Repository navigation
Conversation
Author
|
Could a maintainer rerun the Broken Link Check when convenient? The first run stopped at The workflow is unchanged in this PR. The extracted Python example passed 19 local checks, including an independent Ruby OpenSSL signature vector. I am keeping the PR in draft pending the check and documentation preview. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Webhook consumers can calculate a different digest by signing only the body, reserializing JSON, or using an API/contact identity token instead of the source's webhook signing secret. The API introduction does not currently link to a receiver verification guide.
Related: chatwoot/chatwoot#13809. This documentation change does not claim to fix or close that report.
Solution
Add a webhook verification guide to API Reference navigation and link it from the API introduction. Include a standard-library Python example, the timestamp-plus-original-body signing input, source-specific secrets, and separate replay/idempotency guidance.
Key decisions
Tests
Risks
Mintlify rendering and its broken-links command were not run locally; no Node packages were installed. No live Chatwoot instance was used.
The first CI run failed during
npm i -g mintwithETARGET: No matching version found for @mintlify/cli@4.0.1520. It did not reach the broken-link check. This remains a draft pending a working documentation tool installation, preview and maintainer review; the workflow is unchanged by this PR.The registry subsequently returned metadata for that version, but rerunning the workflow was denied with “Must have admin rights to Repository.” A maintainer rerun is needed to determine whether installation now succeeds.
Follow-up
Review the generated documentation preview and any wording needed for version-specific secret retrieval before marking ready.