Expand description
Webhook verification and translation (§5.6).
Every delivery is authenticated before a byte of it is parsed: GitHub
signs the raw body with HMAC-SHA256 under the App’s webhook secret and
sends the tag in X-Hub-Signature-256. The tag is checked in constant
time, over the exact bytes received — never over re-serialised JSON.
What this cannot check is freshness: the signature covers no timestamp,
so a captured delivery replays cleanly. ForgeEvent::delivery_id is
carried through so the core can drop repeats, and every event here is a
prompt to inspect, not a statement of state to apply — a replayed
“ruleset edited” costs one read.
Functions§
- parse
- Verify, then translate.
hostis the forge host resources are built on. - sign_
body - Compute the
X-Hub-Signature-256value GitHub would send. For tests and for replaying captured deliveries against a local bridge. - verify_
signature - Verify
X-Hub-Signature-256overbody.