Documentation
¶
Overview ¶
Package trampoline implements an HTTP server that receives GitHub webhook events, validates their signatures, and forwards them as CloudEvents to a broker ingress.
Use NewServer to create a Server configured with a CloudEvents client and webhook secrets. The server implements http.Handler and can be registered with any HTTP mux.
Index ¶
Examples ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ValidatePayload ¶
func ValidatePayload(r *http.Request, secrets [][]byte, boundSecrets []BoundSecret) (payload []byte, bound bool, err error)
ValidatePayload validates the payload of a webhook request for a given set of secrets. If any of the secrets are valid, the payload is returned with no error. A bound secret is valid only for the hooks it lists; bound reports that only bound secrets validated the payload.
Types ¶
type BoundSecret ¶ added in v1.53.0
BoundSecret is a webhook secret that only the hooks in HookIDs may use. A delivery that validates only with bound secrets is accepted when one of them lists its X-GitHub-Hook-ID, and then only as a requested check event. A BoundSecret with no HookIDs accepts no deliveries.
type PayloadInfo ¶
type PayloadInfo struct {
Action string `json:"action,omitempty"`
Number int `json:"number,omitempty"`
Repository struct {
FullName string `json:"full_name,omitempty"`
Owner struct {
Login string `json:"login,omitempty"`
} `json:"owner"`
Name string `json:"name,omitempty"`
} `json:"repository"`
Organization struct {
Login string `json:"login,omitempty"`
} `json:"organization"`
PullRequest pullRequestInfo `json:"pull_request"`
Issue struct {
Number int `json:"number,omitempty"`
PullRequestInfo *struct{} `json:"pull_request,omitempty"`
} `json:"issue"`
CheckRun struct {
CheckSuite checkSuiteInfo `json:"check_suite"`
} `json:"check_run"`
CheckSuite checkSuiteInfo `json:"check_suite"`
Comment struct {
ID int `json:"id,omitempty"`
} `json:"comment"`
Review struct {
ID int `json:"id,omitempty"`
} `json:"review"`
}
PayloadInfo is a minimal struct for GitHub webhook payload information, containing only the fields we need to process for our needs of setting cloud event headers.
type Server ¶
type Server struct {
// contains filtered or unexported fields
}
func NewServer ¶
func NewServer(client cloudevents.Client, opts ServerOptions) *Server
Example ¶
package main
import (
"fmt"
"net/http"
"net/http/httptest"
"github.com/chainguard-dev/terraform-infra-common/modules/github-events/internal/trampoline"
cloudevents "github.com/cloudevents/sdk-go/v2"
)
func main() {
client, err := cloudevents.NewClientHTTP()
if err != nil {
panic(err)
}
s := trampoline.NewServer(client, trampoline.ServerOptions{
Secrets: [][]byte{[]byte("my-secret")},
})
// The server implements http.Handler.
req := httptest.NewRequest(http.MethodPost, "/", nil)
w := httptest.NewRecorder()
s.ServeHTTP(w, req)
fmt.Println(w.Code)
}
Output: 403
type ServerOptions ¶
type ServerOptions struct {
// Secrets validate deliveries from any hook.
Secrets [][]byte
BoundSecrets []BoundSecret
WebhookID []string
RequestedOnlyWebhook []string
OrgFilter []string
}