feat: trigger audited webhook pings - #240
Conversation
pilipilisbot
left a comment
There was a problem hiding this comment.
Reviewed the webhook ping action end-to-end and this looks ready.
What I checked:
- Backend endpoint is admin-only, uses the stored hook metadata, validates the exact
https://api.github.com/{org|repo}/.../hooks/{id}/pingspath before invokinggh api, and does not expose raw CLI stderr/stdout to the browser. - Audit flow records requested/succeeded/failed actions and the hook detail endpoint returns recent administrative actions.
- SQLite schema addition is created through the normal packaged schema path.
- Dashboard wiring exposes the action only when a ping URL is known, gives pending/result feedback, refreshes detail state, and keeps the generated static bundle updated.
- Docs cover the operational
ghpermission requirement and the browser/CLI credential separation.
Validation:
- GitHub checks are green:
pytest (3.11),pytest (3.12), anddashboard. - Local focused backend check in a temporary venv:
pytest tests/test_webhook.py tests/test_backend.py -q-> 95 passed, 1 existing Starlette/httpx deprecation warning.
No blocking findings from my side.
Let dashboard administrators request a fresh GitHub hook ping through the operational gh identity. Validate the stored API path, audit every result, refresh hook details, and avoid exposing CLI failures to the browser.\n\nRefs #191\n\nCo-authored-by: Eduard Carreras <ecarreras@gisce.net>
b86b920 to
df47c43
Compare
|
Post-merge audit found one confidentiality mismatch that needs a follow-up fix.
Recommended fix: omit the private Integration audit: final head |
Summary
api.github.comorganization/repository hook path before invokinggh apiSend pingcontrol, progress feedback, delayed refresh and recent administrative actions to hook detailValidation
pytest -q— 410 passednpm test -- --run— 62 passednpm run buildRefs #191
Requested by: @ecarreras