From fd10d2654d2aaaae4ded8803bac01317dd4764d1 Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Mon, 19 Dec 2022 03:33:08 +0000 Subject: [PATCH] fix: github prepend their hashes with sha256= because of course they do --- github-bot/src/main.ts | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/github-bot/src/main.ts b/github-bot/src/main.ts index 224c6025d..e3a112bbc 100644 --- a/github-bot/src/main.ts +++ b/github-bot/src/main.ts @@ -65,15 +65,17 @@ function ConvertGitHubURL(url: string) { * @name POST /webhook */ app.post("/webhook", bodyParser.text({ type: "*/*" }), async (req, res) => { - console.log(req.body); - const hash = crypto .createHmac("SHA256", ProcessEnv.webhookSecret) .update(req.body as string) .digest("hex"); - if (hash !== req.header("X-Hub-Signature-256")) { - console.log(`Signatures didn't match.`); + if (`sha256=${hash}` !== req.header("X-Hub-Signature-256")) { + console.log( + `Signatures didn't match. ours="sha256=${hash}" theirs=${req.header( + "X-Hub-Signature-256" + )}` + ); return res.status(400).json({ success: false, description: `Invalid Signature.`,