-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
I love this project, it's a nice demonstration of what you can do with SAR.
I'm curious if you have any ideas on how security could be improved for these webhook endpoints? It seems like if the URL for the webhook receiver ends up in someone's hands they could send any payload they want.
Some options I'm thinking of:
- support for shared secrets somehow (like Github's)
- IP whitelisting if you have static IPs where you expect these webhooks to arrive from
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels