Skip to main content

Module webhook

Module webhook 

Source
Expand description

Push webhooks: who sent one, whether its signature holds, and what it asks for.

POST /api/v1/webhooks/<org>/<app> is reachable without a session; the app’s webhook secret (an org secret) is its only credential:

  • GitHub: X-Hub-Signature-256: sha256=<hex HMAC-SHA256 of the body>;
  • Gitea / Forgejo: X-Gitea-Signature / X-Forgejo-Signature: the hex HMAC-SHA256 of the body;
  • GitLab: X-Gitlab-Token: the secret itself;
  • anything else: ?token=<secret>.

Every comparison is constant-time.

Structs§

PullRequest
A pull request event (GitHub and Gitea/Forgejo pull_request, GitLab Merge Request Hook).

Enums§

Event
What a verified request asks for.
PrAction
What happened to a pull request, as far as previews care.
Provider
Which kind of sender, by the header that authenticated it.
Refusal
Why a request was refused.

Functions§

delivery_id
A delivery id, for refusing a replayed delivery.
event
What a verified request asks for, from its event header and body.
sign
The hex HMAC-SHA256 a sender computes, for tests and for isb app webhook --test.
verify
Verify a request against the app’s secret: the provider it came from.

Type Aliases§

Headers
A request’s headers by lowercase name.