Expand description
Push webhooks: who sent one, whether its signature holds, and what it asks for.
POST /api/v1/webhooks/<org>/<app> is reachable without a session; the
app’s webhook secret (an org secret) is its only credential:
- GitHub:
X-Hub-Signature-256: sha256=<hex HMAC-SHA256 of the body>; - Gitea / Forgejo:
X-Gitea-Signature/X-Forgejo-Signature: the hex HMAC-SHA256 of the body; - GitLab:
X-Gitlab-Token: the secret itself; - anything else:
?token=<secret>.
Every comparison is constant-time.
Structs§
- Pull
Request - A pull request event (GitHub and Gitea/Forgejo
pull_request, GitLabMerge Request Hook).
Enums§
- Event
- What a verified request asks for.
- PrAction
- What happened to a pull request, as far as previews care.
- Provider
- Which kind of sender, by the header that authenticated it.
- Refusal
- Why a request was refused.
Functions§
- delivery_
id - A delivery id, for refusing a replayed delivery.
- event
- What a verified request asks for, from its event header and body.
- sign
- The hex HMAC-SHA256 a sender computes, for tests and for
isb app webhook --test. - verify
- Verify a request against the app’s secret: the provider it came from.
Type Aliases§
- Headers
- A request’s headers by lowercase name.