fix(ploeg): verify forge webhook signatures before recording the delivery #141
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/ploeg-webhook-auth-before-dedup"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
handleForgeWebhook inserted the delivery id into forge_deliveries before the
provider checked the signature. An unsigned request carrying a real delivery
id got it recorded, and the genuine delivery that arrived later was answered
202 and dropped. Parsing, which verifies the signature against the raw body,
now runs first. Prepared in the 2026-10-02 Execution Pack (AUTH-01).
Adds a regression test: a rejected delivery leaves no dedup row, the verified retry with the same id is processed once, and an invalid replay after it is still rejected.
Verified with
mise run verifyon the pinned toolchain (all gates passed).Ticket: https://vikunja.webgrip.dev/tasks/1715
🤖 Generated with Claude Code