Based on the comments to the original question, here is the solution I have decided on for now. Note that it does NOT leave the perceived bad actor hanging, but instead responds with an error that can be set in the config file or defaults to 404 NOT FOUND. As far as I can tell, even with Response.Clear() and Response.End(), webapi will send an empty 200 response. So I can't completely adhere to the suggestion of the third party.
using System.Collections.Generic;
using System.Configuration;
using System.Net;
using System.Net.Http;
using System.Threading;
using System.Threading.Tasks;
using System.Web;
using System.Web.Http;
using System.Web.Http.Controllers;
using System.Web.Http.Filters;
using IntegrationResearch.Extension;
namespace IntegrationResearch.Filters
public class VerificationAttribute : ActionFilterAttribute
public override async Task OnActionExecutingAsync(HttpActionContext actionContext, CancellationToken cancellationToken)
await base.OnActionExecutingAsync(actionContext, cancellationToken);
IList<string> validationErrors = await actionContext.Request.GetSignedRequestVerificationErrorsAsync(); //The code that does the work of checking signed request
if ((validationErrors?.Count ?? 0) != 0)
// TODO SG - definitely need to log the issue either way
throw new HttpResponseException(HttpContext.Current.IsDebuggingEnabled
? new HttpResponseMessage(HttpStatusCode.OK) { Content = new StringContent(string.Join(", ", validationErrors)) }
: new HttpResponseMessage(await GetDelayedVerificationFailureStatusCodeAsync()));
private static async Task<HttpStatusCode> GetDelayedVerificationFailureStatusCodeAsync()
await Task.Delay(int.TryParse(ConfigurationManager.AppSettings[VerificationFailureDelayMillisecondsConfigKey], out int delayMilliseconds) ? delayMilliseconds : 1000);
return (HttpStatusCode) int.Parse(ConfigurationManager.AppSettings[VerificationFailureStatusCodeConfigKey]);
return HttpStatusCode.NotFound;
private const string VerificationFailureStatusCodeConfigKey = "VerificationFailureStatusCode";
private const string VerificationFailureDelayMillisecondsConfigKey = "VerificationFailureDelayMilliseconds";