Azure上Django Webhook未授权问题:本地测试正常外部请求失败
Django Webhook认证问题(部署在Azure)
我有一个部署在Azure上的Django + React项目,使用Azure Postgres作为数据库,已配置Webhook处理器接收外部API(Seal Subscriptions)的事件。Webhook的subscriptions/create事件会向我的Django后端发送POST请求至:
https://vitaverde-backend.greensky-92f80007.eastus.azurecontainerapps.io/shopify/webhook/subscription/
Azure后端日志流中持续收到以下错误:
ws 11 128676314590080 Received webhook request 2025-03-04T00:39:38.1700588Z stderr F ERROR 2025-03-04 00:39:38,169 views 11 128676314590080 Unauthenticated user request 2025-03-04T00:39:38.1701766Z stderr F WARNING 2025-03-04 00:39:38,170 log 11 128676314590080 Unauthorized: /shopify/webhook/subscription/
已执行的调试步骤
本地测试Webhook
编写test_webhook.sh脚本,携带正确请求头和HMAC签名发送POST请求,Webhook可正常将数据持久化至Azure Postgres数据库。
测试脚本:#!/bin/bash PAYLOAD='{"test": true, "customer": {"first_name": "Test", "last_name": "User", "email": "test@example.com"}}' SEAL_SECRET="seal_secret_****************************" SIGNATURE=$(echo -n "$PAYLOAD" | openssl dgst -sha256 -hmac "$SEAL_SECRET" | cut -d' ' -f2) curl -X POST \ "https://vitaverde-backend.greensky-92f80007.eastus.azurecontainerapps.io/shopify/webhook/customer-creation/" \ -H "Content-Type: application/json" \ -H "X-Seal-Token: seal_token_*************************" \ -H "X-Seal-Hmac-Sha256: $SIGNATURE" \ -d "$PAYLOAD" \ -v echo -e "\n\nPayload: $PAYLOAD" echo "Signature: $SIGNATURE"确保Webhook豁免CSRF
- 在
settings.py中,将Webhook端点添加至CSRF_EXEMPT_URLS:CSRF_EXEMPT_URLS = [ 'shopify/webhook/subscription/', 'shopify/webhook/customer-creation/', 'api/customer/webhook/seal-delivery/', ] - 在
CSRF_TRUSTED_ORIGINS中显式允许相关域名:CSRF_TRUSTED_ORIGINS = [ 'https://vitaverde-frontend.greensky-92f80007.eastus.azurecontainerapps.io', 'https://www.vitaverde.store', 'https://vitaverde.store', 'http://localhost:3000', 'https://app.sealsubscriptions.com', ]
- 在
Webhook视图配置
确保视图无需认证且豁免CSRF:from django.views.decorators.csrf import csrf_exempt from rest_framework.decorators import api_view, permission_classes from rest_framework.permissions import AllowAny from django.http import JsonResponse @csrf_exempt @api_view(['POST']) @permission_classes([AllowAny]) def shopify_webhook_subscription(request): # Process webhook payload return JsonResponse({"message": "Webhook received"}, status=200)
当前问题
- 通过
test_webhook.sh测试时Webhook正常工作; - 但Seal Subscriptions发送请求时,Django日志显示认证错误;
- 怀疑是请求头、CSRF强制或Azure上的CORS设置存在问题。
疑问
- 为何仅Seal Subscriptions发送请求时Webhook失败?
- Azure是否在执行额外安全检查阻挡外部请求?
- 如何进一步调试以查看Seal Subscriptions发送的具体请求头?
内容的提问来源于stack exchange,提问作者A-laz
相关产品推荐
相关产品推荐

