Validate Forgejo HMAC-SHA256 signature instead of plain secret header

FixAPIService
Shipped
April 11, 2026 at 9:35 PM UTC
Author
Kamo
Commit
6636786

Forgejo sends webhook secret as X-Gitea-Signature / X-Forgejo-Signature HMAC-SHA256 hash, not as a plain header value. Read body, verify HMAC, then forward to SecurityService.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing