Webhook Secret
- Dominant language
- Elixir
- Stars
- 33
- Forks
- 3
- PR merge metrics
- No merged PRs in 30d
Description
When creating a New GitHub Application via https://github.com/settings/apps/new
we are given the _option_ to add a `Webhook Secret`:

While the `Webhook Secret` is "_optional_", I feel it would add good "security layer" to our app.
Otherwise _anyone_ can "spoof" a webhook `POST` request to our app and make an "edit" to someone else's issue.
> Yes, this would be "non-destructive" because the "single-source-of-truth" is still _GitHub_.
But if the person made _multiple_ "malicious" edits they could create quite a lot of spam/noise.
I don't think we need to do this "urgently" while we are using the app _internally_,
but as soon as it's `public` we should consider adding this layer of protection.
How would this work in our Elixir/Phoenix App?
The `ruby` code in the docs: https://developer.github.com/webhooks/securing
should be _fairly_ easy to "translate" to Elixir.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.