diff --git a/app/controllers/api/functions.php b/app/controllers/api/functions.php index 7bc408b16a..a1263ced35 100644 --- a/app/controllers/api/functions.php +++ b/app/controllers/api/functions.php @@ -1496,7 +1496,7 @@ App::post('/v1/functions/:functionId/executions') ->param('functionId', '', new UID(), 'Function ID.') ->param('body', '', new Text(8192, 0), 'HTTP body of execution. Default value is empty string.', true) ->param('async', false, new Boolean(), 'Execute code in the background. Default value is false.', true) - ->param('path', '/', new Text(2048, 0), 'HTTP path of execution. Path can include query params. Default value is /', true) + ->param('path', '/', new Text(2048), 'HTTP path of execution. Path can include query params. Default value is /', true) ->param('method', 'POST', new Whitelist(['GET', 'POST', 'PUT', 'PATCH', 'DELETE', 'OPTIONS'], true), 'HTTP method of execution. Default value is GET.', true) ->param('headers', [], new Assoc(), 'HTTP headers of execution. Defaults to empty.', true) ->inject('response') diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index fc352e4809..67f59b9e40 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -789,14 +789,14 @@ App::post('/v1/vcs/github/events') ->inject('getProjectDB') ->action( function (GitHub $github, Request $request, Response $response, Database $dbForConsole, callable $getProjectDB) use ($createGitDeployments) { - $signature = $request->getHeader('x-hub-signature-256', ''); $payload = $request->getRawPayload(); + $signatureRemote = $request->getHeader('x-hub-signature-256', ''); + $signatureLocal = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - $signatureKey = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); + $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); - $valid = $github->validateWebhookEvent($payload, $signature, $signatureKey); if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook signature."); + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook payload signature. Please make sure the webhook secret has same value in your GitHub app and in the _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); } $event = $request->getHeader('x-github-event', '');