feat: use keying for webhook secrets (#10059)
- Follow up of forgejo/forgejo!5041, forgejo/forgejo!6074, forgejo/forgejo!8692, forgejo/forgejo!9923 - The `webhook` table contains a encrypted header authorization. - Use `keying` to safely store this secret and bound them to the table, column and row id - The migration isn't spectacular but does closely follow what we learned in the previous three migrations: use a transaction and delete records when you can't decrypt them. Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/10059 Reviewed-by: Mathieu Fenniak <mfenniak@noreply.codeberg.org> Reviewed-by: oliverpool <oliverpool@noreply.codeberg.org> Co-authored-by: Gusted <postmaster@gusted.xyz> Co-committed-by: Gusted <postmaster@gusted.xyz>
This commit is contained in:
@@ -40,7 +40,7 @@ func TestDeleteComment(t *testing.T) {
|
||||
RepoID: issue.RepoID,
|
||||
IsActive: true,
|
||||
Events: `{"choose_events":true,"events":{"issue_comment": true}}`,
|
||||
}))
|
||||
}, ""))
|
||||
hookTaskCount := unittest.GetCount(t, &webhook_model.HookTask{})
|
||||
|
||||
require.NoError(t, issue_service.DeleteComment(db.DefaultContext, nil, comment))
|
||||
@@ -68,7 +68,7 @@ func TestDeleteComment(t *testing.T) {
|
||||
RepoID: issue.RepoID,
|
||||
IsActive: true,
|
||||
Events: `{"choose_events":true,"events":{"issue_comment": true}}`,
|
||||
}))
|
||||
}, ""))
|
||||
hookTaskCount := unittest.GetCount(t, &webhook_model.HookTask{})
|
||||
|
||||
require.NoError(t, comment.LoadReview(t.Context()))
|
||||
@@ -101,7 +101,7 @@ func TestUpdateComment(t *testing.T) {
|
||||
RepoID: issue.RepoID,
|
||||
IsActive: true,
|
||||
Events: `{"choose_events":true,"events":{"issue_comment": true}}`,
|
||||
}))
|
||||
}, ""))
|
||||
hookTaskCount := unittest.GetCount(t, &webhook_model.HookTask{})
|
||||
oldContent := comment.Content
|
||||
comment.Content = "Hello!"
|
||||
@@ -132,7 +132,7 @@ func TestUpdateComment(t *testing.T) {
|
||||
RepoID: issue.RepoID,
|
||||
IsActive: true,
|
||||
Events: `{"choose_events":true,"events":{"issue_comment": true}}`,
|
||||
}))
|
||||
}, ""))
|
||||
hookTaskCount := unittest.GetCount(t, &webhook_model.HookTask{})
|
||||
oldContent := comment.Content
|
||||
comment.Content = "Hello!"
|
||||
|
||||
Reference in New Issue
Block a user