Skip to content

Таймаут nginx и секрет для вебхука публикации на сайт - #44

Open
sfaqer wants to merge 1 commit into
EvilBeaver:masterfrom
sfaqer:feature/site-publish-webhook
Open

sfaqer wants to merge 1 commit into
EvilBeaver:masterfrom
sfaqer:feature/site-publish-webhook

Conversation

@sfaqer

@sfaqer sfaqer commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Для приема публикации версий на сайт по вебхуку из GitHub Actions:

  • location = /api/publish с proxy_read_timeout 1200: сайт отвечает, когда уже скачал файлы версии с GitHub, а это дольше 60 секунд по умолчанию;
  • сервису site передается publish_secret — секрет подписи вебхука, тот же, что SITE_WEBHOOK_SECRET в репозитории OneScript.

Связано: EvilBeaver/OneScript.WebSite#11 (прием вебхука), EvilBeaver/OneScript#1760 (сборка и публикация).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added support for publication webhook requests over HTTPS, forwarding them to the site service with client and host details preserved.
    • Configured the site service to receive the webhook signing secret and allow longer-running requests.

Сайт принимает публикацию версий из GitHub Actions на /api/publish и
отвечает, когда скачал файлы с GitHub: это дольше 60 секунд таймаута
nginx по умолчанию. Сервису site передается секрет подписи вебхука.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: b9a6e152-f0db-49e5-b65b-49155e47e678

📥 Commits

Reviewing files that changed from the base of the PR and between b7b5ded and 51f28b8.

📒 Files selected for processing (2)
  • docker-compose.yml
  • web/nginx/sites-enabled/oscript.io

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The site service now receives the publication webhook signing secret. Nginx routes exact requests to /api/publish to the site service and forwards request headers.

Changes

Publication webhook

Layer / File(s) Summary
Publication endpoint wiring
docker-compose.yml, web/nginx/sites-enabled/oscript.io
The site service receives publish_secret. Nginx proxies exact /api/publish requests to http://site:3030, forwards client and host headers plus the request scheme, and sets a 1200-second proxy read timeout.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: nixel2007

Merge Risk: ⚪ Minimal · up to 51f28

No concrete defect is established in the deployment changes; the webhook contract of the external backend image remains unverified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 51f28

The webhook continues to use the existing backend and network exposure; this change does not add ports or storage privileges. However, the backend’s signature enforcement, missing-secret behavior, and publication recovery guarantees could not be verified. No introduced authentication bypass is demonstrated.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The relevant attack surface is an Internet-originated request reaching site and its existing shared-content access. If backend publication authorization were bypassed, affected storage would not necessarily be isolated to one release: site mounts the shared web_content volume also used by Nginx, the package hub, Jenkins, and S3 synchronization. This access predates the PR; no bypass or expanded storage permission is demonstrated.

Trust Boundaries and Controls

  • observed — HTTP requests are redirected to HTTPS, and the HTTPS proxy sets client-address, scheme, and host headers before forwarding to site. These transport and forwarding controls do not authenticate the webhook signer. Verification of an attacker-supplied request before publication side effects remains a backend contract gap.

Hardening Proposals

  • proposed — Establish a verified backend revision and secret contract before rollout. Require a nonempty deployment secret, confirm rejection of missing or invalid signatures before mutation, and validate safe retry, concurrent execution, and interruption recovery. Treat Nginx-location rollback as a timeout rollback, not publication revocation.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes both main changes: the nginx timeout and the secret for the site publication webhook.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant