Problem/Motivation

Alpha2 supports source policy mappings and one credential pair with a shared allowlist. Sites receiving events from multiple Postmark servers cannot rotate or revoke one source's credential independently.

Proposed resolution

Introduce optional named source profiles that bind a credential to allowed server/stream pairs. Keep secret material in trusted settings or a supported secret-provider integration, not exported configuration.

Acceptance criteria

  • Authenticate the credential and then enforce only that profile's source bindings; reject cross-profile payloads before storage.
  • Provide independent current/previous credentials with fixed overlap expiry and explicit profile revocation.
  • Preserve the existing shared-endpoint setup through an explicit backward-compatible migration path.
  • Define duplicate/ambiguous profile handling, malformed configuration behavior and source-less provider verification payload behavior.
  • Test rotation, revocation, profile confusion, mixed-source attacks and absence of secret values in URLs, forms, logs and exports.

Scope and dependencies

Optional follow-up after stable release; not a blocker for #3621224: Complete the 1.0.0 stable release verification gates. Builds on #3621132: Scope webhook sources and suppression policy by server and message stream; the completed original issue remains fixed.

Comments

jmcerda created an issue. See original summary.

  • jmcerda committed 900ba0cd on 1.x
    Issue #3621231: Reuse the health credential snapshot in sourceCheck
    

  • jmcerda committed f7f31f2c on 1.x
    Issue #3621231: Avoid null offset access when a profile omits previous
    

  • jmcerda committed b01bbc3b on 1.x
    Issue #3621231: Keep previous_secret_status on shared rotation when...

  • jmcerda committed 5e1f996e on 1.x
    Issue #3621231: Use the soonest still-active previous expiry in health...

  • jmcerda committed 0073c00c on 1.x
    Issue #3621231: Ignore empty profile previous secrets instead of 503
    
    An...

  • jmcerda committed 551f2b0b on 1.x
    Issue #3621231: Report rotation only for credentials the endpoint will...

  • jmcerda committed 9f698f35 on 1.x
    Issue #3621231: Reject non-scalar source labels and document profile...

  • jmcerda committed 7a7c503f on 1.x
    Issue #3621231: Align source-health reporting and restore endpoint...

  • jmcerda committed 9adea5e9 on 1.x
    Issue #3621231: Bind independently rotated webhook credentials to source...
jmcerda’s picture

Assigned: Unassigned » jmcerda
Status: Active » Fixed

Landed on 1.x-dev.

Named source profiles in settings.php bind independently rotated webhook credentials to server and stream pairs. Authentication selects one profile, then only that profile's sources are stored. Cross-profile and source-less payloads return 403 without storage. Duplicate secrets or bindings, and malformed maps, fail closed with 503. The shared webhook secret remains the default and is ignored while any profile is usable; after every profile is revoked it is the fallback again. Secrets stay out of exported configuration, forms, logs and diagnostics.

Kernel coverage includes rotation, revocation, mixed-source rejection, legacy fallback, and diagnostics redaction. This is not a stable-release gate.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.