Skip to content

fix(gitea): fail closed when webhook secret is unset - #4

Closed
utsab345 wants to merge 238 commits into
mainfrom
fix/gitea-webhook-fail-closed-3640
Closed

utsab345 wants to merge 238 commits into
mainfrom
fix/gitea-webhook-fail-closed-3640

Conversation

@utsab345

Copy link
Copy Markdown
Owner

Description

Fixes a fail-open webhook authentication bug in the Gitea server.

The Gitea webhook handler only verified signature authenticity when GITEA.WEBHOOK_SECRET was configured. Since the shipped default leaves it empty, every deployment that skipped the secret accepted forged webhook events. Any internet caller could post fake issue_comment or pull_request events (for example a comment body of /review with an arbitrary pull_request.url) and trigger expensive AI commands against PRs the bot token can read, without it ever coming from Gitea.

The other providers already fail closed:

  • GitHub rejects webhooks with HTTP 403 when the secret is unset.
  • GitLab rejects with HTTP 401 when no shared secret or token is present.
    Gitea was the open outlier.

Change

  • Reject every Gitea webhook with HTTP 403 when GITEA.WEBHOOK_SECRET is not configured, matching the GitHub app behavior.
  • Document the secret as required in the Gitea installation guide and in .secrets_template.toml.

Testing

  • New unit test: test_unconfigured_secret_rejects_every_webhook verifies an unauthenticated request is refused with 403, no command is dispatched, and no background task is scheduled.
  • Existing signature tests still pass (valid sign, missing header 400, bad signature 401).
  • tests/unittest/test_gitea_comment_webhooks.py, test_webhook_logic_core.py, test_should_process_pr_logic_shared.py, and test_pr_command_profiles.py all green.

shashankvarma499 and others added 30 commits September 8, 2026 13:39
…-Agent#3201)

Signed-off-by: Shashank Varma <324153016+shashankvarma499@users.noreply.github.com>
Co-authored-by: Aurora <aurora9c69543e@atomicmail.ai>
…-Agent#3163)

Co-authored-by: Alex Tumanov <6143578+oleksii-tumanov@users.noreply.github.com>
…ent#3219)

Co-authored-by: Aurora <aurora9c69543e@atomicmail.ai>
Co-authored-by: Aurora <aurora9c69543e@atomicmail.ai>
…#3231)

Co-authored-by: mihailchkik <Mihailchik@users.noreply.github.com>
…-Agent#3250)

Co-authored-by: Ismael Martinez Ramos <ismaelmartinez@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Ismael Martinez Ramos <ismaelmartinez@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…Agent#3227)

Co-authored-by: Utsab <utsab@pr-agent.dev>
Co-authored-by: Ismael Martinez Ramos <ismaelmartinez@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
PeterDaveHello and others added 27 commits September 20, 2026 22:02
Co-authored-by: vyuroshchin <>
Co-authored-by: IsmaelMartinez <ISMAELMARTINEZ@GMAIL.COM>
Co-authored-by: Ismael Martinez Ramos <ismaelmartinez@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
…gent#3585)

Co-authored-by: Alex Tumanov <6143578+oleksii-tumanov@users.noreply.github.com>
Co-authored-by: IsmaelMartinez <ISMAELMARTINEZ@GMAIL.COM>
Co-authored-by: Oleksii Tumanov <oleksii-tumanov@users.noreply.github.com>
Co-authored-by: Alex Tumanov <6143578+oleksii-tumanov@users.noreply.github.com>
…-PR-Agent#3594)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@github-actions github-actions Bot added the bug Something isn't working label Sep 23, 2026
@utsab345

Copy link
Copy Markdown
Owner Author

Closed: created against the fork instead of the upstream repo

@utsab345 utsab345 closed this Sep 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.