Update secret-scanning partner onboarding to add more 'gotcha' information for signature validation#5637
Merged
skedwards88 merged 3 commits intomainfrom Apr 28, 2021
Conversation
|
Thanks for opening this pull request! A GitHub docs team member should be by to give feedback soon. In the meantime, please check out the contributing guidelines. |
greysteil
previously approved these changes
Apr 22, 2021
aashah
reviewed
Apr 22, 2021
Contributor
|
@just-joshing Thanks so much for opening a PR! I'll get this triaged for review ⚡ |
greysteil
approved these changes
Apr 26, 2021
skedwards88
approved these changes
Apr 28, 2021
Contributor
skedwards88
left a comment
There was a problem hiding this comment.
🎉 Thank you for opening this PR! I'll get these changes merged down for you.
Contributor
|
Thanks very much for contributing! Your pull request has been merged 🎉 You should see your changes appear on the site in approximately 24 hours. If you're looking for your next contribution, check out our help wanted issues ⚡ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why:
We received partner feedback that they encountered difficulty implementing signature validation because it wasn't clear that the raw payload needed to be used.
They use IBM Cloud Functions Actions which by default parse JSON request payloads.
So when they would stringify the JSON again and find signature validation was failing, it wasn't clear that the issue was stringifying the JSON again rearranged key/value members and changed spacing.
What's being changed:
This change updates:
token_scanningX-Header-Banneras well which wouldn't be included in a payloadCheck off the following:
Writer impact (This section is for GitHub staff members only):