Repository navigation
Return 401 for unverified webhook requests instead of 404 - #215
Merged
Merged
Conversation
…lying An unverified request to /github-hook fell through to Express's 404, which reads as a wrong URL in GitHub's delivery log rather than a signature mismatch. Answer it with a 401 instead. Both /github-hook and /config also called next() after sending their response. With no later route, that landed in finalhandler, which finds the headers already sent and destroys the socket. Neither handler needs next(), so drop it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qq8TZHcEcvGppVjWSdt7ek
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Changed the webhook request verification flow to return HTTP 401 (Unauthorized) for unverified requests in production, instead of falling through to Express's default 404 handler. This provides clearer feedback to GitHub about authentication failures.
Key Changes
GitHub webhook endpoint (
/github-hook):nextparameter from route handler since it's no longer calledres.sendStatus(401)response for unverified requests in productionnext()call that was allowing unverified requests to fall throughConfig endpoint (
/config):nextparameter from async route handlerfinallyblock that was callingnext()Documentation (
error-handling.md):Tests (
test/server.js):Implementation Details
The changes eliminate unnecessary use of the
next()callback in Express middleware. Since these endpoints don't need to pass control to subsequent middleware, removing thenextparameter and explicit calls simplifies the code. The explicit 401 response for unverified webhooks provides better HTTP semantics and clearer debugging information in GitHub's webhook delivery logs.https://claude.ai/code/session_01Qq8TZHcEcvGppVjWSdt7ek