Skip to content

feat(api): add signed webhook verification and receiver - #33

Draft
bdsqqq wants to merge 1 commit into
feat/api-parity-uploadfrom
feat/api-parity-webhooks
Draft

bdsqqq wants to merge 1 commit into
feat/api-parity-uploadfrom
feat/api-parity-webhooks

Conversation

@bdsqqq

@bdsqqq bdsqqq commented Sep 23, 2026 •

Copy link
Copy Markdown
Owner

changes

  • SDK-backed signed webhook verification and explicit loopback-default receiver
  • bounded bytes, strict UTF-8/envelope checks, unknown JSON fields, awaited stdout before acknowledgement
  • one-second shutdown bound; interrupted output may truncate; no durable queue or deduplication

verification

exact-head 0d9f7e1 CI 35931662455 passes all jobs, including existing sandbox scenarios (NOT actual Linear webhook delivery). full offline checks and final 13 focused webhook tests pass; compiled preview passes with ad-hoc signing.
review reproduced real-pipe shutdown hang. production deadline fixed it in an independent undrained-pipe probe. deterministic subprocess regression holds output/stop promises and exercises the deadline; it is synthetic, not real-pipe evidence.

limits

no remote webhook registration, delivery, proxy verification or tunnel. OAuth/full parity remain incomplete. stacked on #32; draft only.

Session-Id: 01a0c9ff-ccff-7106-aa80-086d00182476
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant