Skip to main content

Module webhook

Module webhook 

Source
Expand description

Webhook verification and translation (§5.6).

Every delivery is authenticated before a byte of it is parsed: GitHub signs the raw body with HMAC-SHA256 under the App’s webhook secret and sends the tag in X-Hub-Signature-256. The tag is checked in constant time, over the exact bytes received — never over re-serialised JSON.

What this cannot check is freshness: the signature covers no timestamp, so a captured delivery replays cleanly. ForgeEvent::delivery_id is carried through so the core can drop repeats, and every event here is a prompt to inspect, not a statement of state to apply — a replayed “ruleset edited” costs one read.

Functions§

parse
Verify, then translate. host is the forge host resources are built on.
sign_body
Compute the X-Hub-Signature-256 value GitHub would send. For tests and for replaying captured deliveries against a local bridge.
verify_signature
Verify X-Hub-Signature-256 over body.