feat(webhooks): forward repository, installation_repositories and push to colby-maestro - #532
Merged
Merged
Conversation
…h to colby-maestro colby-maestro's POST /api/github/webhook now handles repo creation, repos added to the App installation, and default-branch pushes. These three events are forwarded raw and unchanged, with x-hub-signature-256, x-github-event and x-github-delivery, over the existing MAESTRO service binding, because Maestro verifies the signature itself. Fire-and-forget in waitUntil; a Maestro error is logged and never affects this Worker's own handling. The existing trimmed pull_request forward is untouched. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
core-github-api now also forwards
repository,installation_repositoriesandpushwebhooks to colby-maestro'sPOST /api/github/webhook. It uses the existingMAESTROservice binding, which has noentrypoint, so the default export'sfetchhandles it.x-hub-signature-256,x-github-event,x-github-deliveryandcontent-type: application/json. Maestro checks the App signature itself, so re-serialising the body would break it.executionCtx.waitUntil. A non-2xx response or a thrown error is logged and never changes this Worker's response to GitHub.pull_requestforward to/api/github/events/pull-requestis untouched.jmbish04/are still dropped earlier by the existing scope check.Merge order
Do not merge until colby-maestro binds
GITHUB_APP_WEBHOOK_SECRETto the WORKER_API_KEY value and deploys. Until then Maestro would return 401 on these App-signed deliveries. That is harmless here because the forward is fire-and-forget, but it is noise in the logs.Tests
tests/unit/maestro-raw-forward.test.tshas 7 tests: the three events forward byte-for-byte with all headers,issues,pull_requestandcheck_runare not forwarded, and a 401 or thrown error never propagates. I broke the code five ways on purpose and each one turned the tests red: a re-serialised body, a dropped event filter, a dropped signature header,pushremoved from the set, and a thrown error.tsc --noEmitshows 27 errors andvitestshows 1 failed suite (planning-health, which can't load acloudflare:import under Node). Both are identical on cleanorigin/main, so this PR adds no new errors. The new tests call the forward function directly; they do not go through the full webhook handler.🤖 Generated with Claude Code