From af4be4051fecf7e3193771fc86cad021ec18b922 Mon Sep 17 00:00:00 2001 From: Khushboo Verma <43381712+vermakhushboo@users.noreply.github.com> Date: Wed, 6 Sep 2023 13:12:27 +0530 Subject: [PATCH 1/4] Skip validation if webhook secret is empty --- app/controllers/api/vcs.php | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index 543a7e6b8b..f6484ae157 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -788,7 +788,8 @@ App::post('/v1/vcs/github/events') $signatureKey = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - $valid = $github->validateWebhookEvent($payload, $signature, $signatureKey); + $valid = !empty($signatureKey) ? $github->validateWebhookEvent($payload, $signature, $signatureKey) : true; + if (!$valid) { throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook signature."); } From 0fbe9d6ce9140c2681e894e54ac5c0df80096878 Mon Sep 17 00:00:00 2001 From: Khushboo Verma <43381712+vermakhushboo@users.noreply.github.com> Date: Wed, 6 Sep 2023 13:46:01 +0530 Subject: [PATCH 2/4] Revert allowing empty string in path --- app/controllers/api/functions.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/api/functions.php b/app/controllers/api/functions.php index 5c8499cdf3..6395673b41 100644 --- a/app/controllers/api/functions.php +++ b/app/controllers/api/functions.php @@ -1500,7 +1500,7 @@ App::post('/v1/functions/:functionId/executions') ->param('functionId', '', new UID(), 'Function ID.') ->param('body', '', new Text(8192, 0), 'HTTP body of execution. Default value is empty string.', true) ->param('async', false, new Boolean(), 'Execute code in the background. Default value is false.', true) - ->param('path', '/', new Text(2048, 0), 'HTTP path of execution. Path can include query params. Default value is /', true) + ->param('path', '/', new Text(2048), 'HTTP path of execution. Path can include query params. Default value is /', true) ->param('method', 'POST', new Whitelist(['GET', 'POST', 'PUT', 'PATCH', 'DELETE', 'OPTIONS'], true), 'HTTP method of execution. Default value is GET.', true) ->param('headers', [], new Assoc(), 'HTTP headers of execution. Defaults to empty.', true) ->inject('response') From 39a444710346c3cb4d1d0d0451434ae3ff452b16 Mon Sep 17 00:00:00 2001 From: Khushboo Verma <43381712+vermakhushboo@users.noreply.github.com> Date: Wed, 6 Sep 2023 22:34:03 +0530 Subject: [PATCH 3/4] Update webhook secret check --- app/controllers/api/vcs.php | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index f6484ae157..d4055e4860 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -783,15 +783,14 @@ App::post('/v1/vcs/github/events') ->inject('getProjectDB') ->action( function (GitHub $github, Request $request, Response $response, Database $dbForConsole, callable $getProjectDB) use ($createGitDeployments) { - $signature = $request->getHeader('x-hub-signature-256', ''); $payload = $request->getRawPayload(); + $signatureRemote = $request->getHeader('x-hub-signature-256', ''); + $signatureLocal = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - $signatureKey = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - - $valid = !empty($signatureKey) ? $github->validateWebhookEvent($payload, $signature, $signatureKey) : true; + $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook signature."); + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Payload is not signed properly. Please make sure webhook secret has same value in GitHub app and in _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); } $event = $request->getHeader('x-github-event', ''); From 3bc085ea3ff71b6404e8693a489ab3bad661f614 Mon Sep 17 00:00:00 2001 From: "Vincent (Wen Yu) Ge" Date: Wed, 6 Sep 2023 13:57:46 -0400 Subject: [PATCH 4/4] Update app/controllers/api/vcs.php Co-authored-by: Christy Jacob --- app/controllers/api/vcs.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index d4055e4860..0dd854ce98 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -790,7 +790,7 @@ App::post('/v1/vcs/github/events') $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Payload is not signed properly. Please make sure webhook secret has same value in GitHub app and in _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook payload signature. Please make sure the webhook secret has same value in your GitHub app and in the _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); } $event = $request->getHeader('x-github-event', '');