ruby
8 lines · 1 tab
Kai Nakamura
Apr 2026
1 tab
event_id = request.headers.fetch('X-Event-Id')
timestamp = request.headers.fetch('X-Signature-Timestamp').to_i
raise ActionController::BadRequest, 'stale request' if Time.now.to_i - timestamp > 300
raise ActionController::BadRequest, 'replay detected' if WebhookEvent.exists?(external_id: event_id)
WebhookEvent.create!(external_id: event_id, payload: request.raw_post)
head :accepted
1 file · ruby
Explain with highlit
A webhook endpoint is an internet-facing parser plus an authentication problem. I verify signatures, enforce recent timestamps, and store event IDs to block replay attempts. Reliability matters too, so handlers should be idempotent and fast to acknowledge.
Related snips
ruby
timestamp = request.headers.fetch('X-Signature-Timestamp')
signature = request.headers.fetch('X-Signature')
payload = request.raw_post
data = "#{timestamp}.#{payload}"
expected = OpenSSL::HMAC.hexdigest('SHA256', ENV.fetch('WEBHOOK_SECRET'), data)
HMAC signed API requests for webhook and partner integrity
hmac
api-signing
webhooks
by Kai Nakamura
2 tabs
ruby
class CreateProcessedEvents < ActiveRecord::Migration[7.1]
def change
create_table :processed_events do |t|
t.string :event_key, null: false
t.string :job_class, null: false
t.jsonb :metadata, null: false, default: {}
Idempotent Job with Advisory Lock
rails
postgres
reliability
by codesnips
3 tabs
ruby
Rails.application.config.middleware.insert_before 0, Rack::Cors do
allow do
origins 'https://app.example.com', 'https://admin.example.com'
resource '/api/*',
headers: %w[Authorization Content-Type],
methods: %i[get post patch delete options],
Security focused CORS configuration for browser APIs
cors
browser-security
api-security
by Kai Nakamura
1 tab
typescript
import crypto from 'crypto';
interface VerifyOptions {
rawBody: Buffer;
signatureHeader: string | undefined;
secret: string;
Webhook signature verification (timing-safe compare)
security
webhooks
hmac
by codesnips
3 tabs
ruby
class AddUniqueIndexToInventorySnapshots < ActiveRecord::Migration[7.1]
disable_ddl_transaction!
def change
add_index :inventory_snapshots,
[:warehouse_id, :sku],
Bulk Upsert with insert_all + Unique Index
rails
activerecord
postgres
by codesnips
3 tabs
typescript
import { Injectable } from '@nestjs/common';
export interface RateLimitResult {
allowed: boolean;
remaining: number;
limit: number;
Sliding-Window Webhook Rate Limiting with a NestJS Interceptor and In-Memory Counter
typescript
nestjs
rate-limiting
by codesnips
3 tabs
Share this code
Here's the card — post it anywhere.