Commit f8b976a972

f8b976a97290a20d552056a999511f5d27d8e8ec

parent: ba885de89c

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-29 00:14 UTC

webhook: document --secret -, pipe it in the e2e test

Closes #284

Layout: unified · split

.gitbay/wiki/API.org +5 −1
@@ -150,13 +150,17 @@ Per-repository outbound POSTs for repository events. Managed by repo
150admins: 150admins:
151 151
152#+begin_src sh 152#+begin_src sh
153gitbay webhook add <url> --secret s3cret [--events push,issue.created] # default * 153printf %s "$SECRET" | gitbay webhook add <url> --secret - [--events push,issue.created] # default *
154gitbay webhook list 154gitbay webhook list
155gitbay webhook deliveries [--limit 50] # status, attempts, last error 155gitbay webhook deliveries [--limit 50] # status, attempts, last error
156gitbay webhook redeliver <delivery-id> # requeue, including dead letters 156gitbay webhook redeliver <delivery-id> # requeue, including dead letters
157gitbay webhook remove <id> 157gitbay webhook remove <id>
158#+end_src 158#+end_src
159 159
160The signing secret is read from stdin with =--secret -=; a value on the
161command line is refused, since argv shows in process listings and shell
162history. Over the JSON API it goes in the request's =stdin= field.
163
160** Events 164** Events
161 165
162Every event this forge records, and so every name =--events= may take. 166Every event this forge records, and so every name =--events= may take.
CHANGELOG.org +5 −2
@@ -6,8 +6,11 @@ anything beyond "replace the binary and restart" is needed.
6 6
7* Unreleased 7* Unreleased
8 8
9- ~webhook add~'s ~--secret~ now reads the signing secret from stdin 9- =webhook add= reads the signing secret from stdin with =--secret -=;
10 (~--secret -~) instead of taking it as a command-line value (#284). 10 a value on the command line is refused, since argv shows in process
11 listings and shell history. A script that passed the value must pipe
12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=
13 (#284).
11- The builds page's status badge section gives an org-mode snippet 14- The builds page's status badge section gives an org-mode snippet
12 beside the Markdown one, for a README.org (#299). 15 beside the Markdown one, for a README.org (#299).
13- API tokens on the settings page: create with a scope and optional 16- API tokens on the settings page: create with a scope and optional
e2e/webhook_test.go +2 −2
@@ -112,8 +112,8 @@ func TestWebhooks(t *testing.T) {
112 112
113 recv := startHookReceiver(t) 113 recv := startHookReceiver(t)
114 hookURL := "http://" + recv.addr + "/hook" 114 hookURL := "http://" + recv.addr + "/hook"
115 if _, errOut, code := inst.ssh(t, aliceKey, "", 115 if _, errOut, code := inst.ssh(t, aliceKey, "s3cret\n",
116 "webhook", "add", "alice/proj", hookURL, "--secret", "s3cret"); code != 0 { 116 "webhook", "add", "alice/proj", hookURL, "--secret", "-"); code != 0 {
117 t.Fatalf("webhook add: %s", errOut) 117 t.Fatalf("webhook add: %s", errOut)
118 } 118 }
119 119