dwyl / dwyl/github-backup

Webhook Secret

Open
#76 0 comments 0 reactions 0 assignees View on GitHub
enhancement question technical
Dominant language
Elixir
Stars
33
Forks
3
PR merge metrics
No merged PRs in 30d

Description

When creating a New GitHub Application via https://github.com/settings/apps/new
we are given the _option_ to add a `Webhook Secret`:
![image](https://user-images.githubusercontent.com/194400/37258025-6ac38556-2569-11e8-866f-32f9bc26ff72.png)
While the `Webhook Secret` is "_optional_", I feel it would add good "security layer" to our app.
Otherwise _anyone_ can "spoof" a webhook `POST` request to our app and make an "edit" to someone else's issue.

> Yes, this would be "non-destructive" because the "single-source-of-truth" is still _GitHub_.
But if the person made _multiple_ "malicious" edits they could create quite a lot of spam/noise.

I don't think we need to do this "urgently" while we are using the app _internally_,
but as soon as it's `public` we should consider adding this layer of protection.

How would this work in our Elixir/Phoenix App?
The `ruby` code in the docs: https://developer.github.com/webhooks/securing
should be _fairly_ easy to "translate" to Elixir.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.