forgejo/modules
oliverpool b6e81357bd
Add Webhook authorization header ()
_This is a different approach to , I took the liberty of adapting
some parts, see below_

## Context

In some cases, a weebhook endpoint requires some kind of authentication.
The usual way is by sending a static `Authorization` header, with a
given token. For instance:

- Matrix expects a `Bearer <token>` (already implemented, by storing the
header cleartext in the metadata - which is buggy on retry )
- TeamCity 
- Gitea instances 
- SourceHut https://man.sr.ht/graphql.md#authentication-strategies (this
is my actual personal need :)

## Proposed solution

Add a dedicated encrypt column to the webhook table (instead of storing
it as meta as proposed in ), so that it gets available for all
present and future hook types (especially the custom ones ).

This would also solve the buggy matrix retry .

As a first step, I would recommend focusing on the backend logic and
improve the frontend at a later stage. For now the UI is a simple
`Authorization` field (which could be later customized with `Bearer` and
`Basic` switches):


![2022-08-23-142911](https://user-images.githubusercontent.com/3864879/186162483-5b721504-eef5-4932-812e-eb96a68494cc.png)

The header name is hard-coded, since I couldn't fine any usecase
justifying otherwise.

## Questions

- What do you think of this approach? @justusbunsi @Gusted @silverwind 
- ~~How are the migrations generated? Do I have to manually create a new
file, or is there a command for that?~~
- ~~I started adding it to the API: should I complete it or should I
drop it? (I don't know how much the API is actually used)~~

## Done as well:

- add a migration for the existing matrix webhooks and remove the
`Authorization` logic there


_Closes #19872_

Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: Gusted <williamzijl7@hotmail.com>
Co-authored-by: delvh <dev.lh@web.de>
2022-11-03 20:23:20 +02:00
..
activitypub Refactor AssertExistsAndLoadBean to use generics () 2022-08-16 10:22:25 +08:00
analyze Simplify IsVendor () 2022-05-06 10:12:30 +01:00
auth Remove legacy +build: constraint () 2022-05-02 23:22:45 +08:00
avatar Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
base Add generic set type () 2022-10-12 13:18:26 +08:00
cache Update go-chi/cache to utilize Ping() () 2022-05-15 20:43:27 +02:00
charset Move go-licenses to generate and separate generate into a frontend and backend component () 2022-09-05 14:04:18 +08:00
container Add generic set type () 2022-10-12 13:18:26 +08:00
context Fix package access for admins and inactive users () 2022-10-24 22:23:25 +03:00
convert Add Webhook authorization header () 2022-11-03 20:23:20 +02:00
csv Go 1.19 format () 2022-08-30 21:15:45 -05:00
doctor Merge db.Iterate and IterateObjects () 2022-10-31 23:51:14 +08:00
emoji Go 1.19 format () 2022-08-30 21:15:45 -05:00
eventsource Move some files into models' sub packages () 2022-08-25 10:31:57 +08:00
generate Use base32 for 2FA scratch token () 2022-01-26 12:10:10 +08:00
git Keep languages defined in .gitattributes () 2022-10-29 15:04:21 +08:00
gitgraph Refactor git command arguments and make all arguments to be safe to be used () 2022-10-23 22:44:45 +08:00
graceful Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
hcaptcha hCaptcha Support () 2020-10-02 23:37:53 -04:00
highlight Upgrade chroma to v2.3.0 () 2022-09-26 13:50:03 +08:00
hostmatcher Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
httpcache Add Cache-Control header to html and api responses, add no-transform () 2022-07-23 14:38:03 +08:00
httplib refactor httplib () 2022-01-19 19:31:39 -05:00
indexer Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
issue/template Deal with markdown template without metadata () 2022-10-31 17:10:33 +02:00
json Refactor legacy unknwon/com package, improve golangci lint () 2022-04-01 16:47:50 +08:00
lfs Removed some vestigial code related to Range bounds checks () 2022-07-28 11:04:36 +08:00
log Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
markup Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
mcaptcha Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
metrics Move some files into models' sub packages () 2022-08-25 10:31:57 +08:00
migration Add more checks in migration code () 2022-09-04 13:47:56 +03:00
mirror Implement sync push mirror on commit () 2022-07-08 20:45:12 +01:00
nosql fix broken insecureskipverify handling in rediss connection uris () 2022-08-29 16:38:49 +02:00
notification feat: notify doers of a merge when automerging () 2022-11-03 23:49:00 +08:00
options Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
packages Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
paginator Remove unnecessary misspell ignore pattern () 2022-10-18 12:52:25 -04:00
password Fixed assert statements. () 2021-06-07 07:27:09 +02:00
pprof Go 1.19 format () 2022-08-30 21:15:45 -05:00
private Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
process Add more linters to improve code readability () 2022-06-20 12:02:49 +02:00
proxy Return nil proxy function if proxy not enabled () 2021-08-19 16:41:20 -04:00
proxyprotocol Support Proxy protocol () 2022-08-21 19:20:43 +01:00
public Add generic set type () 2022-10-12 13:18:26 +08:00
queue Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
recaptcha Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
references Remove unnecessary misspell ignore pattern () 2022-10-18 12:52:25 -04:00
regexplru Custom regexp external issues () 2022-06-10 13:39:53 +08:00
repository Replace all instances of fmt.Errorf(%v) with fmt.Errorf(%w) () 2022-10-24 20:29:17 +01:00
secret Use CryptoRandomBytes instead of CryptoRandomString () 2022-02-04 18:03:15 +01:00
session format with gofumpt () 2022-01-20 18:46:10 +01:00
setting Allow disable sitemap () 2022-10-28 11:17:38 -04:00
sitemap Add sitemap support () 2022-06-25 19:06:01 +02:00
ssh Support Proxy protocol () 2022-08-21 19:20:43 +01:00
storage Save files in local storage as umask () 2022-09-24 21:04:14 +08:00
structs Add Webhook authorization header () 2022-11-03 20:23:20 +02:00
svg Remove legacy +build: constraint () 2022-05-02 23:22:45 +08:00
sync Add generic set type () 2022-10-12 13:18:26 +08:00
system Sync git hooks when config file path changed () 2022-10-28 19:53:08 +03:00
templates feat: notify doers of a merge when automerging () 2022-11-03 23:49:00 +08:00
test Refactor AssertExistsAndLoadBean to use generics () 2022-08-16 10:22:25 +08:00
timeutil Fix Timestamp.IsZero () 2022-10-26 21:34:44 +08:00
translation Make every not exist error unwrappable to a fs.ErrNotExist () 2022-10-18 07:50:37 +02:00
typesniffer Rework raw file http header logic () 2022-07-29 17:26:55 +02:00
updatechecker Add system setting table with cache and also add cache supports for user setting () 2022-10-17 07:29:26 +08:00
upload Simplify parameter types () 2021-12-20 04:41:31 +00:00
uri Prevent NPE if gitea uploader fails to open url () 2021-12-23 16:27:33 +00:00
user Add gitea-vet () 2020-04-05 07:20:50 +01:00
util Make every not exist error unwrappable to a fs.ErrNotExist () 2022-10-18 07:50:37 +02:00
validation Add more checks in migration code () 2022-09-04 13:47:56 +03:00
watcher Share HTML template renderers and create a watcher framework () 2022-08-28 10:43:25 +01:00
web refactor webhook *NewPost () 2022-08-11 17:48:23 +02:00