You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Oct 6, 2026. It is now read-only.
Repository navigation
This repository was archived by the owner on Oct 6, 2026. It is now read-only.
Signature validation should support validating with an old secret #101
Oauth2 signature validation will fail when during credential rotation, since the signature is generated with the oldest secret, and validation can only be configured to validate against a single secret in shopify_python_api.
Solution
This needs to be handled similar to webhook validation, where it must be possible to specify the old API secret as well as the new one for signature validation, and accept the signature if it matches the ones generated with either secret.
Thanks for contributing! This package is deprecated and we're archiving this repo, so we're closing all open issues and PRs. Please use shopify-app-python instead, and open new issues there. More context: Rethinking support for PHP/Python packages
Problem
Oauth2 signature validation will fail when during credential rotation, since the signature is generated with the oldest secret, and validation can only be configured to validate against a single secret in shopify_python_api.
Solution
This needs to be handled similar to webhook validation, where it must be possible to specify the old API secret as well as the new one for signature validation, and accept the signature if it matches the ones generated with either secret.