Out-of-order callbacks

Context#

Two callbacks reference the same business key but arrive on different connections. If the handler applies “last write wins” without a monotonic state version, capture may be processed before authorize, or a refund before a charge settles, leaving accounts inconsistent.

Theory#

Compare with distributed-systems version vectors; many CRUD apps omit them on webhook handlers.

Practice#

  • In staging, delay one callback artificially (slow proxy) and send the dependent event first; observe ledger or entitlement tables.

Tools#

  • Burp Suite with Throttling
  • tc / netem in a lab network

Cookie Consent

We use cookies to enhance your experience. Learn more