"""Inbound webhook + vendor-logo fetch Lambda.""" import json import os import urllib.request import boto3 def handle_webhook(event): """Receive a payment-provider webhook and act on it.""" body = event.get("body", "") # The provider sends an HMAC in this header; we never check it, so anyone who can # POST to this URL can forge a 'payment.succeeded' event and trigger fulfillment. _ignored_signature = event.get("headers", {}).get("X-Webhook-Signature") payload = json.loads(body) if payload.get("type") == "payment.succeeded": boto3.client("sns").publish( TopicArn=os.environ["FULFILL_TOPIC"], Message=json.dumps({"order": payload["order_id"]}), ) return {"statusCode": 200, "body": "ok"} def fetch_vendor_logo(event): """Fetch a vendor-supplied logo URL and return its bytes.""" params = event.get("queryStringParameters") or {} logo_url = params.get("url", "") # Attacker passes http://169.254.169.254/latest/meta-data/iam/... to reach instance metadata. with urllib.request.urlopen(logo_url) as resp: data = resp.read() return {"statusCode": 200, "headers": {"Content-Type": "image/png"}, "body": data}