Skip to content

Enforce webhook project and receiver authorization boundaries - #3

Merged
chen21019 merged 1 commit into
mainfrom
verification/webhook-automation-service-0.10.2-authz
Sep 27, 2026
Merged

chen21019 merged 1 commit into
mainfrom
verification/webhook-automation-service-0.10.2-authz

Conversation

@chen21019

Copy link
Copy Markdown

Scope

  • Match authenticated control-plane project header to management project query and handle mixed read-only role lists.
  • Require webhookReceiver kind for management and signed/public execution paths, including post-filter verification.
  • Add role, project, receiver-kind, and signed JWT regression tests; candidate 0.10.2.

Verification

  • Go validation, tests including race coverage, build and integration tests passed locally (coverage 80.7%).
  • Immutable release/security gate and isolated 8080 integration are still required before publication.

@chen21019
chen21019 requested a review from a team as a code owner September 27, 2026 04:20
@chen21019
chen21019 force-pushed the verification/webhook-automation-service-0.10.2-authz branch from 25a1d3f to 1db2cba Compare September 27, 2026 04:26
@chen21019
chen21019 enabled auto-merge (squash) September 27, 2026 04:27
@chen21019
chen21019 merged commit 7e8bdcd into main Sep 27, 2026
5 checks passed
@chen21019
chen21019 deleted the verification/webhook-automation-service-0.10.2-authz branch September 27, 2026 04:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant