
Gaiia webhook: accept even when signature fails, log details for debugging
2026-02-14 16:52:25 -06:00
be5fa8f4d7
Gaiia webhook: proper HMAC verification per docs, optional when no header
2026-02-14 16:28:35 -06:00
ba895b0ca2
Remove Gaiia webhook secret verification entirely — Gaiia has no signing mechanism
2026-02-14 16:25:56 -06:00
95d833874a
Gaiia webhook: verify secret via query param instead of signature header
2026-02-14 16:08:27 -06:00
82dd75d2e9
Fix Gaiia webhook (no signature), sites page with table + insights
2026-02-14 16:07:26 -06:00
05cdc79124
Fix Gaiia webhook: eventName field, payload extraction, add header logging
2026-02-14 15:40:06 -06:00
a028695d3b
format
2026-02-14 13:57:25 -06:00
950f4d9ae0
fix: implement Gaiia webhook signature verification per their spec
...
- Header: X-Gaiia-Webhook-Signature with t=timestamp,v1=signature format
- Signed payload: timestamp.body (not just body)
- 5-minute timestamp tolerance to prevent replay attacks
- Updated tests to match new 4-arity verify_signature/4
2026-02-14 13:37:26 -06:00
bad1590fed
add gaiia webhook listener with per-org signature verification
...
Stage 3 of Gaiia integration: webhook event processing for real-time
incremental updates from Gaiia. HMAC-SHA256 signature verification
using per-organization secrets stored in integration credentials.
Handles account, billing subscription, and inventory item events.
2026-02-13 10:40:49 -06:00