Travis webhook verification
Open
bug
- Dominant language
- Go
- Stars
- 206
- Forks
- 42
- PR merge metrics
- No merged PRs in 30d
Description
https://github.com/abiosoft/caddy-git/blob/7c37f04cfac86475f954286aa1b7e7aba0fa1ca9/travis_hook.go#L81
Is the `handleSignature` function correct? The [Travis documentation](https://docs.travis-ci.com/user/notifications/#Verifying-Webhook-requests) seems to imply the code should check the `Signature` header against Travis’ public key.
It seems like the `Authorization` header is an [old method of authenticating Travis requests](https://blog.travis-ci.com/2016-08-31-webhook-delivery-changes) phased out in November 2016.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.