Commit f8b976a972

f8b976a97290a20d552056a999511f5d27d8e8ec

parent: ba885de89c

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-29 00:14 UTC

webhook: document --secret -, pipe it in the e2e test

Closes #284

Layout: unified · split

.gitbay/wiki/API.org +5 −1
@@ -150,13 +150,17 @@ Per-repository outbound POSTs for repository events. Managed by repo
150150admins:
151151
152152#+begin_src sh
153gitbay webhook add <url> --secret s3cret [--events push,issue.created] # default *
153printf %s "$SECRET" | gitbay webhook add <url> --secret - [--events push,issue.created] # default *
154154gitbay webhook list
155155gitbay webhook deliveries [--limit 50] # status, attempts, last error
156156gitbay webhook redeliver <delivery-id> # requeue, including dead letters
157157gitbay webhook remove <id>
158158#+end_src
159159
160The signing secret is read from stdin with =--secret -=; a value on the
161command line is refused, since argv shows in process listings and shell
162history. Over the JSON API it goes in the request's =stdin= field.
163
160164** Events
161165
162166Every event this forge records, and so every name =--events= may take.
CHANGELOG.org +5 −2
@@ -6,8 +6,11 @@ anything beyond "replace the binary and restart" is needed.
66
77* Unreleased
88
9- ~webhook add~'s ~--secret~ now reads the signing secret from stdin
10 (~--secret -~) instead of taking it as a command-line value (#284).
9- =webhook add= reads the signing secret from stdin with =--secret -=;
10 a value on the command line is refused, since argv shows in process
11 listings and shell history. A script that passed the value must pipe
12 it: =printf %s "$SECRET" | gitbay webhook add <repo> <url> --secret -=
13 (#284).
1114- The builds page's status badge section gives an org-mode snippet
1215 beside the Markdown one, for a README.org (#299).
1316- API tokens on the settings page: create with a scope and optional
e2e/webhook_test.go +2 −2
@@ -112,8 +112,8 @@ func TestWebhooks(t *testing.T) {
112112
113113 recv := startHookReceiver(t)
114114 hookURL := "http://" + recv.addr + "/hook"
115 if _, errOut, code := inst.ssh(t, aliceKey, "",
116 "webhook", "add", "alice/proj", hookURL, "--secret", "s3cret"); code != 0 {
115 if _, errOut, code := inst.ssh(t, aliceKey, "s3cret\n",
116 "webhook", "add", "alice/proj", hookURL, "--secret", "-"); code != 0 {
117117 t.Fatalf("webhook add: %s", errOut)
118118 }
119119