WebHook响应问题:如何返回无响应体的200状态码
Got it, let's sort out that annoying "Response contained a body" feedback from your webhook endpoint. Since you already have your checkHash() function working correctly to validate signatures, the only tweak you need is to send a 200 status code with absolutely no content in the response body. Here's how to do this across the most common backend frameworks:
Node.js / Express
If you were using res.send(200) or res.json({}) before, those add unnecessary response bodies. Instead, use either:
res.sendStatus(200): This sends a 200 status with an empty body (Express handles the headers correctly)res.status(200).end(): Explicitly ends the response without sending any content
Example code:
app.post('/webhook', (req, res) => { const isValid = checkHash(req.body, req.headers['x-signature']); if (!isValid) { return res.sendStatus(401); // No body, just 401 unauthorized } // Process your payload logic here (if needed) res.sendStatus(200); // Sends empty 200 response });
Python / Flask
Avoid returning empty strings like return '', 200—some endpoints still count that as a body. Instead, create a response without any content and set the Content-Length header to 0:
from flask import Flask, request, make_response app = Flask(__name__) @app.route('/webhook', methods=['POST']) def webhook(): payload = request.get_json() signature = request.headers.get('X-Signature') if not checkHash(payload, signature): return make_response('', 401) # Process payload here # Send empty 200 response response = make_response() response.status_code = 200 response.headers['Content-Length'] = '0' return response
Python / Django
Use HttpResponse with no content and explicitly set Content-Length to ensure no body is sent:
from django.http import HttpResponse from django.views.decorators.http import require_POST @require_POST def webhook(request): payload = request.body signature = request.headers.get('X-Signature') if not checkHash(payload, signature): return HttpResponse(status=401) # Process payload logic return HttpResponse(status=200, content=b'', headers={'Content-Length': '0'})
Java / Spring Boot
Return a ResponseEntity<Void> to indicate no response body, paired with the appropriate status code:
import org.springframework.http.HttpStatus; import org.springframework.http.ResponseEntity; import org.springframework.web.bind.annotation.PostMapping; import org.springframework.web.bind.annotation.RequestBody; import org.springframework.web.bind.annotation.RequestHeader; import org.springframework.web.bind.annotation.RestController; @RestController public class WebhookController { @PostMapping("/webhook") public ResponseEntity<Void> handleWebhook( @RequestBody String payload, @RequestHeader("X-Signature") String signature) { boolean isValid = checkHash(payload, signature); if (!isValid) { return new ResponseEntity<>(HttpStatus.UNAUTHORIZED); } // Process your payload here return new ResponseEntity<>(HttpStatus.OK); } }
Key Notes to Remember:
- Don't return any content at all—even empty strings or null objects can trigger the "response contained a body" error with strict webhook endpoints.
- Use your framework's built-in methods for sending empty responses (like
sendStatusin Express orResponseEntity<Void>in Spring) to ensure headers are set correctly (e.g.,Content-Length: 0).
After making this change, test your endpoint again—this should resolve the feedback you're getting.
内容的提问来源于stack exchange,提问作者pcgben

