basalt / webhooks/src / MIN_WEBHOOK_SECRET_LENGTH
Variable: MIN_WEBHOOK_SECRET_LENGTH
> const MIN_WEBHOOK_SECRET_LENGTH: 16 = 16
Defined in: webhooks/src/deliver.ts:44
Minimum length of a webhook signing secret. Shorter (or empty/unset) secrets are refused on both ends: the deliverer won't sign with one and verifySignature won't accept one, so a receiver whose secret env var is unset can never be satisfied by an HMAC computed with an empty key.