memos/internal/webhook
boojack f497f009ce fix(webhook): fail loud on malformed signing secret and add tests
Follow-up to #6013. The signing path silently fell back to using the raw
secret string as the HMAC key when a whsec_-prefixed secret had invalid
base64, producing signatures no receiver could verify with no server-side
signal.

- Extract resolveSigningKey helper that errors on invalid whsec_ base64
- Post returns that error (logged by the async dispatcher); ValidateSigningSecret
  rejects it at write time so a bad secret is never stored
- Fix stale comment referencing a nonexistent Authorization header
- Add Go tests: key derivation, secret validation, end-to-end signature
  round-trip, and the invariant that the secret never leaks into API responses
2026-06-09 22:58:10 +08:00
..
validate.go fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00
webhook.go fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00
webhook_test.go fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00