mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-10-03 06:53:30 +00:00
35 lines
1.2 KiB
Python
35 lines
1.2 KiB
Python
|
|
"""Inbound webhook + vendor-logo fetch Lambda."""
|
||
|
|
import json
|
||
|
|
import os
|
||
|
|
import urllib.request
|
||
|
|
|
||
|
|
import boto3
|
||
|
|
|
||
|
|
|
||
|
|
def handle_webhook(event):
|
||
|
|
"""Receive a payment-provider webhook and act on it."""
|
||
|
|
body = event.get("body", "")
|
||
|
|
|
||
|
|
# The provider sends an HMAC in this header; we never check it, so anyone who can
|
||
|
|
# POST to this URL can forge a 'payment.succeeded' event and trigger fulfillment.
|
||
|
|
_ignored_signature = event.get("headers", {}).get("X-Webhook-Signature")
|
||
|
|
|
||
|
|
payload = json.loads(body)
|
||
|
|
if payload.get("type") == "payment.succeeded":
|
||
|
|
boto3.client("sns").publish(
|
||
|
|
TopicArn=os.environ["FULFILL_TOPIC"],
|
||
|
|
Message=json.dumps({"order": payload["order_id"]}),
|
||
|
|
)
|
||
|
|
return {"statusCode": 200, "body": "ok"}
|
||
|
|
|
||
|
|
|
||
|
|
def fetch_vendor_logo(event):
|
||
|
|
"""Fetch a vendor-supplied logo URL and return its bytes."""
|
||
|
|
params = event.get("queryStringParameters") or {}
|
||
|
|
logo_url = params.get("url", "")
|
||
|
|
|
||
|
|
# Attacker passes http://169.254.169.254/latest/meta-data/iam/... to reach instance metadata.
|
||
|
|
with urllib.request.urlopen(logo_url) as resp:
|
||
|
|
data = resp.read()
|
||
|
|
return {"statusCode": 200, "headers": {"Content-Type": "image/png"}, "body": data}
|