Skip to content

Improved security for webhooks #1

@mwarkentin

Description

@mwarkentin

I love this project, it's a nice demonstration of what you can do with SAR.

I'm curious if you have any ideas on how security could be improved for these webhook endpoints? It seems like if the URL for the webhook receiver ends up in someone's hands they could send any payload they want.

Some options I'm thinking of:

  • support for shared secrets somehow (like Github's)
  • IP whitelisting if you have static IPs where you expect these webhooks to arrive from

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions