memos/internal/webhook
boojack eb826455b6 chore(webhook): reveal-later signing secret flow
Generate webhook signing secrets server-side and let users reveal them on
demand, replacing the create-dialog secret controls that surfaced internal
mask state (Status / Generate & Copy / Clear / Pending) to users.

- Add owner-gated GetUserWebhookSigningSecret RPC — the only path that
  returns the secret; list/create/update responses still omit it.
- Generate the secret server-side on create (webhook.GenerateSigningSecret),
  so validity no longer depends on the client.
- Rename UserWebhook.has_signing_secret -> signing_secret_set for parity
  with the existing api_key_set field.
- Create dialog drops the secret section to a one-line note; the generated
  secret is shown once right after create and revealable from Edit later.
2026-06-26 09:03:24 +08:00
..
validate.go fix(webhook): fail loud on malformed signing secret and add tests 2026-06-09 22:58:10 +08:00
webhook.go chore(webhook): reveal-later signing secret flow 2026-06-26 09:03:24 +08:00
webhook_test.go chore(webhook): reveal-later signing secret flow 2026-06-26 09:03:24 +08:00