Understand the create-webhook authorisation limitation
Record that create_webhook lacks an explicit capability check.
Exact navigationTechnical route → /ideal/create_webhook
Before you begin
- Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
- Confirm module activation and the stated permission before attempting the action.
- Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.
What this guide covers
Record that create_webhook lacks an explicit capability check. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.
Exact step-by-step process
- Restrict route access operationally.
- Use authenticated administrator workflows only.
- Consider hardening in the application module separately from this Help Centre.
Fields, choices and supported possibilities
Explicit guardNone in supplied method
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/
Code-backed validations and workflow rules
- The supplied module implements or omits this behaviour exactly as described.
Expected result and verification
- Understand the create-webhook authorisation limitation completes through the supplied module flow.
- Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.
Security, privacy and operational checks
- Protect credentials and invoice/payment data.
- Verify Stripe state before any retry or manual finance correction.
