Checklist
- Nonce invalidation — clear
req.session.helixNonceimmediately after a successful callback to prevent replay attacks. - Secret management — store
HELIX_SECRETin environment variables or a secrets manager. Never commit it to source control. - URL signing is server-side —
createAuthUrlneeds the shared secret, so it must run on your backend. Calling it from browser code would ship the secret to every visitor. - Never mutate a signed URL — appending, dropping or reordering query params after
createAuthUrlinvalidatessig. Pass the returnedurlthrough verbatim. - Query normalization — always normalize
req.queryto a flatRecordbefore callingverifyCallbackto avoid array injection. - HTTPS only — the callback endpoint must be served over HTTPS in production to protect the HMAC signature in transit.
- Timestamp window — the SDK rejects callbacks older than a configured time window. Keep server clocks synchronized (NTP).