Skip to content

fix: return verified boolean in verify_signature, prevent timing attacks, and ensure thread-safe headers - #108

Open
cobanfurkanx wants to merge 1 commit into
iyzico:masterfrom
cobanfurkanx:fix/verify-signature-thread-safety
Open

cobanfurkanx wants to merge 1 commit into
iyzico:masterfrom
cobanfurkanx:fix/verify-signature-thread-safety

Conversation

@cobanfurkanx

Copy link
Copy Markdown

Summary

This PR addresses several critical reliability, security, and concurrency issues in IyzipayResource:

  1. verify_signature returned None: The method computed verified = signature == calculated_signature and printed it to stdout, but never returned the boolean, causing any caller performing if not payment.verify_signature(...) to always fail even on valid signatures.
  2. Timing Attack Vulnerability: Replaced standard string equality comparison with constant-time hmac.compare_digest to protect against HMAC timing side-channel attacks.
  3. TypeError in calculate_hmac_sha256_signature: When params contained numbers (paidPrice, price, installment) or None (conversationId), ':'.join(params) raised TypeError: sequence item X: expected str instance. It now safely converts values to string or empty string.
  4. Multi-threading Race Condition on header (Addresses Bugs I experienced & Concept (FastAPI, MongoDB, React) #91): IyzipayResource.header was a shared class variable mutated in-place during each request (self.header.update({'x-iyzi-rnd': ...})). In concurrent environments (e.g. FastAPI / Django / Flask with threaded workers), concurrent requests could overwrite headers mid-flight, causing Geçersiz imza authentication failures. Headers are now copied per-request.
  5. base_url Host Sanitization: Gracefully handles both scheme-less hostnames (sandbox-api.iyzipay.com) and standard URLs (https://sandbox-api.iyzipay.com), preventing InvalidURL: nonnumeric port errors.
  6. Automated Unit Tests & CI Execution: Added a unit test suite in tests/ and updated .github/workflows/github_pull_request.yml to run automated test discovery across the matrix (Python 3.9–3.13).

Verification

All 14 unit tests pass cleanly:

$ python -m unittest discover -s tests -v
Ran 14 tests in 0.028s
OK

…cks, and ensure thread-safe headers

- Fix verify_signature to return verified boolean rather than None, enabling callers to properly check payment notification validity.
- Use hmac.compare_digest for constant-time comparison in verify_signature to guard against timing attacks.
- Make calculate_hmac_sha256_signature resilient against TypeErrors when params contain numbers or None.
- Prevent multi-threading race conditions in concurrent web frameworks (FastAPI/Django) by returning per-request copies rather than mutating class-level header dict in-place.
- Sanitize base_url host in connect() to handle both scheme-less and https:// prefixes.
- Add comprehensive unit test suite in tests/ covering signature verification, thread-safety, and helpers.
- Update GitHub Actions workflow to run automated unit tests across Python 3.9-3.13 matrix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant