Monobank payment API
The module does not check the digital signature from Monobank before processing payment status updates. A visitor could change payment statuses. They could not read any hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Monobank payment API to 1.0.3.
For developers: what the fix changed
Adds webhook signature verification in the `status` callback within `src/Controller/Pages.php` and implements the verification logic in `src/Monobank.php`.
Also in this release Added Drupal 12 support, dropped Drupal 9, migrated hooks to a new class using attributes, and updated translation method calls.
monobank.info.yml+2 −2monobank.module+12 −33monobank.services.yml+4 −0src/Controller/Pages.php+22 −15 fixsrc/Form/MonobankPaymentsForm.php+9 −9src/Form/SettingsForm.php+4 −4src/Hook/MonobankHooks.php+84 −0src/Monobank.php+115 −3 fixsrc/Plugin/Basket/Payment/BasketMonobank.php+5 −5