#molar0020
1 messages · Page 1 of 1 (latest)
👋 happy to help
we don't really recommend doing this
if you use the Strive Signature verification this can be enough evidence for you that the event is coming from Stripe
In order to verify the signature, I will have to check each request, and in the case of a DDOS attack, it could be a bit problematic. Applying an IP restriction can help mitigate this issue. Of course, this is in addition to checking the signature. From your response, I understand that we cannot rely on this list, correct?
you have the list https://stripe.com/docs/ips#webhook-notifications
but it's really up to you to decide if you want to do that, because this means, as you said it, you have to maintain it periodically
I appreciate your assistance!