[Schema Inaccuracy] WebHooks lacking discriminator based on X-Github-Event header
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 38/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 停滞
- 技術スタック
- openapi
- 領域
- api
調査の方向性
issue に示されている OpenAPI YAML の webhooks.branch-protection-rule-created.post.parameters 定義から始め、X-Github-Event header と webhook event name を比較します。event value を enum として追加し、関連する webhook definitions に同じルールを適用します。完了とは、生成された handlers が request body だけを検証せずに event を識別できる状態です。
索引モデルが issue の本文から書いたものです。
説明
Schema Inaccuracy
While working on a generated webhook handler I noticed that the spec doesn't include a way to communicate which value X-Github-Event should hold. Currently this is the spec:
webhooks:
branch-protection-rule-created:
post:
summary: |-
This event occurs when there is activity relating to branch protection rules. For more information, see "[About protected branches](https://docs.github.com/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches)." For information about the APIs to manage branch protection rules, see [the GraphQL documentation](https://docs.github.com/graphql/reference/objects#branchprotectionrule) or "[Branch protection](https://docs.github.com/rest/branches/branch-protection)" in the REST API documentation.
To subscribe to this event, a GitHub App must have at least read-level access for the "Administration" repository permission
description: A branch protection rule was created.
operationId: branch-protection-rule/created
externalDocs:
url: https://docs.github.com/developers/webhooks-and-events/webhooks/webhook-events-and-payloads#branch-protection-rule
parameters:
- name: User-Agent
in: header
example: GitHub-Hookshot/123abc
schema:
type: string
- name: X-Github-Hook-Id
in: header
example: 12312312
schema:
type: string
- name: X-Github-Event
in: header
example: issues
schema:
type: string
- name: X-Github-Hook-Installation-Target-Id
in: header
example: 123123
schema:
type: string
- name: X-Github-Hook-Installation-Target-Type
in: header
example: repository
schema:
type: string
- name: X-GitHub-Delivery
in: header
example: 0b989ba4-242f-11e5-81e1-c7b6966d2516
schema:
type: string
- name: X-Hub-Signature-256
in: header
example: sha256=6dcb09b5b57875f334f61aebed695e2e4193db5e
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
"$ref": "#/components/schemas/webhook-branch-protection-rule-created"
responses:
'200':
description: Return a 200 status to indicate that the data was received
successfully
x-github:
githubCloudOnly: false
category: webhooks
subcategory: branch-protection-rule
supported-webhook-types:
- repository
- organization
- app
Expected
This is what I would have expected:
webhooks:
branch-protection-rule-created:
post:
summary: |-
This event occurs when there is activity relating to branch protection rules. For more information, see "[About protected branches](https://docs.github.com/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/about-protected-branches)." For information about the APIs to manage branch protection rules, see [the GraphQL documentation](https://docs.github.com/graphql/reference/objects#branchprotectionrule) or "[Branch protection](https://docs.github.com/rest/branches/branch-protection)" in the REST API documentation.
To subscribe to this event, a GitHub App must have at least read-level access for the "Administration" repository permission
description: A branch protection rule was created.
operationId: branch-protection-rule/created
externalDocs:
url: https://docs.github.com/developers/webhooks-and-events/webhooks/webhook-events-and-payloads#branch-protection-rule
parameters:
- name: User-Agent
in: header
example: GitHub-Hookshot/123abc
schema:
type: string
- name: X-Github-Hook-Id
in: header
example: 12312312
schema:
type: string
- name: X-Github-Event
in: header
example: issues
schema:
type: string
enum:
- branch-protection-rule
- name: X-Github-Hook-Installation-Target-Id
in: header
example: 123123
schema:
type: string
- name: X-Github-Hook-Installation-Target-Type
in: header
example: repository
schema:
type: string
- name: X-GitHub-Delivery
in: header
example: 0b989ba4-242f-11e5-81e1-c7b6966d2516
schema:
type: string
- name: X-Hub-Signature-256
in: header
example: sha256=6dcb09b5b57875f334f61aebed695e2e4193db5e
schema:
type: string
requestBody:
required: true
content:
application/json:
schema:
"$ref": "#/components/schemas/webhook-branch-protection-rule-created"
responses:
'200':
description: Return a 200 status to indicate that the data was received
successfully
x-github:
githubCloudOnly: false
category: webhooks
subcategory: branch-protection-rule
supported-webhook-types:
- repository
- organization
- app
Notes
In theory it shouldn't matter that you don't specify which value the X-Github-Event holds. But by defining it for each webhook event, there is no need to validate each possible webhook schema against the request body. On top of that this will guarantee that we don't accidentally mix up two different webhooks. While in theory we could get this from the post.operationId, but that assumes we know we should ignore the / in there and everything after it, which isn't the case for all specs out there. Plus is uses dashes between words and not underscores so using that one on one also doesn't
Reproduction Steps
n/a
- 主要言語
- 言語のデータがありません
- スター
- 1.6k
- フォーク
- 345
- 平均マージ
- 6時間
- マージ済み PR(30日)
- 82
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/rest-api-description のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
github/rest-api-description#7266 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
github/rest-api-description#7246 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
github/rest-api-description#7220 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
github/rest-api-description#7201 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/rest-api-description#7163 ·
メンテナーはふだん 1 日以内に返信
github/rest-api-description の issue をすべて見る
似ている issue
-
Change output crossing a compactsize boundary leaves the fee slightly below the requested feerateオープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
bitcoindevkit/bdk_wallet#578 ·
メンテナーはふだん 8 日以内に返信
-
Hydraulic gas_pressure omits the reference-density offset, breaking roundtrips and the pressure joinオープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
ethereum/execution-apis#915 ·
メンテナーはふだん 1 日以内に返信
-
enhancement via-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
pingdotgg/t3code#14816 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
OpenConext/OpenConext-access#1015 ·
メンテナーはふだん 1 日以内に返信