diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index f6484ae157..d4055e4860 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -783,15 +783,14 @@ App::post('/v1/vcs/github/events') ->inject('getProjectDB') ->action( function (GitHub $github, Request $request, Response $response, Database $dbForConsole, callable $getProjectDB) use ($createGitDeployments) { - $signature = $request->getHeader('x-hub-signature-256', ''); $payload = $request->getRawPayload(); + $signatureRemote = $request->getHeader('x-hub-signature-256', ''); + $signatureLocal = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - $signatureKey = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - - $valid = !empty($signatureKey) ? $github->validateWebhookEvent($payload, $signature, $signatureKey) : true; + $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook signature."); + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Payload is not signed properly. Please make sure webhook secret has same value in GitHub app and in _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); } $event = $request->getHeader('x-github-event', '');