mirror of https://github.com/go-gitea/gitea.git
You cannot select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
_This is a different approach to #20267, I took the liberty of adapting some parts, see below_ ## Context In some cases, a weebhook endpoint requires some kind of authentication. The usual way is by sending a static `Authorization` header, with a given token. For instance: - Matrix expects a `Bearer <token>` (already implemented, by storing the header cleartext in the metadata - which is buggy on retry #19872) - TeamCity #18667 - Gitea instances #20267 - SourceHut https://man.sr.ht/graphql.md#authentication-strategies (this is my actual personal need :) ## Proposed solution Add a dedicated encrypt column to the webhook table (instead of storing it as meta as proposed in #20267), so that it gets available for all present and future hook types (especially the custom ones #19307). This would also solve the buggy matrix retry #19872. As a first step, I would recommend focusing on the backend logic and improve the frontend at a later stage. For now the UI is a simple `Authorization` field (which could be later customized with `Bearer` and `Basic` switches):  The header name is hard-coded, since I couldn't fine any usecase justifying otherwise. ## Questions - What do you think of this approach? @justusbunsi @Gusted @silverwind - ~~How are the migrations generated? Do I have to manually create a new file, or is there a command for that?~~ - ~~I started adding it to the API: should I complete it or should I drop it? (I don't know how much the API is actually used)~~ ## Done as well: - add a migration for the existing matrix webhooks and remove the `Authorization` logic there _Closes #19872_ Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com> Co-authored-by: Gusted <williamzijl7@hotmail.com> Co-authored-by: delvh <dev.lh@web.de> |
2 years ago | |
---|---|---|
.. | ||
activitypub | 3 years ago | |
analyze | 3 years ago | |
auth | 3 years ago | |
avatar | 2 years ago | |
base | 2 years ago | |
cache | 3 years ago | |
charset | 3 years ago | |
container | 2 years ago | |
context | 2 years ago | |
convert | 2 years ago | |
csv | 3 years ago | |
doctor | 2 years ago | |
emoji | 3 years ago | |
eventsource | 3 years ago | |
generate | 3 years ago | |
git | 2 years ago | |
gitgraph | 2 years ago | |
graceful | 2 years ago | |
hcaptcha | 5 years ago | |
highlight | 3 years ago | |
hostmatcher | 2 years ago | |
httpcache | 3 years ago | |
httplib | 3 years ago | |
indexer | 2 years ago | |
issue/template | 2 years ago | |
json | 3 years ago | |
lfs | 3 years ago | |
log | 2 years ago | |
markup | 2 years ago | |
mcaptcha | 2 years ago | |
metrics | 3 years ago | |
migration | 3 years ago | |
mirror | 3 years ago | |
nosql | 3 years ago | |
notification | 2 years ago | |
options | 2 years ago | |
packages | 2 years ago | |
paginator | 2 years ago | |
password | 4 years ago | |
pprof | 3 years ago | |
private | 2 years ago | |
process | 3 years ago | |
proxy | 4 years ago | |
proxyprotocol | 3 years ago | |
public | 2 years ago | |
queue | 2 years ago | |
recaptcha | 2 years ago | |
references | 2 years ago | |
regexplru | 3 years ago | |
repository | 2 years ago | |
secret | 3 years ago | |
session | 3 years ago | |
setting | 2 years ago | |
sitemap | 3 years ago | |
ssh | 3 years ago | |
storage | 3 years ago | |
structs | 2 years ago | |
svg | 3 years ago | |
sync | 2 years ago | |
system | 2 years ago | |
templates | 2 years ago | |
test | 3 years ago | |
timeutil | 2 years ago | |
translation | 2 years ago | |
typesniffer | 3 years ago | |
updatechecker | 2 years ago | |
upload | 3 years ago | |
uri | 3 years ago | |
user | 5 years ago | |
util | 2 years ago | |
validation | 3 years ago | |
watcher | 3 years ago | |
web | 3 years ago |