Scott Riley
08/29/2023, 4:33 PMNote that if you are using your own instance of the open source Pact Broker, it does not support secrets, and it does not have a user interface for managing webhooks. Youāll need to use the API or HAL Browser to create the webhook, and your CI token will have to be stored in plain text in the webhook. See the Webhooks API reference docs hereIn our case (where our CI provider doesnāt have any granularity on the capabilities for an api token, and creating a machine user comes with some other downsides) I wanted to know if this is something that the OSS broker does not intent to support? Is this something we contribution? Another small question I had was: In the webhook template examples, for github thereās a template variable
user.GithubToken but in the docs on whatās available for variable substitution thereās nothing there š - is it a pactflow-only value? or from something else?Yousaf Nabi (pactflow.io)
user.GithubToken in during this change when updating. It is PactFlow only that, so will update to reflect.
https://github.com/pact-foundation/docs.pact.io/commit/e60945f518b353b6c72e796fa6c18d9ea19880ec
I wanted to know if this is something that the OSS broker does not intent to support?Not sure on this answer. I did look to implement token redaction, in this PR where Beth started working on some secrets func in the Pact Broker https://github.com/pact-foundation/pact_broker/pull/262#issuecomment-501914838 It was around that time that PactFlow was launched and no free time was available for Pact Broker playtime, so it never progressed futher. Might be a decent starting point to have a look.
Scott Riley
08/29/2023, 10:21 PMAuthorization header is auto-redacted? I hadnāt seen that mentioned anywhere in the docs and hadnāt thought to just try it out š That should cover my use case to be honest - weāre on circle and the token for webhooks is in that auth header, Iām not that fussed about a userās api token in the db/plaintext if itās not accessible from the api š
> I wanted to know if this is something that the OSS broker does not intent to support?
Not sure on this answer.My question was more a āis this not in the oss pact broker because itās a differentiator between it and pactflowā - Iāve not seen that sort of vibe anywhere else though to be fair š
Yousaf Nabi (pactflow.io)
⢠Whilst implementing webhooks, I noted that URL based tokens are visible to users both rw/ro, to the pact-broker, so we are blocking access to theurl. This will also block/webhooks/webhooks/**
error_page 418 = @blockAccess;
location /webhooks {
return 418;
}
location @blockAccess {
deny all;
}
I suppose it depends on your setup but you should be good to go as is, it seem s:)Scott Riley
08/29/2023, 10:44 PMCircle-Token so I think we should be good š