Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Webhook Secret

未關閉
#76 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
35/100
Issue 類型
功能
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
elixir, github
領域
api, backend, security

研究方向

先閱讀 issue 中連結的 GitHub webhook 安全文檔,然後定位 Elixir/Phoenix 應用程式的 webhook POST 處理程式。確定處理程式如何在接受 issue 編輯之前驗證 GitHub 的 Webhook Secret;當偽造的請求遭到拒絕,而真正的 GitHub webhook 仍能正常運作時,即表示完成。

由索引模型根據 Issue 內容生成。

描述

enhancement question technical

When creating a New GitHub Application via https://github.com/settings/apps/new
we are given the option to add a Webhook Secret:
image
While the Webhook Secret is "optional", I feel it would add good "security layer" to our app.
Otherwise anyone can "spoof" a webhook POST request to our app and make an "edit" to someone else's issue.

Yes, this would be "non-destructive" because the "single-source-of-truth" is still GitHub.
But if the person made multiple "malicious" edits they could create quite a lot of spam/noise.

I don't think we need to do this "urgently" while we are using the app internally,
but as soon as it's public we should consider adding this layer of protection.

How would this work in our Elixir/Phoenix App?
The ruby code in the docs: https://developer.github.com/webhooks/securing
should be fairly easy to "translate" to Elixir.

主要語言
Elixir
星號
33
分支
3
PR 合併指標
30 天內沒有已合併 PR

環境準備

這個專案沒有提供開發容器、Dockerfile 或貢獻指南,環境需要你自己搭建:先看它的 README,通用步驟見我們的新手貢獻指南。

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

dwyl/github-backup 的其他 Issue

查看 dwyl/github-backup 的全部 Issue

相似的 Issue

更多 Elixir Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。