Skip to content

Tags: ExpediaGroup/github-webhook-proxy

Tags

v2.4.2

Toggle v2.4.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: drop redundant decodeURIComponent and repair urlencoded schema v…

…alidation (#267)

* fix: URLSearchParams refactor broke valid urlencoded webhooks; drop redundant decodeURIComponent

The current `URL_ENCODED` branch of `parseRequestBody` has two bugs that combine to make every valid urlencoded GitHub webhook fail:

1. `bodySchema.parse(payloadParam)` is called with a `string | null` returned by `URLSearchParams.get("payload")`, but `bodySchema` is `z.object({ payload: z.string() })` — i.e. it expects an *object* with a `payload` key. zod throws `Invalid input: expected object, received string` on every valid payload, so the function returns `undefined`. The pre-existing fixture test (`fixtures/invalid-payload-urlencoded.txt`) hides this because it only exercises an invalid payload that's expected to be rejected with 403.

2. `JSON.parse(decodeURIComponent(payload))` calls `decodeURIComponent` a second time on a value `URLSearchParams.get` has already URL-decoded. This throws `URIError: URI malformed` whenever the decoded JSON contains a literal `%` that isn't part of a valid `%XX` escape — which is common in real PR titles, commit messages, and comments ("30% threshold", "set %USERPROFILE% to ~", "WHERE x LIKE '%foo%'", "printf(\"%s\", val)").

Fixes:

- Wrap the `URLSearchParams.get("payload")` value into the `{ payload: string }` shape the schema expects, so schema validation actually runs against valid payloads.
- Drop the redundant `decodeURIComponent(payload)` — `URLSearchParams.get` already URL-decodes once, which is exactly what GitHub's single-URL-encoded webhook body needs.

Tests: 9 new cases in `lambda/proxy.test.ts` cover the percent-character regression patterns plus a control and a `%20`-preservation case, exercised both end-to-end through the handler and directly against `parseRequestBody`.

* Apply suggestions from code review

Co-authored-by: Dan Adajian <danadajian@gmail.com>

---------

Co-authored-by: Dan Adajian <danadajian@gmail.com>

v2.4.1

Toggle v2.4.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(deps): replace actions/setup-node action with semantic-release ac…

…tion (#249)

* chore(deps): update actions/setup-node action from vv5 to v6

* Replace Bun setup with semantic-release action

* Update release.yaml

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Dan Adajian <dadajian@expediagroup.com>

v2.4.0

Toggle v2.4.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
feat(deps): update dependencies (#235)

* feat(deps): update dependencies

* terraform-docs: automated action

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

v2.3.4

Toggle v2.3.4's commit message
terraform-docs: automated action

v2.3.3

Toggle v2.3.3's commit message
fix(deps): update dependencies axios from v1.7.3 to v1.7.4 [security]

v2.3.2

Toggle v2.3.2's commit message
terraform-docs: automated action

v2.3.1

Toggle v2.3.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(deps): update dependencies zod from v3.23.6 to v3.23.8 (#197)

v2.3.0

Toggle v2.3.0's commit message
feat(repo): switch to bun (#191)

* switch to bun

* workflows

* terraform-docs: automated action

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

v2.2.4

Toggle v2.2.4's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(deps): update dependency hashicorp/terraform from v1.8.0 to v1.8.1 (

#189)

v2.2.3

Toggle v2.2.3's commit message
fix(deps): update dependencies