bitbot icon indicating copy to clipboard operation
bitbot copied to clipboard

Restrict github/gitea webhook API keys to a specific organisation

Open jesopo opened this issue 6 years ago • 1 comments

anyone can send a webhook payload to bitbot if they have a valid API key and they can lie about the repository, which can cause bitbot to spam other channels that have hooks for other orgs/repos

jesopo avatar Sep 16 '19 10:09 jesopo

this will require data migration

jesopo avatar Sep 16 '19 15:09 jesopo