From 39a444710346c3cb4d1d0d0451434ae3ff452b16 Mon Sep 17 00:00:00 2001 From: Khushboo Verma <43381712+vermakhushboo@users.noreply.github.com> Date: Wed, 6 Sep 2023 22:34:03 +0530 Subject: [PATCH] Update webhook secret check --- app/controllers/api/vcs.php | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php index f6484ae157..d4055e4860 100644 --- a/app/controllers/api/vcs.php +++ b/app/controllers/api/vcs.php @@ -783,15 +783,14 @@ App::post('/v1/vcs/github/events') ->inject('getProjectDB') ->action( function (GitHub $github, Request $request, Response $response, Database $dbForConsole, callable $getProjectDB) use ($createGitDeployments) { - $signature = $request->getHeader('x-hub-signature-256', ''); $payload = $request->getRawPayload(); + $signatureRemote = $request->getHeader('x-hub-signature-256', ''); + $signatureLocal = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - $signatureKey = App::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - - $valid = !empty($signatureKey) ? $github->validateWebhookEvent($payload, $signature, $signatureKey) : true; + $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook signature."); + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Payload is not signed properly. Please make sure webhook secret has same value in GitHub app and in _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); } $event = $request->getHeader('x-github-event', '');