Rescue webhook replay window defense
Extreme Security Basics arena: HMAC signatures, timestamp tolerance, idempotency, and delivery dedupe
Log in and clear the lower tiers to unlock this mission.
Missing prerequisites: security-easy-webhook-replay-window
Attackers replay old webhook deliveries and the billing system accepts them as fresh events. You are working inside a secure engineering review room, and the arena only clears when the result is safe, deterministic, and explainable.
Learn to apply HMAC signatures, timestamp tolerance, idempotency, and delivery dedupe in a secure engineering review room while explaining the invariant, safety constraints, and hidden edge cases.
- Demonstrates HMAC signatures, timestamp tolerance, idempotency, and delivery dedupe
- Handles the visible sample and hidden edge cases
- Keeps output deterministic and explainable
- Avoids unsafe dynamic execution
Clear the route first
You can read the mission brief, but the editor, hints, tests, and submit flow stay locked until progression or plan access catches up.
Test Results
Run the visible checks when your first pass is ready.
Clear Protocol
Rewards
Mission Route
Hints
Hints are metered and logged for No Hint Hero runs.
Genie Mentor Core
Hint protocol / contextual guardrails active