feat: per-group webhook ingress, custom webhooks, GitHub App tenant isolation

Add POST /webhook/{groupId} with per-group secrets (KV tenant:{groupId}), a custom provider (X-WebHooker-Signature HMAC, arbitrary JSON -> custom events through the route pipeline), and GitHub App installation isolation (Group.installationId) with automatic provisioning on installation.created (inst-{id} groups or binding matching owners groups). Includes WebhookPanel admin UI, custom route template, docs and 157 passing tests.
This commit is contained in:
RhenCloud 2026-08-13 09:24:50 +08:00
parent 0b078d938b
commit b600f02027
No known key found for this signature in database
GPG key ID: A574A617378C4E0B
34 changed files with 1711 additions and 183 deletions

View file

@ -84,6 +84,12 @@
:saving="savingGroup"
@save="onSaveGroupFromPanel"
/>
<WebhookPanel
v-if="canEditGroup(selectedGroup.id)"
:group-id="selectedGroup.id"
:can-edit="canEditGroup(selectedGroup.id)"
/>
</template>
<!-- Top-level views -->
@ -227,6 +233,7 @@
<script setup lang="ts">
import type { Group, Route } from "~/types";
import { useAuditApi } from "~/composables/useAudit";
import WebhookPanel from "~/components/WebhookPanel.vue";
const { t, toggle } = useI18n();
const { push } = useToasts();

View file

@ -106,6 +106,19 @@
</div>
<div class="hint">{{ t("groupEditor.providersHint") }}</div>
</div>
<div class="field">
<label
>{{ t("groupEditor.installationId") }}
<span class="lbl-note">{{ t("groupEditor.installationIdNote") }}</span></label
>
<input
v-model="form.installationId"
type="text"
inputmode="numeric"
:placeholder="t('groupEditor.installationIdPlaceholder')"
/>
<div class="hint">{{ t("groupEditor.installationIdHint") }}</div>
</div>
<div class="field">
<label
>{{ t("groupEditor.logTarget") }}
@ -183,6 +196,7 @@ const form = reactive({
name: "",
owners: "",
providers: [] as ("github" | "gitea")[],
installationId: "",
emoji: true,
lang: "",
logPlatform: "" as "" | "discord" | "telegram",
@ -218,6 +232,7 @@ watch(
form.providers = (g?.providers ?? []).filter(
(p): p is "github" | "gitea" => p === "github" || p === "gitea",
);
form.installationId = g?.installationId != null ? String(g.installationId) : "";
form.emoji = g?.emoji ?? true;
form.lang = g?.lang ?? "";
form.logPlatform = lt?.platform ?? "";
@ -268,6 +283,15 @@ function save(): void {
}
logTarget = { platform: "telegram", chatId, topicId: form.logTopicId.trim() || undefined };
}
const installationText = form.installationId.trim();
let installationId: number | undefined;
if (installationText) {
installationId = Number(installationText);
if (!Number.isInteger(installationId) || installationId <= 0) {
formError.value = t("groupEditor.errInstallationId");
return;
}
}
const owners = splitList(form.owners);
const members = props.group?.members
? props.group.members.map((m) => ({ ...m }))
@ -281,6 +305,7 @@ function save(): void {
adminIds: members.filter((m) => m.role === "owner").map((m) => m.login),
owners: props.superAdmin ? (owners.length ? owners : undefined) : props.group?.owners,
providers: form.providers.length ? form.providers : undefined,
installationId,
emoji: form.emoji,
lang: form.lang.trim() || undefined,
logTarget,

