Auditor
Every payment-provider webhook handler verifies the provider signature before acting on the event.
1.1.1: a callee whose root is a name that `Object.prototype` also carries (`build().toString()` tokenizes to the bare callee `toString`; also `constructor`, `valueOf`, `hasOwnProperty`) was looked up in the plain object that holds the imported names, so it resolved to the INHERITED FUNCTION instead of to nothing and the whole check died with "name.includes is not a function". Only a real binding counts now, and the name of a unit is always read as a string. Found on a 1 319-file checkout (2fa-available and session-expiry-rotation, 2026-09-24); the same line was in the 15 scripts that walk the call graph, so all fifteen ship the fix. (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. Handlers are function units (route handler, decorated view, controller action, Lambda handler); the verification (provider API, HMAC over the body with a constant-time comparison, signature or token header compared, external verification library) is searched in the handler, its middleware and decorators, and the functions it calls within 3 module hops (resolved by the imported name); none on any path is FAIL with the handler line; a loose comparison is MEDIUM; a hard-coded secret is HIGH. (1.0.2: evaluates only endpoints that RECEIVE a webhook of an external provider (provider SDK verification such as constructEvent, a provider signature header such as stripe-signature or x-hub-signature, or a /webhook(s)/<provider> route); an internal service-to-service callback authenticated with a service token, a bearer token or the application's own HMAC is not a third-party webhook (not-applicable with the callbacks listed, or PASS when real handlers exist); files that only mention webhooks and a provider without receiving a request are not reported; verification delegated to an imported module of the checkout counts and the module is reviewed together with the handler (assess mode); never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
| // a handler is a FUNCTION UNIT (route handler, decorated view, controller action, Lambda handler) of the static analysis kit |
| const SIGNATURE_HEADER = /stripe-signature|paypal-transmission-sig|hmacsignature|bt_signature|x-razorpay-signature|paddle-signature|x-hub-signature(?:-256)?|x-gitlab-token|x-slack-signature/i; |
| const PROVIDER_API = /constructEvent(?:Async)?\s*\(|Webhook\.construct_event|WebhookSignature::verifyHeader|HmacValidator|webhookNotification\.parse\s*\(/i; |
| const HMAC_COMPUTE = /createHmac\s*\(|hmac\.new\s*\(|hash_hmac\s*\(/i; |
| const CONSTANT_TIME = /timingSafeEqual|compare_digest|hash_equals|safeEqual\s*\(/i; |
| // verificationOf(handler): breadth-first over the call graph (own body -> local functions, middleware, decorators -> imported functions, <= 3 module hops) |
| // provider API | HMAC + constant-time | header compared -> verified (loose operator -> MEDIUM) |
| // nothing on any path -> FAIL with the handler line; no third-party webhook handler -> not-applicable |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.