flippercloud/flipper · error · ArgumentError

payload should be a string

Error message

payload should be a string

What it means

Error "payload should be a string" thrown in flippercloud/flipper.

Source

Thrown at lib/flipper/cloud/message_verifier.rb:28

      def self.header(signature, timestamp, version = DEFAULT_VERSION)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "signature should be a string" unless signature.is_a?(String)
        "t=#{timestamp.to_i},#{version}=#{signature}"
      end

      def initialize(secret:, version: DEFAULT_VERSION)
        @secret = secret
        @version = version || DEFAULT_VERSION

        raise ArgumentError, "secret should be a string" unless @secret.is_a?(String)
        raise ArgumentError, "secret should not be empty" if @secret.empty?
        raise ArgumentError, "version should be a string" unless @version.is_a?(String)
      end

      def generate(payload, timestamp)
        raise ArgumentError, "timestamp should be an instance of Time" unless timestamp.is_a?(Time)
        raise ArgumentError, "payload should be a string" unless payload.is_a?(String)

        OpenSSL::HMAC.hexdigest(OpenSSL::Digest.new("sha256"), @secret, "#{timestamp.to_i}.#{payload}")
      end

      def header(signature, timestamp)
        self.class.header(signature, timestamp, @version)
      end

      # Public: Verifies the signature header for a given payload.
      #
      # Raises a InvalidSignature in the following cases:
      # - the header does not match the expected format
      # - no signatures found with the expected scheme
      # - no signatures matching the expected signature
      # - a tolerance is provided and the timestamp is not within the
      #   tolerance
      #
      # Returns true otherwise.

View on GitHub (pinned to 1f86de3ec9)

Solutions

  1. Verify the raw request body string, not a parsed hash: use request.body.read before JSON parsing
  2. In Rails, use request.raw_post so middleware has not consumed the body
  3. Re-read the body carefully: signature verification must run over the exact raw payload string

When it happens

Trigger: Thrown at lib/flipper/cloud/message_verifier.rb:28 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of flippercloud/flipper@1f86de3ec9 (2026-08-23). Data as JSON: /api/errors/88e8ee223a489918. Report an issue: GitHub.