fix(formstack): record live-capture findings and add real delivery test vectors - #197
Merged
Merged
Conversation
…st vectors Two real Formstack Forms WebHook deliveries were captured on 2026-09-25 and their signatures recomputed. They settle what the public docs leave out: - HMAC-SHA256 over the raw urlencoded body, lowercase hex, sent as sha256=<hex>. The base64 form does not match. A key change verified only with the new key. - The Shared Secret arrives as a body field named HandshakeKey, inside the signed content. The HMAC Key is never sent. - FormID and UniqueID arrive as strings, first on the wire. - User-Agent is FormstackWebhook/1.0 (Form <FormID>). No delivery-id header. Removes the 'if hex never matches, try base64' fallback and the single-upstream hedging, closes the matching TODO items, updates the brief, and adds both captured deliveries as test vectors in the express, nextjs and fastapi suites. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…Secret Both captures had a Shared Secret set, so whether the field is omitted or sent empty without one was never observed. Say so, and track it in TODO. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
garethx
marked this pull request as ready for review
September 25, 2026 13:56
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two real Formstack Forms WebHook deliveries were captured through a Hookdeck source on 2026-09-25, and their signatures were recomputed. This settles the facts the skill previously hedged on, because Formstack's public docs don't state them.
What the captures confirmed
sha256=<hex>. The base64 form of the same MAC does not match.test. The key was then changed totest1, and the second delivery verified only withtest1.HandshakeKey, afterFormIDandUniqueID, inside the signed content. It stayedtestacross the key change, so the HMAC Key itself is never sent.FormIDandUniqueIDarrive as strings. No timestamp, delivery-id or event-type field or header.FormstackWebhook/1.0 (Form <FormID>). The skill records it as observed and still routes onFormID.Wire body of the second capture:
Changes
merge_id,handshake,file_nameandfile_contents, and says it sends no signature header.providers.yamlbrief is updated so a regeneration doesn't reintroduce the old hedges.Not asserted
HandshakeKeyname and the user-agent format are marked observed, not documented.HandshakeKeyis omitted or sent empty without one.Testing
validate-provider.sh formstack-webhookspasses.Related PRs:
🤖 Generated with Claude Code