KamoCRM

Validate Forgejo HMAC-SHA256 signature instead of plain secret header

FixAPIService
Shipped
11 ஏப்ரல், 2026 அன்று 9:35 PM UTC
Author
Kamo
Commit
6636786

Forgejo sends webhook secret as X-Gitea-Signature / X-Forgejo-Signature HMAC-SHA256 hash, not as a plain header value. Read body, verify HMAC, then forward to SecurityService.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing