Skip to content

v2.23.0

Choose a tag to compare

@jszobody jszobody released this 07 Jul 19:08
· 26 commits to master since this release
ab6ab16

Non-interactive install now reports the full webhook-auth setup

The report used to tell you the webhook URL but not that you also have to configure the matching auth — and a registered URL alone gets rejected, since every provider authenticates inbound webhooks and the authorizers fail closed on a missing credential.

It now always prints that provider's webhook-auth setup:

  • which credential it uses and whether it's set in your .env,
  • what to configure on the provider side so its webhooks authenticate (Postmark basic-auth / token on the webhook; SendGrid / Mailgun / Resend signing key from the dashboard; SES SNS subscription),
  • a warning that inbound webhooks are rejected until the credential is set, when it's missing.

Secret values are never echoed — only env var names — so it's safe to run in a deploy log. The guidance is rendered in full (no longer truncated in an ~80-column log).

Internal: ProviderSetup::authFailureGuidance() is renamed to webhookAuthGuidance(), now serving both install setup and verify's failure diagnosis. See #30.