Documentation
¶
Overview ¶
Package webhook receives and verifies GitHub App webhooks, then drives onboarding and incremental refresh. This route has no bearer auth: every request is authenticated by an HMAC-SHA256 signature over the raw body, and a mismatch is rejected with 401 before any work. Verified deliveries are deduplicated by their X-GitHub-Delivery id (webhook_deliveries) so a replay is a no-op, then routed by event type — installation and installation_repositories drive onboard/offboard, push enqueues an incremental re-ingest, and release is logged only (versions are deferred).
The handler never ingests inline: onboarding and push both enqueue a job on the async queue and return promptly, keeping webhook latency low and letting the worker, debounce window, and content-hash gate do the heavy lifting.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler is the http.Handler for POST /webhooks/github.
func New ¶
New builds a webhook Handler. secret is the GitHub App webhook secret (raw bytes) used for HMAC verification. purger may be nil to disable search-index cleanup on offboarding (used by tests without a Meilisearch backend).
func (*Handler) ServeHTTP ¶
func (h *Handler) ServeHTTP(w http.ResponseWriter, r *http.Request)
ServeHTTP verifies the signature, deduplicates the delivery, parses the event, and routes it. The raw body is read exactly once — HMAC is computed over the precise bytes GitHub signed, and the same bytes are reused for parsing.