Page MenuHomePhabricator

Investigate 'Invalid control' errors from AstroPay
Closed, ResolvedPublic1 Story Points

Description

We're still getting some of these errors, which indicate that AstroPay didn't think we signed the request correctly. We eliminated most of the early ones when we added fiscal number validation, so I'm guessing a quirk in the format of one of the fields is to blame. When we get one of these errors, we should log the signed string and the signature so we can determine what's going wrong, while still not logging any sensitive parts of the request.

Event Timeline

Ejegg created this task.Aug 17 2015, 4:54 PM
Ejegg claimed this task.
Ejegg raised the priority of this task from to Normal.
Ejegg updated the task description. (Show Details)
Ejegg added a subscriber: Ejegg.
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptAug 17 2015, 4:54 PM

Change 232071 had a related patch set uploaded (by Ejegg):
Log signed message and signature on 'Invalid control'

https://gerrit.wikimedia.org/r/232071

Ejegg set Security to None.
Ejegg edited a custom field.
Ejegg moved this task from Backlog to Review on the Fundraising Sprint Queen board.

Change 232071 merged by jenkins-bot:
Log signed message and signature on 'Invalid control'

https://gerrit.wikimedia.org/r/232071

Change 232577 had a related patch set uploaded (by Ejegg):
Fix AstroPay signature when values contain plus sign

https://gerrit.wikimedia.org/r/232577

Ejegg moved this task from Done to Review on the Fundraising Sprint Queen board.Aug 19 2015, 8:15 PM

Change 232577 merged by jenkins-bot:
Fix AstroPay signature when values contain plus sign

https://gerrit.wikimedia.org/r/232577

Ejegg closed this task as Resolved.Aug 26 2015, 5:24 PM