webhook

package
v0.10.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: Apache-2.0 Imports: 17 Imported by: 0

Documentation

Overview

Package webhook receives and verifies GitHub App webhooks, then drives onboarding and incremental refresh. This route has no bearer auth: every request is authenticated by an HMAC-SHA256 signature over the raw body, and a mismatch is rejected with 401 before any work. Verified deliveries are deduplicated by their X-GitHub-Delivery id (webhook_deliveries) so a replay is a no-op, then routed by event type — installation and installation_repositories drive onboard/offboard, push enqueues an incremental re-ingest, and release is logged only (versions are deferred).

The handler never ingests inline: onboarding and push both enqueue a job on the async queue and return promptly, keeping webhook latency low and letting the worker, debounce window, and content-hash gate do the heavy lifting.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Handler

type Handler struct {
	// contains filtered or unexported fields
}

Handler is the http.Handler for POST /webhooks/github.

func New

func New(secret []byte, st webhookStore, enq enqueuer, purger indexPurger) *Handler

New builds a webhook Handler. secret is the GitHub App webhook secret (raw bytes) used for HMAC verification. purger may be nil to disable search-index cleanup on offboarding (used by tests without a Meilisearch backend).

func (*Handler) ServeHTTP

func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request)

ServeHTTP verifies the signature, deduplicates the delivery, parses the event, and routes it. The raw body is read exactly once — HMAC is computed over the precise bytes GitHub signed, and the same bytes are reused for parsing.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL