Skip to main content

Module webhook

Module webhook 

Source
Expand description

Webhook verification and translation (§5.6).

Forgejo signs the raw body with HMAC-SHA256 under the hook’s secret and sends the tag as bare hex in X-Forgejo-Signature (and, for Gitea compatibility, the same tag in X-Gitea-Signature). The tag is checked in constant time over the exact bytes received, before a byte is parsed. When X-Forgejo-Signature is present it is the one checked — a bad one is not rescued by a good X-Gitea-Signature.

The org webhook subscribes to repository only (created, deleted): that is the one drift Forgejo announces. It sends no event for collaborator, branch-protection, rename or archive changes, so those are found by the scheduled inspect sweep — which is why the adapter reports webhooks: false.

As on GitHub, the signature covers no timestamp: a captured delivery replays. ForgeEvent::delivery_id carries X-Forgejo-Delivery for the core to drop repeats, and every event is a prompt to inspect.

Constants§

HOOK_EVENTS
The events the org webhook subscribes to.

Functions§

parse
Verify, then translate. host is the forge host resources are built on.
sign_body
The signature header value Forgejo would send. For tests and for replaying captured deliveries against a local bridge.
verify_signature
Verify X-Forgejo-Signature (or, failing that header, X-Gitea-Signature) over body.