Closed (fixed)
Project:
Postmark Webhooks
Version:
1.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Reporter:
Created:
6 Sep 2026 at 16:05 UTC
Updated:
21 Sep 2026 at 03:25 UTC
Jump to comment: Most recent
Alpha2 supports source policy mappings and one credential pair with a shared allowlist. Sites receiving events from multiple Postmark servers cannot rotate or revoke one source's credential independently.
Introduce optional named source profiles that bind a credential to allowed server/stream pairs. Keep secret material in trusted settings or a supported secret-provider integration, not exported configuration.
Optional follow-up after stable release; not a blocker for #3621224: Complete the 1.0.0 stable release verification gates. Builds on #3621132: Scope webhook sources and suppression policy by server and message stream; the completed original issue remains fixed.
Comments
Comment #11
jmcerdaLanded on 1.x-dev.
Named source profiles in settings.php bind independently rotated webhook credentials to server and stream pairs. Authentication selects one profile, then only that profile's sources are stored. Cross-profile and source-less payloads return 403 without storage. Duplicate secrets or bindings, and malformed maps, fail closed with 503. The shared webhook secret remains the default and is ignored while any profile is usable; after every profile is revoked it is the fallback again. Secrets stay out of exported configuration, forms, logs and diagnostics.
Kernel coverage includes rotation, revocation, mixed-source rejection, legacy fallback, and diagnostics redaction. This is not a stable-release gate.