dwyl / dwyl/github-backup

Webhook Secret

Aperta
#76 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement question technical
Lingua principale
Elixir
Stelle
33
Fork
3
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

When creating a New GitHub Application via https://github.com/settings/apps/new
we are given the _option_ to add a `Webhook Secret`:
![image](https://user-images.githubusercontent.com/194400/37258025-6ac38556-2569-11e8-866f-32f9bc26ff72.png)
While the `Webhook Secret` is "_optional_", I feel it would add good "security layer" to our app.
Otherwise _anyone_ can "spoof" a webhook `POST` request to our app and make an "edit" to someone else's issue.

> Yes, this would be "non-destructive" because the "single-source-of-truth" is still _GitHub_.
But if the person made _multiple_ "malicious" edits they could create quite a lot of spam/noise.

I don't think we need to do this "urgently" while we are using the app _internally_,
but as soon as it's `public` we should consider adding this layer of protection.

How would this work in our Elixir/Phoenix App?
The `ruby` code in the docs: https://developer.github.com/webhooks/securing
should be _fairly_ easy to "translate" to Elixir.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.