trampoline

package
v1.56.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Overview

Package trampoline implements an HTTP server that receives GitHub webhook events, validates their signatures, and forwards them as CloudEvents to a broker ingress.

Use NewServer to create a Server configured with a CloudEvents client and webhook secrets. The server implements http.Handler and can be registered with any HTTP mux.

Index

Examples

Constants

This section is empty.

Variables

This section is empty.

Functions

func ValidatePayload

func ValidatePayload(r *http.Request, secrets [][]byte, boundSecrets []BoundSecret) (payload []byte, bound bool, err error)

ValidatePayload validates the payload of a webhook request for a given set of secrets. If any of the secrets are valid, the payload is returned with no error. A bound secret is valid only for the hooks it lists; bound reports that only bound secrets validated the payload.

Types

type BoundSecret added in v1.53.0

type BoundSecret struct {
	Secret  []byte
	HookIDs []string
}

BoundSecret is a webhook secret that only the hooks in HookIDs may use. A delivery that validates only with bound secrets is accepted when one of them lists its X-GitHub-Hook-ID, and then only as a requested check event. A BoundSecret with no HookIDs accepts no deliveries.

type PayloadInfo

type PayloadInfo struct {
	Action     string `json:"action,omitempty"`
	Number     int    `json:"number,omitempty"`
	Repository struct {
		FullName string `json:"full_name,omitempty"`
		Owner    struct {
			Login string `json:"login,omitempty"`
		} `json:"owner"`
		Name string `json:"name,omitempty"`
	} `json:"repository"`
	Organization struct {
		Login string `json:"login,omitempty"`
	} `json:"organization"`
	PullRequest pullRequestInfo `json:"pull_request"`
	Issue       struct {
		Number          int       `json:"number,omitempty"`
		PullRequestInfo *struct{} `json:"pull_request,omitempty"`
	} `json:"issue"`
	CheckRun struct {
		CheckSuite checkSuiteInfo `json:"check_suite"`
	} `json:"check_run"`
	CheckSuite checkSuiteInfo `json:"check_suite"`
	Comment    struct {
		ID int `json:"id,omitempty"`
	} `json:"comment"`
	Review struct {
		ID int `json:"id,omitempty"`
	} `json:"review"`
}

PayloadInfo is a minimal struct for GitHub webhook payload information, containing only the fields we need to process for our needs of setting cloud event headers.

type Server

type Server struct {
	// contains filtered or unexported fields
}

func NewServer

func NewServer(client cloudevents.Client, opts ServerOptions) *Server
Example
package main

import (
	"fmt"
	"net/http"
	"net/http/httptest"

	"github.com/chainguard-dev/terraform-infra-common/modules/github-events/internal/trampoline"
	cloudevents "github.com/cloudevents/sdk-go/v2"
)

func main() {
	client, err := cloudevents.NewClientHTTP()
	if err != nil {
		panic(err)
	}

	s := trampoline.NewServer(client, trampoline.ServerOptions{
		Secrets: [][]byte{[]byte("my-secret")},
	})

	// The server implements http.Handler.
	req := httptest.NewRequest(http.MethodPost, "/", nil)
	w := httptest.NewRecorder()
	s.ServeHTTP(w, req)
	fmt.Println(w.Code)
}
Output:
403

func (*Server) ServeHTTP

func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request)

type ServerOptions

type ServerOptions struct {
	// Secrets validate deliveries from any hook.
	Secrets              [][]byte
	BoundSecrets         []BoundSecret
	WebhookID            []string
	RequestedOnlyWebhook []string
	OrgFilter            []string
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL