Skip to content

Commit 22d3d02

Browse files
Add signatures to webhooks (#6428)
1 parent 909feaa commit 22d3d02

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed

models/webhook.go

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,10 @@
66
package models
77

88
import (
9+
"crypto/hmac"
10+
"crypto/sha256"
911
"crypto/tls"
12+
"encoding/hex"
1013
"encoding/json"
1114
"fmt"
1215
"io/ioutil"
@@ -101,6 +104,7 @@ type Webhook struct {
101104
RepoID int64 `xorm:"INDEX"`
102105
OrgID int64 `xorm:"INDEX"`
103106
URL string `xorm:"url TEXT"`
107+
Signature string `xorm:"TEXT"`
104108
ContentType HookContentType
105109
Secret string `xorm:"TEXT"`
106110
Events string `xorm:"TEXT"`
@@ -529,6 +533,7 @@ type HookTask struct {
529533
UUID string
530534
Type HookTaskType
531535
URL string `xorm:"TEXT"`
536+
Signature string `xorm:"TEXT"`
532537
api.Payloader `xorm:"-"`
533538
PayloadContent string `xorm:"TEXT"`
534539
ContentType HookContentType
@@ -657,11 +662,23 @@ func prepareWebhook(e Engine, w *Webhook, repo *Repository, event HookEventType,
657662
payloader = p
658663
}
659664

665+
var signature string
666+
if len(w.Secret) > 0 {
667+
data, err := payloader.JSONPayload()
668+
if err != nil {
669+
log.Error(2, "prepareWebhooks.JSONPayload: %v", err)
670+
}
671+
sig := hmac.New(sha256.New, []byte(w.Secret))
672+
sig.Write(data)
673+
signature = hex.EncodeToString(sig.Sum(nil))
674+
}
675+
660676
if err = createHookTask(e, &HookTask{
661677
RepoID: repo.ID,
662678
HookID: w.ID,
663679
Type: w.HookTaskType,
664680
URL: w.URL,
681+
Signature: signature,
665682
Payloader: payloader,
666683
ContentType: w.ContentType,
667684
EventType: event,
@@ -712,8 +729,10 @@ func (t *HookTask) deliver() {
712729
req := httplib.Post(t.URL).SetTimeout(timeout, timeout).
713730
Header("X-Gitea-Delivery", t.UUID).
714731
Header("X-Gitea-Event", string(t.EventType)).
732+
Header("X-Gitea-Signature", t.Signature).
715733
Header("X-Gogs-Delivery", t.UUID).
716734
Header("X-Gogs-Event", string(t.EventType)).
735+
Header("X-Gogs-Signature", t.Signature).
717736
HeaderWithSensitiveCase("X-GitHub-Delivery", t.UUID).
718737
HeaderWithSensitiveCase("X-GitHub-Event", string(t.EventType)).
719738
SetTLSClientConfig(&tls.Config{InsecureSkipVerify: setting.Webhook.SkipTLSVerify})

0 commit comments

Comments
 (0)