View file

@ -0,0 +1,154 @@
<template>
<section class="members-panel webhook-panel">
<div class="panel-head">
<h3>{{ t("webhook.title") }}</h3>
<span class="lbl-note">{{ t("webhook.note") }}</span>
</div>
<p v-if="!info" class="empty-log">{{ t("webhook.empty") }}</p>
<template v-else>
<div class="wh-row">
<span class="wh-label">{{ t("webhook.url") }}</span>
<code class="wh-value">{{ info.url }}</code>
<button class="btn btn-ghost btn-sm" @click="copy(info.url, 'url')">
{{ copiedUrl ? t("webhook.copied") : t("webhook.copy") }}
</button>
</div>
<div class="wh-row">
<span class="wh-label">{{ t("webhook.secret") }}</span>
<code class="wh-value">{{
info.secret ? info.secret : info.hasSecret ? maskedSecret : t("webhook.noSecret")
}}</code>
<button
v-if="info.secret"
class="btn btn-ghost btn-sm"
@click="copy(info.secret!, 'secret')"
>
{{ copiedSecret ? t("webhook.copied") : t("webhook.copy") }}
</button>
</div>
<p v-if="info.hasSecret && !info.secret" class="hint">{{ t("webhook.secretHidden") }}</p>
<div class="wh-actions">
<button class="btn btn-accent btn-sm" :disabled="busy" @click="onRegenerate">
{{ info.hasSecret ? t("webhook.regenerate") : t("webhook.generate") }}
</button>
<button
v-if="info.hasSecret"
class="btn btn-ghost btn-sm"
:disabled="busy"
@click="onDisable"
>
{{ t("webhook.disable") }}
</button>
</div>
<details class="wh-usage">
<summary>{{ t("webhook.usageTitle") }}</summary>
<p class="hint">{{ t("webhook.usageGitHub") }}</p>
<p class="hint">{{ t("webhook.usageGitea") }}</p>
<p class="hint">{{ t("webhook.usageCustom") }}</p>
<pre class="wh-code">{{ customExample }}</pre>
</details>
</template>
<div class="err">{{ error }}</div>
</section>
</template>
<script setup lang="ts">
import { ref, watch } from "vue";
import { useWebhookApi, type GroupWebhookInfo } from "~/composables/useWebhook";
const { t } = useI18n();
const props = defineProps<{ groupId: string; canEdit: boolean }>();
const api = useWebhookApi();
const info = ref<GroupWebhookInfo | null>(null);
const copiedUrl = ref(false);
const copiedSecret = ref(false);
const busy = ref(false);
const error = ref("");
const maskedSecret = "••••••••••••••••";
const customExample = [
'curl -X POST "$URL" \\',
' -H "Content-Type: application/json" \\',
' -H "X-WebHooker-Signature: sha256=$(hmac-sha256 "$BODY" "$SECRET")" \\',
" -d '{",
' "title": "Deploy failed",',
' "description": "Prod rollout failed at 12:03 UTC",',
' "color": "red",',
' "repo": "acme/widget",',
' "url": "https://ci.example.com/runs/42",',
' "fields": [{ "name": "Env", "value": "prod", "inline": true }]',
" }'",
].join("\n");
watch(
() => props.groupId,
() => {
if (!props.canEdit) return;
load();
},
{ immediate: true },
);
async function load(): Promise<void> {
error.value = "";
try {
info.value = await api.info(props.groupId);
} catch (err) {
error.value = err instanceof Error ? err.message : String(err);
info.value = null;
}
}
async function onRegenerate(): Promise<void> {
busy.value = true;
error.value = "";
try {
info.value = await api.regenerate(props.groupId);
copiedSecret.value = false;
} catch (err) {
error.value = err instanceof Error ? err.message : String(err);
} finally {
busy.value = false;
}
}
async function onDisable(): Promise<void> {
busy.value = true;
error.value = "";
try {
await api.disable(props.groupId);
info.value = { url: info.value?.url ?? "", hasSecret: false };
} catch (err) {
error.value = err instanceof Error ? err.message : String(err);
} finally {
busy.value = false;
}
}
async function copy(text: string, which: "url" | "secret"): Promise<void> {
try {
await navigator.clipboard.writeText(text);
if (which === "url") {
copiedUrl.value = true;
window.setTimeout(() => {
copiedUrl.value = false;
}, 1500);
} else {
copiedSecret.value = true;
window.setTimeout(() => {
copiedSecret.value = false;
}, 1500);
}
} catch {
// ignore clipboard failures
}
}
</script>