Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ A simple nuxt module that works on the edge to easily validate incoming webhooks

## Features

- 20 [Webhook validators](#supported-webhook-validators)
- 21 [Webhook validators](#supported-webhook-validators)
- Works on the edge
- Exposed [Server utils](#server-utils)

Expand Down Expand Up @@ -78,6 +78,7 @@ Go to [playground/.env.example](./playground/.env.example) or [playground/nuxt.c

#### Supported webhook validators:

- Bitbucket
- Brevo
- Discord
- Dropbox
Expand Down
3 changes: 3 additions & 0 deletions playground/.env.example
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
# Bitbucket Validator
NUXT_WEBHOOK_BITBUCKET_SECRET_KEY=

# Brevo Validator
NUXT_WEBHOOK_BREVO_TOKEN=

Expand Down
3 changes: 3 additions & 0 deletions playground/nuxt.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,9 @@ export default defineNuxtConfig({
devtools: { enabled: true },
runtimeConfig: {
webhook: {
bitbucket: {
secretKey: '',
},
brevo: {
token: '',
},
Expand Down
7 changes: 7 additions & 0 deletions playground/server/api/webhooks/bitbucket.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
export default defineEventHandler(async (event) => {
const isValidWebhook = await isValidBitbucketWebhook(event)

if (!isValidWebhook) throw createError({ status: 401, message: 'Unauthorized: webhook is not valid' })

return { isValidWebhook }
})
4 changes: 4 additions & 0 deletions src/module.ts
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,10 @@ export default defineNuxtModule<ModuleOptions>({
const runtimeConfig = nuxt.options.runtimeConfig
// Webhook settings
runtimeConfig.webhook = defu(runtimeConfig.webhook, {})
// Bitbucket Webhook
runtimeConfig.webhook.bitbucket = defu(runtimeConfig.webhook.bitbucket, {
secretKey: '',
})
// Brevo Webhook
runtimeConfig.webhook.brevo = defu(runtimeConfig.webhook.brevo, {
token: '',
Expand Down
25 changes: 25 additions & 0 deletions src/runtime/server/lib/validators/bitbucket.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
import { type H3Event, getRequestHeaders } from 'h3'
import { computeSignature, HMAC_SHA256, ensureConfiguration, readRawBodyClone } from '../helpers'

const BITBUCKET_SIGNATURE = 'X-Hub-Signature'.toLowerCase()
const HMAC_PREFIX = 'sha256='

/**
* Validates Bitbucket webhooks on the Edge
* @see {@link https://support.atlassian.com/bitbucket-cloud/docs/manage-webhooks/#Validating-webhook-deliveries}
* @param event H3Event
* @returns {boolean} `true` if the webhook is valid, `false` otherwise
*/
export const isValidBitbucketWebhook = async (event: H3Event): Promise<boolean> => {
const config = ensureConfiguration('bitbucket', event)

const headers = getRequestHeaders(event)
const body = await readRawBodyClone(event)

const signature = headers[BITBUCKET_SIGNATURE]

if (!signature || !body) return false

const computedHash = await computeSignature(config.secretKey, HMAC_SHA256, body)
return signature === `${HMAC_PREFIX}${computedHash}`
}
1 change: 1 addition & 0 deletions test/events.ts
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
export { simulateBitbucketEvent } from './simulations/bitbucket'
export { simulateBrevoEvent } from './simulations/brevo'
export { simulateDiscordEvent } from './simulations/discord'
export { simulateDropboxEvent } from './simulations/dropbox'
Expand Down
3 changes: 3 additions & 0 deletions test/fixtures/basic/nuxt.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ export default defineNuxtConfig({
modules: [myModule],
runtimeConfig: {
webhook: {
bitbucket: {
secretKey: 'testBitbucketSecretKey',
},
brevo: {
token: 'testToken',
},
Expand Down
25 changes: 25 additions & 0 deletions test/simulations/bitbucket.ts
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
import { subtle } from 'node:crypto'
import { Buffer } from 'node:buffer'
import { $fetch } from '@nuxt/test-utils/e2e'
import { encoder, HMAC_SHA256 } from '../../src/runtime/server/lib/helpers'
import nuxtConfig from '../fixtures/basic/nuxt.config'

const body = { data: 'testBody' }
const secretKey = nuxtConfig.runtimeConfig?.webhook?.bitbucket?.secretKey

export const simulateBitbucketEvent = async () => {
const signature = await subtle.importKey('raw', encoder.encode(secretKey), HMAC_SHA256, false, ['sign'])
const hmac = await subtle.sign(HMAC_SHA256.name, signature, encoder.encode(JSON.stringify(body)))
const computedHash = Buffer.from(hmac).toString('hex')
const validSignature = `sha256=${computedHash}`

const headers = {
'X-Hub-Signature': validSignature,
}

return $fetch<{ isValidWebhook: boolean }>('/api/webhooks/bitbucket', {
method: 'POST',
headers,
body,
})
}