fix: github prepend their hashes with sha256=

because of course they do
This commit is contained in:
zkldi
2022-12-19 03:33:08 +00:00
parent 90c8530229
commit fd10d2654d
+6 -4
View File
@@ -65,15 +65,17 @@ function ConvertGitHubURL(url: string) {
* @name POST /webhook
*/
app.post("/webhook", bodyParser.text({ type: "*/*" }), async (req, res) => {
console.log(req.body);
const hash = crypto
.createHmac("SHA256", ProcessEnv.webhookSecret)
.update(req.body as string)
.digest("hex");
if (hash !== req.header("X-Hub-Signature-256")) {
console.log(`Signatures didn't match.`);
if (`sha256=${hash}` !== req.header("X-Hub-Signature-256")) {
console.log(
`Signatures didn't match. ours="sha256=${hash}" theirs=${req.header(
"X-Hub-Signature-256"
)}`
);
return res.status(400).json({
success: false,
description: `Invalid Signature.`,