fix(ploeg): reject tracker webhooks when no signing secret is set #142
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/ploeg-tracker-webhook-secret"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Vikunja and ClickUp skipped signature verification when their secret was
empty, so anyone who could reach /webhooks/tracker/{provider} could assign
or withdraw work. They now reject every delivery without a configured
secret, the same as the Forgejo and GitLab forge providers, and ploegd
warns at startup when a tracker secret is missing.
Production already sets PLOEG_VIKUNJA_SECRET through the ploeg-webhook-secret ExternalSecret, so live Vikunja dispatch is unaffected. Deployments without it now reject every tracker webhook and log a warning at startup.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1716
🤖 Generated with Claude Code
Vikunja and ClickUp skipped signature verification when their secret was empty, so anyone who could reach /webhooks/tracker/{provider} could assign or withdraw work. They now reject every delivery without a configured secret, the same as the Forgejo and GitLab forge providers, and ploegd warns at startup when a tracker secret is missing. VIK-1716 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>