Skip to content
This repository has been archived by the owner on Jun 7, 2018. It is now read-only.

webhook endpoint is vulnerable to unprivileged requests #2

Open
esno opened this issue May 15, 2018 · 0 comments
Open

webhook endpoint is vulnerable to unprivileged requests #2

esno opened this issue May 15, 2018 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@esno
Copy link
Member

esno commented May 15, 2018

currently w2d is only verifying the travis signature which means that only travis instances are allowed to send requests. if someone creates a travis job that notifies w2d it will be also forwarded to discord.

add a config file to define discord webhook urls per github slug (owner/repo) that only specific repos are allowed to forward travis notifications to discord

@esno esno added the enhancement New feature or request label May 15, 2018
@esno esno self-assigned this May 15, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant