Expand description
Webhook verification and translation (§5.6).
Forgejo signs the raw body with HMAC-SHA256 under the hook’s secret and
sends the tag as bare hex in X-Forgejo-Signature (and, for Gitea
compatibility, the same tag in X-Gitea-Signature). The tag is checked
in constant time over the exact bytes received, before a byte is parsed.
When X-Forgejo-Signature is present it is the one checked — a bad one
is not rescued by a good X-Gitea-Signature.
The org webhook subscribes to repository only (created, deleted): that
is the one drift Forgejo announces. It sends no event for collaborator,
branch-protection, rename or archive changes, so those are found by the
scheduled inspect sweep — which is why the adapter reports
webhooks: false.
As on GitHub, the signature covers no timestamp: a captured delivery
replays. ForgeEvent::delivery_id carries X-Forgejo-Delivery for the
core to drop repeats, and every event is a prompt to inspect.
Constants§
- HOOK_
EVENTS - The events the org webhook subscribes to.
Functions§
- parse
- Verify, then translate.
hostis the forge host resources are built on. - sign_
body - The signature header value Forgejo would send. For tests and for replaying captured deliveries against a local bridge.
- verify_
signature - Verify
X-Forgejo-Signature(or, failing that header,X-Gitea-Signature) overbody.