Webhook Automation Service v0.10.2
Webhook Automation Service v0.10.2
This release closes project and object-type authorization gaps in webhook receiver management and execution:
- A project-scoped management request must carry the matching trusted control-plane project header.
- Read-only roles are enforced when the trusted role header contains multiple roles.
- Receiver list, lookup, delete, name checks, and key or signed-JWT execution accept only
webhookReceiverobjects. - Regression tests cover cross-project access, unrelated generic-object kinds, and valid receiver execution.
The release was built from merged commit 7e8bdcd4b6b9456116a4b2e2c9c40e501b456366. The Linux security-release gate completed successfully, including unit and integration tests, deterministic packaging, vulnerability analysis, and artifact scans. This component release alone does not claim Server 8080 deployment or browser acceptance; those are separate Server integration gates.