Commit f8b976a972
f8b976a97290a20d552056a999511f5d27d8e8ec
parent: ba885de89c
Verified · cmc ci/build: success ci/test: success
cmc <hello@cleberg.net> · 2026-09-29 00:14 UTC
webhook: document --secret -, pipe it in the e2e test
Closes #284
Layout: unified · split
.gitbay/wiki/API.org
+5 −1
| @@ -150,13 +150,17 @@ Per-repository outbound POSTs for repository events. Managed by repo |
| 150 | admins: |
150 | admins: |
| 151 | |
151 | |
| 152 | #+begin_src sh |
152 | #+begin_src sh |
| 153 | gitbay webhook add <url> --secret s3cret [--events push,issue.created] # default * |
153 | printf %s "$SECRET" | gitbay webhook add <url> --secret - [--events push,issue.created] # default * |
| 154 | gitbay webhook list |
154 | gitbay webhook list |
| 155 | gitbay webhook deliveries [--limit 50] # status, attempts, last error |
155 | gitbay webhook deliveries [--limit 50] # status, attempts, last error |
| 156 | gitbay webhook redeliver <delivery-id> # requeue, including dead letters |
156 | gitbay webhook redeliver <delivery-id> # requeue, including dead letters |
| 157 | gitbay webhook remove <id> |
157 | gitbay webhook remove <id> |
| 158 | #+end_src |
158 | #+end_src |
| 159 | |
159 | |
| |
160 | The signing secret is read from stdin with =--secret -=; a value on the |
| |
161 | command line is refused, since argv shows in process listings and shell |
| |
162 | history. Over the JSON API it goes in the request's =stdin= field. |
| |
163 | |
| 160 | ** Events |
164 | ** Events |
| 161 | |
165 | |
| 162 | Every event this forge records, and so every name =--events= may take. |
166 | Every event this forge records, and so every name =--events= may take. |
CHANGELOG.org
+5 −2
| @@ -6,8 +6,11 @@ anything beyond "replace the binary and restart" is needed. |
| 6 | |
6 | |
| 7 | * Unreleased |
7 | * Unreleased |
| 8 | |
8 | |
| 9 | - ~webhook add~'s ~--secret~ now reads the signing secret from stdin |
9 | - =webhook add= reads the signing secret from stdin with =--secret -=; |
| 10 | (~--secret -~) instead of taking it as a command-line value (#284). |
10 | a value on the command line is refused, since argv shows in process |
| |
11 | listings and shell history. A script that passed the value must pipe |
| |
12 | it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -= |
| |
13 | (#284). |
| 11 | - The builds page's status badge section gives an org-mode snippet |
14 | - The builds page's status badge section gives an org-mode snippet |
| 12 | beside the Markdown one, for a README.org (#299). |
15 | beside the Markdown one, for a README.org (#299). |
| 13 | - API tokens on the settings page: create with a scope and optional |
16 | - API tokens on the settings page: create with a scope and optional |
e2e/webhook_test.go
+2 −2
| @@ -112,8 +112,8 @@ func TestWebhooks(t *testing.T) { |
| 112 | |
112 | |
| 113 | recv := startHookReceiver(t) |
113 | recv := startHookReceiver(t) |
| 114 | hookURL := "http://" + recv.addr + "/hook" |
114 | hookURL := "http://" + recv.addr + "/hook" |
| 115 | if _, errOut, code := inst.ssh(t, aliceKey, "", |
115 | if _, errOut, code := inst.ssh(t, aliceKey, "s3cret\n", |
| 116 | "webhook", "add", "alice/proj", hookURL, "--secret", "s3cret"); code != 0 { |
116 | "webhook", "add", "alice/proj", hookURL, "--secret", "-"); code != 0 { |
| 117 | t.Fatalf("webhook add: %s", errOut) |
117 | t.Fatalf("webhook add: %s", errOut) |
| 118 | } |
118 | } |
| 119 | |
119 | |