Security, limitations and troubleshooting

Understand the webhook CSRF exclusion

Limit the CSRF exclusion to the inbound Stripe endpoint.

Audience: CRM staffPermission: Administrator / finance / technical supportModule v1.0.0
Exact navigationTechnical configuration → ideal/webhook
Before you begin
  • Use the exact navigation above and confirm the intended invoice, case, client, property, document or environment.
  • Confirm module activation and the stated permission before attempting the action.
  • Use a controlled test record for payments, emails, public/portal access, provider calls and deletion.

What this guide covers

Limit the CSRF exclusion to the inbound Stripe endpoint. These instructions follow the supplied module’s live hooks, menus, controllers, forms, model rules and downstream effects.

Exact step-by-step process

  1. Keep the exclusion unchanged and narrow.
  2. Do not add broad payment-controller exclusions.

Fields, choices and supported possibilities

Excluded URIideal/webhook
Category/help-centre/category/stripe-ideal-payment-gateway/
Topic/help-centre/topic/stripe-ideal-security-troubleshooting/

Code-backed validations and workflow rules

  • The module config excludes only ideal/webhook.

Expected result and verification

  • Understand the webhook CSRF exclusion completes through the supplied module flow.
  • Reopen the source record or settings page and verify the stored value, status, payment, file, timeline entry or notification.

Security, privacy and operational checks

  • Protect credentials and invoice/payment data.
  • Verify Stripe state before any retry or manual finance correction.